LATEST NEWS

VIEW ALL
Frequent VBA Macros used in Office Malware
Pierluigi Paganini October 01, 2019

The malware expert Marco Ramilli collected a small set of VBA Macros widely re-used to “weaponize” Maldoc (Malware Document) in cyber attacks. Nowadays one of the most frequent cybersecurity ...

Gucci IOT Bot Discovered Targeting European Region
Pierluigi Paganini October 01, 2019

Security Labs discovered a new IOT bot named “GUCCI”. It seems like the IOT botnet is named after an Italian luxury brand of fashion and leather goods. Analysis The discovery came to exi ...

Tridium Niagara framework affected by 2 flaws in BlackBerry QNX OS
Pierluigi Paganini October 01, 2019

Tridium’s Niagara product is affected by two vulnerabilities in BlackBerry’s QNX operating system for embedded devices. The U.S. Department of Homeland Security’s Cybersecurity and Infrastru ...

eGobbler 's malvertising campaign hijacked over 1 billion ad impressions
Pierluigi Paganini September 30, 2019

A recently observed a malvertising campaign carried out by a threat group dubbed eGobbler that hijacked roughly 1.16 billion ad impressions. Researchers at Confiant observed a malvertising campai ...

recent articles

Security
FCC Restricts New Foreign Robots and Inverters Over Security Risks

The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this ...

Pierluigi Paganini July 30, 2026
Security
U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and In ...

Pierluigi Paganini July 30, 2026
Security
eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds

Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps available in EU app stores, Nicegram, with o ...

Pierluigi Paganini July 30, 2026
Artificial Intelligence
Claude Mythos Shows AI Can Outpace Human Cryptography Research

Claude Mythos found new flaws in HAWK and reduced AES, proving AI can autonomously advance cryptography research. Anthropic published two cryptographic research results achieved by Claude Mythos P ...

Pierluigi Paganini July 29, 2026
Hacking
Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline

Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in ...

Pierluigi Paganini July 29, 2026
Data Breach
ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data

ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibi ...

Pierluigi Paganini July 29, 2026
Security
Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address f ...

Pierluigi Paganini July 29, 2026
Hacking
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach

OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached ...

Pierluigi Paganini July 29, 2026
Artificial Intelligence
OpenAI's Rogue AI Agent Breached Second Company, Report Says

Reuters says OpenAI's rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hack ...

Pierluigi Paganini July 29, 2026
Security
VPN Breach Exposes 58 Million Connection Logs Despite "No-Logs" Claims

A breached "no-logs" VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is d ...

Pierluigi Paganini July 29, 2026
Malware
Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure

Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China's CNCERT, disclosed Dysphoria, a bot ...

Pierluigi Paganini July 28, 2026
Security
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover

JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises ...

Pierluigi Paganini July 28, 2026
Malware
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide

Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint's research team traced a wave of income-tax-themed ...

Pierluigi Paganini July 28, 2026
Security
U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity an ...

Pierluigi Paganini July 28, 2026
Artificial Intelligence
Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected

Reuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Huggi ...

Pierluigi Paganini July 27, 2026
Malware
MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data

MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legi ...

Pierluigi Paganini July 27, 2026
Data Breach
DentaQuest disclosed a data breach that impacted +23 million individuals

DentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data br ...

Pierluigi Paganini July 27, 2026
Hacking
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain

Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code ...

Pierluigi Paganini July 27, 2026
Security
EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency

EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, a ...

Pierluigi Paganini July 27, 2026
Security
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations

A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and ...

Pierluigi Paganini July 27, 2026