Jessica Lyons's Avatar

Jessica Lyons

@jessicalyons

Cybersecurity editor @theregister.com Contact me with tips: jessica.lyons@theregister.com or jess.825 on Signal Mama bear, book worm, outdoor lover, coffee and wine snob. PNW after decades in Santa Cruz but Blazers fan always.

5,554
Followers
553
Following
344
Posts
27.09.2023
Joined
Posts Following

Latest posts by Jessica Lyons @jessicalyons

Preview
Dev stunned by $82K Gemini API key bill after theft : Probably not an isolated incident only as researchers have already found 2,863 live API keys exposed

A developer says their company is on the hook for more than $82,000 in unauthorized charges after a stolen Google Gemini API key racked massive usage costs up in just 48 hours.

03.03.2026 23:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
DEF CON hackers 'fed up with government,' Jake Braun says Interview: Jake Braun thinks hackers need to create a 'Digital arsenal of democracy' to defend us all

Thinking back to Ben Franklin, we saw society moving in the right direction for the last 500 years because of our commitment to science, human rights, etc., and that seems to be at the very least slowing down, if not reversing,” Jake Braun told me via The Register.

02.03.2026 20:25 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
They Helped Women Fight Online Abuse. They Were Barred From the U.S.

well this is bullshit

26.02.2026 22:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Americans sue Homeland Security over 'illegal' surveillance : 'This is a warning. We know you live right here'

Two US residents have sued several Homeland Security agencies and officials, including Secretary Kristi Noem, for allegedly using surveillance tools to harass them, branding them as "domestic terrorists," and even showing up at their homes based on license-plate recognition.

23.02.2026 23:45 πŸ‘ 8 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Adidas investigates third-party data breach : 'Potential data protection incident' at an 'independent licensing partner,' we're told

BREAKING: Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.

19.02.2026 00:02 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

agreed

19.02.2026 00:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
ShinyHunters allegedly drove off with 1.7M CarGurus records : Latest in a rash of grab-and-leak data incidents

CarGurus allegedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on its leak site on Wednesday.

18.02.2026 23:50 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Ransomware crews abuse bossware to blend into networks : As if snooping on your workers wasn't bad enough

Your supervisor may like using employee monitoring apps to keep tabs on you, but crims like the snooping software even more. Threat actors are now using legit bossware to blend into corporate networks and attempt ransomware deployment.

HT: @huntress.com security operations analyst Michael Tigges

12.02.2026 22:03 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Google Fulfilled ICE Subpoena Demanding Student Journalist’s Bank and Credit Card Numbers Amandla Thomas-Johnson didn't know how much information ICE requested in a subpoena now. Google never gave him a chance to fight it.

Don't be evil, Google

12.02.2026 15:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Payroll pirates conned the help desk, stole employee’s pay Exclusive: Attackers using social engineering to exploit business processes, rather than tunnelling in via tech

EXCLUSIVE: I spoke with Binary Defense lead threat hunter John Dwyer about a new type of payroll scam where attackers call the help desk, force an MFA token reset, and use the org's own VDI to access HR platforms and reroute paychecks. As John told me: "Every employee on earth becomes a target."

11.02.2026 16:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AWS intruder pulled off AI-assisted cloud break-in in 8 mins UPDATED: LLMs automated most phases of the attack

A digital intruder broke into an AWS cloud environment and in just under 10 minutes went from initial access to administrative privileges, thanks to an AI speed assist.

05.02.2026 19:37 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Incident Report: CVE-2024-YIKES A series of unfortunate events.

Best thing I've read all day.

03.02.2026 20:11 πŸ‘ 6 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
Preview
CISA insider-threat warning comes with an ironic twist opinion: The call is coming from inside the house

Maybe everything is all about timing, like the time (this week) America's lead cyber-defense agency sounded the alarm on insider threats after it came to light that its senior official uploaded sensitive documents to ChatGPT.

Or maybe it's about hypocrisy.

30.01.2026 00:41 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Gregory Bovino Gets Demoted The Border Patrol chief was the public face of a traveling immigration crackdown on cities governed by Democrats.

BREAKING Greg Bovino has been removed as Border Patrol "commander at large" and will return to El Centro Calif, where he is expected to retire soon. A stunning turnaround after Pretti killing. Bovino's traveling blue city crackdown is over www.theatlantic.com/politics/202...

26.01.2026 23:40 πŸ‘ 10485 πŸ” 3187 πŸ’¬ 1273 πŸ“Œ 3636
Preview
Canva among ~100 ShinyHunters credential-theft targets : Atlassian, RingCentral, ZoomInfo also among tech targets

ShinyHunters has targeted around 100 organizations in its latest Okta single sign-on (SSO) credential stealing campaign, according to researchers and the criminal group itself.

26.01.2026 22:45 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

For every person that was at the march today there was also someone tailing ICE vehicles or watching over a neighborhood business or doing mutual aid. This crowd is only part of us!

I love this state, I love this city (and I'm including the whole metro in that).

23.01.2026 23:08 πŸ‘ 254 πŸ” 52 πŸ’¬ 4 πŸ“Œ 1
Preview
Tech employees demand their leaders take a stand against ICE : But CEOs remain frozen in place

More than 400 tech workers have urged their CEOs to "call the White House and demand ICE leave our cities" after masked federal agents shot and killed Alex Pretti over the weekend and the world's richest and most powerful chief executives remained silent.

26.01.2026 19:01 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
CISA won't attend infosec industry's biggest conference exclusive: But ex-CISA boss and new RSAC CEO Jen Easterly will be there

BREAKING: The US Cybersecurity and Infrastructure Security Agency won't attend the annual RSA Conference in March, an agency spokesperson confirmed to The Register.

24.01.2026 00:27 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
ShinyHunters claims Okta customer breaches, leaks data : 'A lot more' victims to come, we're told

ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.

23.01.2026 19:19 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Now if ICE would just stop shooting people... www.theregister.com/2026/01/09/h...

12.01.2026 17:23 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CrowdStrike buys SGNL, identity security startup, for $740M : Authentication is basically solved. Authorization is another thing entirely...

I can now die a satisfied man. I've been quoted in the NYTimes before, but never in The Register (my absolute favorite IT tabloid). Today I was quoted in The Reg. Thank you @jessicalyons.bsky.social for letting me contribute to your article - www.theregister.com/2026/01/08/c...

09.01.2026 01:55 πŸ‘ 2 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0

Thank you for your insight!

09.01.2026 17:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
European Space Agency initiates criminal probe into breach exclusive: Two weeks, two major data leaks … not a good look for the European Space Agency

BREAKING: ESA confirmed yet another massive security breach, and told me via @theregister.com that the data thieves responsible will be subject to a criminal investigation.

07.01.2026 18:13 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
HackerOne 'ghosted' me over $8,500 bounty: Researcher : Long after CVEs issued and open source flaws fixed

This story illustrates the importance of transparency and clear communication when it comes to bug bounties. If we want ethical hackers to report vulns so they can be fixed before the criminals find and exploit them, bug bounties need to keep their end of the bargain.

07.01.2026 18:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Cybercrook claims to sell critical info about utilities : For the bargain price of 6.5 bitcoin

A cybercrook claims to have breached Pickett and Associates, a Florida-based engineering firm whose clients include major US utilities, and is selling what they claim to be about 139 GB of engineering data about Tampa Electric Company, Duke Energy Florida, and American Electric Power.

02.01.2026 18:47 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Remedio CEO: If you don't think like a hacker, you won't win interview: In supercharged AI race, defenders need to keep up

I sat down (virtually) with Remedio CEO Tal Kollender to discuss her former life hacking video games and how that led her to start a security company that uses AI to defend against AI.

02.01.2026 18:08 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Spy turned startup CEO: 'The WannaCry of AI will happen' Interview: Ah, the good old days when 0-day development took a year

"In my past life, it would take us 360 days to develop an amazing zero day," Zafran Security CEO Sanaz Yashar told me via @theregister.com. I had a great conversation with the former "hacking architect" whose startup uses AI to map and manage companies' threat exposure - you can read it all here:

22.12.2025 19:50 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CEO spills the Tea about massive token farming campaigns interview: Plus: automated SBOMs, $250,000 bounties ahead

"I view this as a canary in the coal mine," Tea co-founder Tim Lewis told me via @theregister.com

18.12.2025 23:07 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Analytics provider: We didn't expose stolen smut data : An employee of the adult site could be responsible.

Shiny Hunters claims to be behind the breach, while Mixpanel tells us a Pornhub parent company employee - not the analytics provider - last accessed the stolen data: "If this data is in the hands of an unauthorized party, we do not believe that is the result of a security incident at Mixpanel."

16.12.2025 22:07 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
React2Shell vuln exploited by China, Iran, Google warns : Who hasn't exploited this max-severity flaw?

At least five more Chinese spy crews, Iran-linked goons, and financially motivated criminals are now attacking React2Shell, according to Google's threat intel team.

15.12.2025 20:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0