Security Affairs newsletter Round 577 by Pierluigi Paganini – INTERNATIONAL EDITION

3 weeks ago

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs…

Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores

3 weeks ago

Attackers are exploiting a critical flaw in the WordPress Funnel Builder plugin to inject skimming code into WooCommerce checkout pages.…

Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total

4 weeks ago

Pwn2Own Berlin 2026 ended with 47 zero-days and $1.29M in payouts, as DEVCORE dominated the competition across all categories. Pwn2Own…

U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog

4 weeks ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities…

Russian APT Turla builds long-term access tool with Kazuar Botnet evolution

4 weeks ago

Russia-linked APT group Turla turned its Kazuar malware into a stealthy P2P botnet for long-term access to compromised systems. Russia-linked…

OpenAI hit by supply chain attack linked to malicious TanStack packages

4 weeks ago

OpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories. OpenAI confirmed that…

Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900K

4 weeks ago

Day two of Pwn2Own Berlin 2026 saw $385,750 earned for 15 zero-days, bringing the total to $908,750 and 39 vulnerabilities…

CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day

4 weeks ago

Microsoft warned that attackers are exploiting a new Exchange Server zero-day vulnerability, tracked as CVE-2026-42897, in the wild. Microsoft warned…

Ghostwriter group resumes attacks on Ukrainian Government targets

4 weeks ago

ESET uncovered new Ghostwriter (aka FrostyNeighbor) activity targeting Ukrainian government organizations in a campaign active since March 2026. ESET researchers…

This website uses cookies.