LATEST NEWS

VIEW ALL
Facebook Zeus malware targeting bank accounts
Pierluigi Paganini June 07, 2013

Principal security firms detected a new variant of Facebook Zeus malware that is exploiting the popular social network to target user's bank accounts. A Facebook Zeus malware variant (aka ZeuS/ZBO ...

NSA collecting phone records of millions of US citizens daily
Pierluigi Paganini June 06, 2013

The U.S. NSA is collecting phone records of millions of Verizon Communications customers, according to a secret court order obtained by the Guardian. The U.S. NSA is collecting phone records of mill ...

The business behind a cashout service for cybercriminals
Pierluigi Paganini June 06, 2013

An interesting post by Brian Krebs is food for thought on the business behind a cashout service for cybercriminals. Brian Krebs has recently published an interesting post on his KrebsOnSecurity blog ...

NetTraveler, new global cyber espionage campaign from Kaspersky
Pierluigi Paganini June 05, 2013

NetTraveler cyber espionage campaign, revealed by Kaspersky's team, targeted over 350 high profile victims from 40 countries. NetTraveler, this is the name of a new global cyber espionage campai ...

recent articles

Cyber Crime
CEO of cybersecurity firm charged with installing malware on hospital systems

Veritaco CEO Jeffrey Bowie faces charges for allegedly installing malware on hospital computers, violating Oklahoma's Computer Crimes Act. Jeffrey Bowie, CEO of the cybersecurity firm Veritaco, is ...

Pierluigi Paganini April 26, 2025
Malware
JPCERT warns of DslogdRAT malware deployed in Ivanti Connect Secure

Researchers identified a new malware, named DslogdRAT, deployed after exploiting a now-patched flaw in Ivanti Connect Secure (ICS). JPCERT/CC researchers reported that a new malware, dubbed Dslogd ...

Pierluigi Paganini April 25, 2025
Hacking
SAP NetWeaver zero-day allegedly exploited by an initial access broker

A zero-day in SAP NetWeaver is potentially being exploited, putting thousands of internet-facing applications at risk. Researchers warn that a zero-day vulnerability, tracked as CVE-2025-31324 ( ...

Pierluigi Paganini April 25, 2025
APT
Operation SyncHole: Lazarus APT targets supply chains in South Korea

The North Korea-linked Lazarus Group targeted at least six firms in South Korea in a cyber espionage campaign called Operation SyncHole. Kaspersky researchers reported that the North Korea-linked ...

Pierluigi Paganini April 25, 2025
Cyber Crime
Interlock ransomware gang started leaking data allegedly stolen from leading kidney dialysis firm DaVita

The Interlock ransomware gang claimed responsibility for the attack on the leading kidney dialysis company DaVita and leaked alleged stolen data. DaVita Inc. provides kidney dialysis services t ...

Pierluigi Paganini April 25, 2025
Data Breach
Yale New Haven Health (YNHHS) data breach impacted 5.5 million patients

Yale New Haven Health (YNHHS) announced that threat actors stole the personal data of 5.5 million patients in a cyberattack. Yale New Haven Health (YNHHS) disclosed a data breach that exposed pers ...

Pierluigi Paganini April 24, 2025
Cyber Crime
Crooks exploit the death of Pope Francis

Crooks exploit the death of Pope Francis, using public curiosity and emotion to launch scams and spread malware, an old tactic during global events. After Pope Francis' death, cybercriminals launc ...

Pierluigi Paganini April 24, 2025
Security
WhatsApp introduces Advanced Chat Privacy to protect sensitive communications

WhatsApp adds Advanced Chat Privacy feature that allows users to block others from sharing chat content outside the app. WhatsApp announced the availability of a new feature called "Advanced Chat ...

Pierluigi Paganini April 24, 2025
Malware
Android spyware hidden in mapping software targets Russian soldiers

A new Android spyware was discovered in a fake Alpine Quest app, reportedly used by Russian soldiers for war zone planning. Doctor Web researchers uncovered a new spyware, tracked as Android.Spy.1 ...

Pierluigi Paganini April 24, 2025
Malware
Crypto mining campaign targets Docker environments with new evasion technique

New malware campaign targets Docker environments using unknown methods to secretly mine cryptocurrency, researchers warn. Researchers from Darktrace and Cado Security have spotted a malware campai ...

Pierluigi Paganini April 23, 2025
Hacking
The popular xrpl.js Ripple cryptocurrency library was compromised in a supply chain attack

The xrpl.js Ripple cryptocurrency library was compromised in a supply chain attack aimed at stealing users' private keys. Threat actors compromised the Ripple cryptocurrency npm JavaScript library ...

Pierluigi Paganini April 23, 2025
Hacking
British retailer giant Marks & Spencer (M&S) is managing a cyber incident

Marks & Spencer (M&S) confirmed it's managing a cyber incident after multiple customer complaints surfaced on social media. Marks and Spencer Group plc (M&S) announced it has been mana ...

Pierluigi Paganini April 23, 2025
Cyber Crime
Chinese Cybercriminals Released Z-NFC Tool for Payment Fraud

Cybercriminals leverage NFC fraud against ATMs and POS terminals, stealing money from consumers at scale. Resecurity (USA) investigated multiple incidents identified in Q1 2025, exceeding several ...

Pierluigi Paganini April 23, 2025
Data Breach
Millions of SK Telecom customers are potentially at risk following USIM data compromise

SK Telecom warned that threat actors accessed customer Universal Subscriber Identity Module (USIM) info through a malware attack. SK Telecom is South Korea’s largest wireless telecom company, a ...

Pierluigi Paganini April 22, 2025
Hacking
Japan ’s FSA warns of unauthorized trades via stolen credentials from fake security firms' sites

Japan ’s Financial Services Agency (FSA) warns of hundreds of millions in unauthorized trades linked to hacked brokerage accounts. Japan ’s Financial Services Agency (FSA) reported that the da ...

Pierluigi Paganini April 22, 2025
APT
Kimsuky APT exploited BlueKeep RDP flaw in attacks against South Korea and Japan

Researchers spotted a new North Korea-linked group Kimsuky 's campaign, exploiting a patched Microsoft Remote Desktop Services flaw to gain initial access. While investigating a security breach, t ...

Pierluigi Paganini April 21, 2025
Malware
New sophisticate malware SuperCard X targets Androids via NFC relay attacks

‘SuperCard X’ - a new MaaS - targets Androids via NFC relay attacks, enabling fraudulent POS and ATM transactions with stolen card data. Cleafy researchers discovered a new malware-as-a-servic ...

Pierluigi Paganini April 21, 2025
APT
Russia-linked APT29 targets European diplomatic entities with GRAPELOADER malware

Russia-linked group APT29 targeted diplomatic entities across Europe with a new malware loader codenamed GRAPELOADER. Check Point Research team reported that Russia-linked cyberespionage group APT ...

Pierluigi Paganini April 21, 2025
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 42

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malicious NPM Packages Targeting PayPal Users New Malware V ...

Pierluigi Paganini April 20, 2025
Breaking News
Security Affairs newsletter Round 520 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffair ...

Pierluigi Paganini April 20, 2025