Sign in

Jessica Lyons

@jessicalyons.bsky.social
5.7K followers 565 following 385 posts

Cybersecurity editor @theregister.com Contact me with tips: jessica.lyons@theregister.com or jess.825 on Signal Mama bear, book worm, outdoor lover, coffee and wine snob. PNW after decades in Santa Cruz but Blazers fan always.

PostsRepliesMedia
Jessica Lyons @jessicalyons.bsky.social · 6h
AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure - via two 0days in its Zammad support platform. Today, the nonprofit said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details.
theregister.com
AI agents hacked the hackers, stealing email addresses from security research org
Chained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds
033
Jessica Lyons @jessicalyons.bsky.social · 30/09/2026
A 16-year-old security researcher @faav.net found an auth flaw in Microsoft’s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion records.
theregister.com
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
It's 2 am. Do you know what your teen is doing?
132
Jessica Lyons @jessicalyons.bsky.social · 25/09/2026
ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, wanted to preserve their reputation and keep their “business” afloat. So it hacked the FBI.
theregister.com
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
Data theft and extortion biz, that is
030
Jessica Lyons @jessicalyons.bsky.social · 22/09/2026
ShinyHunters claims they hacked the FBI and stole 2-3TB of employee data via an Oracle PeopleSoft 0day. “This is NOT financially motivated,” they told me. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”
theregister.com
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
This time it's personal
17282155
Jessica Lyons @jessicalyons.bsky.social · 02/09/2026
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take around two weeks. And at the end of the operation, the AI left the company a list of its security failings, detailing “dozens of exploited findings.”
theregister.com
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
Adding insult to injury
020
Jessica Lyons @jessicalyons.bsky.social · 06/08/2026
OpenAI loves to talk about the Hugging Face hack, and yesterday at Black Hat we learned that the whole chain of events leading up to the intrusion started back in May with an AI agent message board.
theregister.com
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
011
Jessica Lyons @jessicalyons.bsky.social · 08/07/2026
GitHub Copilot refuses harmful prompts if asked in chat - like, "how to fool a breathalyzer test" or "smuggle bulk cash out of the US" - but then will write them in code 100 percent of the time if the prompt is broken into smaller steps across multiple stages of a software development workflow.
theregister.com
GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code
More fun with AI jailbreaks, this time at the workflow level
0127
Jessica Lyons @jessicalyons.bsky.social · 07/07/2026
EXCLUSIVE There's no honor among thieves as a new worm steals from other infectious software. It pilfers “multiple” victims’ credentials and mines for cryptocurrency while killing competitors’ processes, including similar secret-harvesting malware.
theregister.com
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Dog-eat-dog world for credential-stealing attackers
000
Jessica Lyons @jessicalyons.bsky.social · 30/06/2026
More on Huntress as CEO changes his tune from “firmly disagree” and don't “understand Ben's accusations” about a still-employed threat hunter passing along insider info the ransomware operator. Now he admits "questionable, long-term threat actor communications” and called this “poor judgment.”
theregister.com
Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe
Ex-employee claims this 'meets the definition of an insider threat'
040
Jessica Lyons @jessicalyons.bsky.social · 25/06/2026
Security firm Huntress allegedly has a turncoat insider leaking info to a ransomware operation, according to an ex-employee who took his grievances to social media after claiming the security shop tried to “silence” him with legal threats.
theregister.com
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
Former employee accuses company of prioritizing pending IPO over client security
062
Jessica Lyons @jessicalyons.bsky.social · 17/06/2026
If you have a Fortinet firewall, it's time to stop and change your passwords. Intruders somehow gained access to around 75,000 Fortinet firewall devices and stole credentials belonging to major corporations across 194 countries, in some cases leading to full network compromise.
theregister.com
Massive password-stealing attack hits 75k Fortinet firewalls
Why are you even reading this?! Rotate your passwords!!
033
Jessica Lyons @jessicalyons.bsky.social · 15/06/2026
The “jailbreak” that prompted the Trump administration to block Anthropic’s most advanced models was a three-word prompt: “Fix this code.” That's according to Luta Security CEO @k8em0.bsky.social - the only outside expert to read the research paper on the guardrail bypass that prompted the ban.
theregister.com
Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher
According to the one person who actually read the research paper
070
Jessica Lyons @jessicalyons.bsky.social · 11/06/2026
Data theft and extortion group ShinyHunters exploited a critical Oracle PeopleSoft bug as a zero-day to compromise more than 100 organizations, including the University of Nottingham, across 300 vulnerable instances, beginning in May.
theregister.com
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day
University of Nottingham is first of many, Shiny tells The Reg
000
Jessica Lyons @jessicalyons.bsky.social · 10/06/2026
Nightmare Eclipse, the prolific bug hunter and possibly disgruntled ex-Microsoft employee, released another 0-day - this one is No. 7 - just hours after Microsoft's Patch Tuesday security updates. www.theregister.com/security/202...
theregister.com
Angry bug hunter with Microsoft beef drops new Windows 0-day
Revenge is a dish best served code
023
Jessica Lyons @jessicalyons.bsky.social · 27/05/2026
An npm-slop package “mouse5212-super-formatter” targeting Claude users and acting as a stealer reached 676 downloads before being removed from the registry - and after making a major vibe coding blunder.
theregister.com
Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token
Script kiddies these days
041
Jessica Lyons @jessicalyons.bsky.social · 26/05/2026
Turns out Gemini makes a perfect hacking partner.
theregister.com
A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets
Hey, Gemini, how much can we earn from one pump-and-dump cycle?
000
Jessica Lyons @jessicalyons.bsky.social · 19/05/2026
"A national agency having 844 MB of production infrastructure material in a public GitHub repository for six months is as serious as a secrets leak gets," GitGuardian researcher Guillaume Valadon told me.
theregister.com
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'?
172
Reposted by Jessica Lyons
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 15/05/2026
Thank you @jessicalyons.bsky.social & @theregister.com for letting me call ShinyHunters scumbags 😂
theregister.com
Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data
Other than Instructure execs - maybe?
3155
Jessica Lyons @jessicalyons.bsky.social · 14/05/2026
“At first, yes, this means more patches and thus more work for admins,” @dustinchilds.bsky.social told me. “The goal over time would be to eliminate as many as possible, and, over time, that monthly number goes down.”
theregister.com
Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Palo Alto Networks found and fixed 75 flaws this month, up from its usual five
011
Jessica Lyons @jessicalyons.bsky.social · 30/04/2026
"I'm concerned about what they are leaving behind: What type of C2 on a sleep cycle is still lingering in these environments?" TrendAI VP Tom Kellermann told me in an exclusive interview about the never-before-seen campaign.
theregister.com
Chinese spy group caught lurking in Poland, Asia networks
Exclusive: Just in time for the Trump-Xi summit
020
Reposted by Jessica Lyons
Socket @socket.dev · 28/04/2026
Thanks to @jessicalyons.bsky.social for bringing more attention to this story. OSS security tools are getting hammered right now, and this piece captures why these incidents matter beyond any one vendor compromise.
073
Jessica Lyons @jessicalyons.bsky.social · 21/04/2026
"Felony murder law does not require that a defendant pull the trigger, only that they commit a dangerous felony that results in death," ex-FBI cyber chief/Halcyon SVP Cynthia Kaiser told lawmakers.
theregister.com
Ex-FBI lead urges homicide charges against ransomware scum
: Lawmakers decry CISA cuts: 'We are shooting ourselves in the foot'
010
Jessica Lyons @jessicalyons.bsky.social · 17/04/2026
A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic's official Model Context Protocol (MCP) puts as many as 200,000 servers at risk of complete takeover, according to security researchers.
theregister.com
MCP 'design flaw' puts 200k servers at risk: Researcher
: Bug or feature?
010
Jessica Lyons @jessicalyons.bsky.social · 15/04/2026
Anthropic surprised the world by declaring that its latest model, Mythos, is so good at bug hunting that it would create chaos if released. Now, with Project Glasswing, 50+ select orgs are testing the hyped up LLM to find holes in their own products. But just how many problems have they discovered?
theregister.com
Anthropic's Project Glasswing CVE count is still guesswork
: Like the majority of the companies participating, it remains a mystery
021
Jessica Lyons @jessicalyons.bsky.social · 15/04/2026
EXCLUSIVE: Security researchers hijacked three popular AI agents that integrate with GitHub Actions by using a new type of prompt injection attack to steal API keys and access tokens, and the vendors who run agents didn’t disclose the problem.
theregister.com
Anthropic, Google, Microsoft paid AI bug bounties – quietly
Exclusive: Researchers who found the flaws scored beer money bounties and warn the problem is probably pervasive
011
Jessica Lyons @jessicalyons.bsky.social · 13/04/2026
An unknown malware slinger targeting open source software developers via Slack impersonated a real Linux Foundation official and used pages hosted on Google to steal developers' credentials and take over their systems.
theregister.com
Fake Linux Foundation leader using Slack to phish devs
: Google Sites lure leads to bogus root certificate
121
Jessica Lyons @jessicalyons.bsky.social · 11/04/2026
Here's my latest: A tale of two supply-chain attacks. Different attackers, but they both targeted open source software and developer environments and shares similar end goals.
theregister.com
041
Jessica Lyons @jessicalyons.bsky.social · 10/04/2026
The struggle is real…
000
Jessica Lyons @jessicalyons.bsky.social · 06/04/2026
"Everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers," Trellix VP John Fokker told me.
theregister.com
Don't glamorize cybercrims, roast them instead
interview: True-crime tales of criminals making fools of themselves
040
Jessica Lyons @jessicalyons.bsky.social · 02/04/2026
Tens of thousands of people eagerly downloaded the leaked Claude Code source code this week, and hundreds - if not more - of those downloads came with a side of credential-stealing malware.
theregister.com
Fake Claude Code source downloads actually delivered malware
: Source code with a side of Vidar stealer and GhostSocks
212963
Jessica Lyons @jessicalyons.bsky.social · 24/03/2026
We are seeing a dangerous convergence between supply chain attackers and high-profile extortion groups like Lapsus$," Ben Read, a lead researcher at Wiz, told me via @theregister.com on Tuesday.
theregister.com
1K+ cloud environments infected via Trivy attack
RSAC 2026: Crims 'creating a snowball effect' across open source projects
002
Jessica Lyons @jessicalyons.bsky.social · 18/03/2026
“We can remove their navy. We can remove their air power. We can attack them across all instruments of power, diplomatic, information, military, and economic. And they'll still have the ability to hack," retired US Army Lt. Gen. Ross Coffman told me via @theregister.com
theregister.com
Iran cyberattack against med tech firm 'just the beginning'
: Even without a navy, or air power, 'They'll still have the ability to hack'
011
Jessica Lyons @jessicalyons.bsky.social · 12/03/2026
BREAKING: FBI, international cops take down SocksEscort, a residential proxy service used by criminals to compromise hundreds of thousands of routers worldwide. FBI Deputy Assistant Director Jason Bilnoski spoke exclusively to @theregister.com about the disruption.
theregister.com
SocksEscort fraud-enabling proxy service taken down
: International cops stuck down 23 servers in 7 countries
010
Jessica Lyons @jessicalyons.bsky.social · 10/03/2026
It's good to be back with @theregister.com Kettle! Give us a listen and subscribe on Apple podcasts, Spotify, whatever podcast platform you like.
011
Jessica Lyons @jessicalyons.bsky.social · 10/03/2026
Researchers at red-team security startup CodeWall told us their AI agent hacked McKinsey's internal AI platform and gained full read and write access to the chatbot in just two hours. www.theregister.com/2026/03/09/m...
theregister.com
AI agent hacked McKinsey chatbot for read-write access
: David and Goliath…but with AI agents
272
Jessica Lyons @jessicalyons.bsky.social · 09/03/2026
ShinyHunters told me via @theregister.com that the extorion crew has stolen data from about 100 high-profile companies in its latest Salesforce customer data heist, including Salesforce itself.
theregister.com
ShinyHunters claims yet another Salesforce customers breach
: And they abused a Mandiant-developed open source tool in the attacks
035
Jessica Lyons @jessicalyons.bsky.social · 03/03/2026
A developer says their company is on the hook for more than $82,000 in unauthorized charges after a stolen Google Gemini API key racked massive usage costs up in just 48 hours.
theregister.com
Dev stunned by $82K Gemini API key bill after theft
: Probably not an isolated incident only as researchers have already found 2,863 live API keys exposed
010
Jessica Lyons @jessicalyons.bsky.social · 02/03/2026
Thinking back to Ben Franklin, we saw society moving in the right direction for the last 500 years because of our commitment to science, human rights, etc., and that seems to be at the very least slowing down, if not reversing,” Jake Braun told me via The Register.
theregister.com
DEF CON hackers 'fed up with government,' Jake Braun says
Interview: Jake Braun thinks hackers need to create a 'Digital arsenal of democracy' to defend us all
011
Jessica Lyons @jessicalyons.bsky.social · 26/02/2026
well this is bullshit
nytimes.com
They Helped Women Fight Online Abuse. They Were Barred From the U.S.
110
Jessica Lyons @jessicalyons.bsky.social · 23/02/2026
Two US residents have sued several Homeland Security agencies and officials, including Secretary Kristi Noem, for allegedly using surveillance tools to harass them, branding them as "domestic terrorists," and even showing up at their homes based on license-plate recognition.
theregister.com
Americans sue Homeland Security over 'illegal' surveillance
: 'This is a warning. We know you live right here'
083
Jessica Lyons @jessicalyons.bsky.social · 19/02/2026
BREAKING: Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.
theregister.com
Adidas investigates third-party data breach
: 'Potential data protection incident' at an 'independent licensing partner,' we're told
032
Jessica Lyons @jessicalyons.bsky.social · 18/02/2026
CarGurus allegedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on its leak site on Wednesday.
theregister.com
ShinyHunters allegedly drove off with 1.7M CarGurus records
: Latest in a rash of grab-and-leak data incidents
000
Jessica Lyons @jessicalyons.bsky.social · 12/02/2026
Your supervisor may like using employee monitoring apps to keep tabs on you, but crims like the snooping software even more. Threat actors are now using legit bossware to blend into corporate networks and attempt ransomware deployment. HT: @huntress.com security operations analyst Michael Tigges
theregister.com
Ransomware crews abuse bossware to blend into networks
: As if snooping on your workers wasn't bad enough
121
Jessica Lyons @jessicalyons.bsky.social · 12/02/2026
Don't be evil, Google
theintercept.com
Google Fulfilled ICE Subpoena Demanding Student Journalist’s Bank and Credit Card Numbers
Amandla Thomas-Johnson didn't know how much information ICE requested in a subpoena now. Google never gave him a chance to fight it.
010
Jessica Lyons @jessicalyons.bsky.social · 11/02/2026
EXCLUSIVE: I spoke with Binary Defense lead threat hunter John Dwyer about a new type of payroll scam where attackers call the help desk, force an MFA token reset, and use the org's own VDI to access HR platforms and reroute paychecks. As John told me: "Every employee on earth becomes a target."
theregister.com
Payroll pirates conned the help desk, stole employee’s pay
Exclusive: Attackers using social engineering to exploit business processes, rather than tunnelling in via tech
000
Jessica Lyons @jessicalyons.bsky.social · 05/02/2026
A digital intruder broke into an AWS cloud environment and in just under 10 minutes went from initial access to administrative privileges, thanks to an AI speed assist.
theregister.com
AWS intruder pulled off AI-assisted cloud break-in in 8 mins
UPDATED: LLMs automated most phases of the attack
011
Jessica Lyons @jessicalyons.bsky.social · 03/02/2026
Best thing I've read all day.
nesbitt.io
Incident Report: CVE-2024-YIKES
A series of unfortunate events.
164
Jessica Lyons @jessicalyons.bsky.social · 30/01/2026
Maybe everything is all about timing, like the time (this week) America's lead cyber-defense agency sounded the alarm on insider threats after it came to light that its senior official uploaded sensitive documents to ChatGPT. Or maybe it's about hypocrisy.
theregister.com
CISA insider-threat warning comes with an ironic twist
opinion: The call is coming from inside the house
050
Reposted by Jessica Lyons
Nick Miroff @nickmiroff.bsky.social · 26/01/2026
BREAKING Greg Bovino has been removed as Border Patrol "commander at large" and will return to El Centro Calif, where he is expected to retire soon. A stunning turnaround after Pretti killing. Bovino's traveling blue city crackdown is over www.theatlantic.com/politics/202...
theatlantic.com
Gregory Bovino Gets Demoted
The Border Patrol chief was the public face of a traveling immigration crackdown on cities governed by Democrats.
1248103793147
Jessica Lyons @jessicalyons.bsky.social · 26/01/2026
ShinyHunters has targeted around 100 organizations in its latest Okta single sign-on (SSO) credential stealing campaign, according to researchers and the criminal group itself.
theregister.com
Canva among ~100 ShinyHunters credential-theft targets
: Atlassian, RingCentral, ZoomInfo also among tech targets
011