惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

The Register - Security

Anthropic to release Mythos-class models to the public AI eyes scanning for bugs create a worrisome Linux security trend Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users Megalodon chums the waters in 5.5K+ GitHub repo poisonings Trump Mobile site leaks customer data as phone finally ships Cisco used AI to write security incident reports, with mixed results Dems slam Trump cyber cuts amid ballroom, Jan. 6 'slush fund' Threat hunters find Google API keys still usable 23 minutes after deletion HackerOne takes an axe to its bug bounty rewards 46k plaintext passwords pwned in Myspace93 breach Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw Microsoft open-sources agentic AI safety tools Zombie user account let hackers control the city’s water Even Claude agrees: hole in its sandbox was real and dangerous GitHub says internal repos exfiltrated after poisoned VS Code extension attack London's police asked Big Tech for comms data over 700,000 times last year Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames Clear your calendar, Drupal user: You have a critically urgent patch to install Clear your calendar, Drupal user: You have a critically urgent patch to install Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them Shai-Hulud copycat hits another npm package Linux kernel flaw opens root-only files to unprivileged users TanStack weighs invitation-only pull requests after supply chain attack NGINX Rift attackers waste no time targeting exposed servers Poland directs officials to ditch Signal in favor of 'secure' state-developed alternative F-35 software delays leave UK buying time with US glide bombs Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ OpenAI caught in TanStack npm supply chain chaos after employee devices compromised MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Cops arrest man suspected of being Dream Market kingpin Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access To gain root access at this company, all an intruder had to do was ask nicely To gain root access at this company, all an intruder had to do was ask nicely AI models are getting better at replacing cybersecurity pros on certain tasks Cisco to fire 4,000 staff and generously give them free training – on Cisco Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits AWS patched Quick auth bypass, says customers weren't using control AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem? Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft US bank reports itself after AI customer data mishap Cache-poisoning caper turns TanStack npm packages toxic Apple, Google drag cross-platform texting into the encrypted age Japan’s PM orders cybersecurity review to stop Mythos going full CyberZilla Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline Cookie thieves caught stealing dev secrets via fake Claude Code installers Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged Taiwan's train cyber-trauma reveals a global system that’s coming off the tracks Worm rubs out competitor's malware, then takes control 'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit Meta U-turns on encryption push for Instagram as DMs go plaintext Hackers ate my homework: Educational SaaS Canvas down after cyberattack Hackers ate my homework: Educational SaaS Canvas down after cyberattack Meta fights Ofcom over how many billions count as billions Mozilla boasts Mythos boosted Firefox bug cull Anthropic response to 1-click pwn: Shouldn't have clicked 'ok' 60% of MD5 password hashes are crackable in under an hour The network password was a key plot point in one of the most famous movies of all time Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime spree India orders infosec red alert in case Mythos sparks crime ServiceNow clears agents for landing with new AI control tower Attackers are cashing in on fresh 'CopyFail' Linux flaw 'CopyFail' attackers start cashing in on Linux flaw Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Romance scammers turn sweet talk into £102M payday Romance scammers turn sweet talk into £102M payday NHS to close-source hundreds of GitHub repos over AI, security concerns Microsoft's bad obsession is showing up in shabby services and slipshod software. Here's proof Singapore boffins get diverse SIEMs singing in harmony with agentic rule translation Singapore boffins get diverse SIEMs singing in harmony Kids say they can beat age checks by drawing on a fake mustache Kids say they can beat age checks by drawing on a fake mustache AI-BOMs replace SBOMs as way to track AI agents and bots Shadow IT has given way to shadow AI. Enter AI-BOMs If the vote you rocked, your personal info can be grokked If the vote you rocked, your personal info can be grokked Five Eyes spook shops warn agentic is too wonky for rapid rollout Five Eyes spook shops warn rapid rollouts of agentic AI are too risky Brace for the patch tsunami: AI is unearthing decades of buried code debt Brace for the patch tsunami: AI is unearthing decades of buried code debt
NHS Scotland-linked domains push pr0n and illegal streams
2026-04-08 · via The Register - Security

REG AD

Security

NHS Scotland-linked domains caught serving pr0n and dodgy sports streams

Two practice web addresses appear to have been compromised

Multiple domains belonging to Scottish healthcare providers have been hijacked and are now pushing links to adult content and illegal sports streams, according to a researcher.

First spotted by Nick Hatter, a former cybersecurity engineer turned psychotherapist and life coach, an influx of links hosted on a domain belonging to The New Surgery in Kilmacolm, near Glasgow, flooded Google's index in recent days.

On closer inspection, some seem to have been created as far back as January.

REG AD

The landing page for the domain is not the one currently used by the practice, but it was likely used previously, given the scot.nhs.uk namespace appears to belong to a US-based web developer as a guise for the illicit content it now hosts.

REG AD

The Register asked NHS Greater Glasgow and Clyde (NHSGGC), Scotland's largest health board and the one that oversees The New Surgery, to comment.

A spokesperson for NHSGGC said: "NHS Greater Glasgow and Clyde's cybersecurity team is working with Public Services Delivery Scotland's Cyber Centre of Excellence to support an independent GP practice after being made aware that a legacy website had been compromised. This affects a legacy website that was independently set up and managed by the GP practice, and there is no evidence the practice's primary website, or any NHS Scotland systems locally or nationally, were compromised."

We also contacted NHS National Services Scotland (NSS), which administers the scot.nhs.uk domain.

In a statement, Scott Barnett, Chief Information Security Officer, Public Services Delivery Scotland, said: "Our NHS Scotland Cyber Centre of Excellence (CCoE) was made aware of a security issue affecting a legacy website associated with a local GP practice.

"At this time, we are not aware of personal or sensitive data exposure as a result of this incident. There is also no evidence the practice's primary website, or any NHS Scotland systems locally or nationally, were compromised.

"Our CCoE teams are continuing to work closely with NHS Greater Glasgow and Clyde's cyber security team to understand the cause of the issue and to ensure it has been fully contained."

Hatter also told The Register that after unearthing the initial compromise related to The New Surgery, he found similar activity at the domain for Lerwick GP Practice, located in the remote Shetland Isles.

REG AD

In Lerwick's case, the domain currently in use by the practice is the one serving the illicit links. The New Surgery's compromised domain has not been used for the practice's primary website in years.

A search using the Wayback Machine shows that as of 2019, one of the sites now serving dodgy links was indeed the one used to access The New Surgery, suggesting it was compromised at some point more recently.

In discussions related to the original The New Surgery findings, Alan Woodward, professor of cybersecurity at the University of Surrey, told The Register: "The big question is, is it a real surgery or is someone putting up a dodgy URL to automatically redirect? 

"Either way, the scot.nhs.uk subdomains are managed by NHS Scotland, so somehow someone has managed to set up a subdomain of scot.nhs.uk, which should be under NHS Scotland's control.

"The most obvious way I can think someone would have done that is to steal credentials of a system admin, access the DNS controller, and add in the redirect from a URL that looks like it could be a particular GP surgery but actually isn't. That suggests a deeper penetration than just one surgery being hacked. It also means that the usual users of that GP's website won't have noticed anything, so how long it's been there, who knows."

Because the nhs.uk and scot.nhs.uk domains are closed, an everyday cybercrook cannot simply register a copycat of a GP practice within these namespaces and begin hosting questionable content.

Registering a website using these namespaces requires official authorization through the NHS directly, so the question for NHS Scotland is how a domain under its control was apparently compromised.

The same applies to DNS record changes, and NHS domains are also eligible for protection under the UK NCSC's Protective DNS scheme, although each public sector organization must apply for it, rather than it being applied automatically.

REG AD

Hatter told The Register: "My guess is this could be a DNS attack of some sort or a compromised WordPress setup, which is more likely."

Domain Information Groper (dig) queries show that the NHS domains are correctly and safely pointing to WP Engine, suggesting the compromise was on the WordPress side.

Hypothetically, if the hijackings were caused by exploitation of a plugin vulnerability, for example, it would hardly be the first time something like this had transpired as a result.

"In my opinion, it is quite possible other NHS Scotland practices are vulnerable to this attack," Hatter added. ®