LATEST NEWS

VIEW ALL
Former DoE worker was hacking to steal nuclear secrets and resell them
Pierluigi Paganini February 04, 2016

A former Department of Energy (DoE) employee, Charles Harvey Eccleston [62], has been charged with trying to steal and sell nuclear secrets to foreign governments. A former employee at the Department ...

Europol, a new move against terrorism and money laundering
Pierluigi Paganini February 03, 2016

The Europol is increasing its efforts against terrorism, it has joined forces with EU to fight terrorist financing and money laundering. Since 1 January 2016, Europol has increased the level of inte ...

Comodo Chromodo Secure Internet Browser exposes you at risks
Pierluigi Paganini February 03, 2016

Security Expert discovered that the Comodo Chromodo browser has 'Same Origin Policy' (SOP) disabled by default, if you are using it you are at risk. Chromodo is the name of a free browser offered b ...

Cybersecurity Operational Tests And Assessments - US Defence can't check F-35 data due to insecure systems
Pierluigi Paganini February 03, 2016

Cybersecurity Operational Tests And Assessments conducted by the US Defence are essential to improve overall security ... and discover that US Govt can't check F-35 data due to insecure systems. It i ...

recent articles

Cyber Crime
Xsolis Data Breach Impacts 1.4 Million People

Xsolis disclosed a breach affecting 1.4M people after a phishing attack exposed personal and health data from its hospital clients’ systems. Healthcare tech company Xsolis, Inc. has disclosed a ...

Pierluigi Paganini June 23, 2026
Hacking
ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates

Attackers backdoored ShapedPlugin Pro updates, deploying malware that steals credentials, 2FA secrets, and grants full site access. If you installed a ShapedPlugin Pro plugin between April and Jun ...

Pierluigi Paganini June 23, 2026
Hacking
Squidbleed: 29-Year-Old Squid Bug Leaks User Credentials

Squidbleed is a 29-year-old Squid Proxy flaw that can leak credentials, tokens, and other users' HTTP data through a memory overread. Researchers at Calif.io have disclosed CVE-2026-47729, a memor ...

Pierluigi Paganini June 23, 2026
Malware
WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools

WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims' PCs. Kaspersky published a technical analysis this week of an ...

Pierluigi Paganini June 22, 2026
Data Breach
Texas Parks & Wildlife (TPWD) Data Breach impacts 3 Million People

Texas Parks and Wildlife Department (TPWD) breach exposed data of 3M people via a third-party license vendor, including sensitive personal information. The Texas Parks and Wildlife Department (TPW ...

Pierluigi Paganini June 22, 2026
Artificial Intelligence
Anthropic's Mythos AI broke into almost all NSA classified systems in hours

Senate testimony claims Anthropic's Mythos AI breached NSA and Cyber Command systems in hours, prompting a U.S.-ordered shutdown. On June 12, the Trump administration directed Anthropic to restric ...

Pierluigi Paganini June 22, 2026
Hacking
FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation

FortiBleed targeted 430,000+ FortiGate devices, harvesting 110M credentials and enabling breaches through large-scale credential theft. A new threat intelligence report from SOCRadar's Threat Rese ...

Pierluigi Paganini June 22, 2026
Security
4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware

AryStinger hijacks outdated routers via old flaws, turning 4,300+ devices into a stealth network for reconnaissance and intrusion support. On March 12, 2026, QiAnXin's XLab threat detection system ...

Pierluigi Paganini June 22, 2026
Hacking
usbliter8 Brings Unpatchable BootROM Exploit to Apple A12 and A13 Devices

usbliter8 is an unpatchable BootROM exploit affecting A12/A13 devices, enabling code execution and extending checkm8-like risks to newer iPhones. Security researchers at Paradigm Shift published a ...

Pierluigi Paganini June 22, 2026
Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter OptinMonster supply chain attack hits 1. ...

Pierluigi Paganini June 21, 2026
Uncategorized
Security Affairs newsletter Round 582 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini June 21, 2026
Malware
Inside GentleKiller: The EDR-Killer Powering The Gentlemen

The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks. ESET published a detailed breakdown of ...

Pierluigi Paganini June 20, 2026
Hacking
FortiBleed Exposes Global Credential-Spraying Operation

FortiBleed exposed a massive campaign that made billions of login attempts against Fortinet VPNs, compromising organizations worldwide. FortiBleed wasn't a targeted hack. It was a factory. A multi ...

Pierluigi Paganini June 20, 2026
Hacking
CISA Warns of Active Exploitation Following FortiBleed Leak

FortiBleed exposed credentials for 74,000 Fortinet devices, with attackers actively exploiting the leak to target systems worldwide. On June 18, CISA issued an emergency alert after reports surfac ...

Pierluigi Paganini June 20, 2026
Malware
14,971 WordPress Sites Cleaned in Global SocGholish Takedown

Operation EndGame disrupted SocGholish, taking down 106 servers and cleaning 14,971 WordPress sites used to spread fake-update malware. On June 18, 2026, law enforcement agencies from the Netherla ...

Pierluigi Paganini June 19, 2026
Security
U.S. CISA adds Splunk Enterprise flaw to its Known Exploited Vulnerabilities catalog and urges agencies to fix it by Sunday

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Splunk Enterprise flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ...

Pierluigi Paganini June 19, 2026
Intelligence
Peter Thiel 's Secret Society Leak Creates a Perfect Target List for Espionage, Influence Operations, and Blackmail

A simple website flaw exposed members, political profiles, login tokens, and dating data from Peter Thiel 's secretive Dialog network. Dialog, a private invitation-only organization cofounded in 2 ...

Pierluigi Paganini June 19, 2026
Security
24 Billion Stolen Credentials Exposed in Massive Data Leak

24 Billion Records Left Open Online: Passwords, Emails, and Everything Else Exposed database with 24 Billion records revealed stolen credentials from infostealers, Telegram channels, and breach co ...

Pierluigi Paganini June 19, 2026
Security
Cisco fixed a critical ISE vulnerability that lets attackers to gain root access

Cisco addressed CVE-2026-20181, a critical ISE vulnerability that lets authenticated admins execute commands and gain root access. Cisco addressed a critical command execution vulnerability, track ...

Pierluigi Paganini June 18, 2026
Security
F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code Execution

F5 released emergency updates for critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) that could enable unauthenticated code execution. F5 has issued out-of-band patches for multiple NGINX vulne ...

Pierluigi Paganini June 18, 2026