LATEST NEWS

VIEW ALL
China arrested hackers responding to a US Government request
Pierluigi Paganini October 11, 2015

For the first time, hackers have been arrested in China by law enforcement at the behest of the US government. Is it true cooperation? It is probably the first time that Chinese authorities have ...

The Dark web - Why the hidden part of the web is even more dangerous?
Pierluigi Paganini October 11, 2015

Cyber Threat Summit 2015 - Study on criminal activities in the dark web.  "The Dark web - Why the hidden part of the web is even more dangerous?" Also, this year I have participated as a speaker t ...

The Dow Jones firm confirmed data breach of 3,500 Users
Pierluigi Paganini October 11, 2015

The Dow Jones firm confirmed to have suffered a data breach, payment card and contact info for less than 3,500 users have been exposed. At the end of the last week, the CEO of Dow Jones & Co di ...

Cost of Breaking SHA-1 decreases due to a new Collision Attack
Pierluigi Paganini October 10, 2015

A group of researchers has demonstrated that the cost of breaking the SHA-1 hash algorithm is lower than previously estimated. The SHA-1 is still one of the most used cryptographic hash algorithm, bu ...

recent articles

Security
Check Point Fixes a New Actively Exploited Critical Security Flaw

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for C ...

Pierluigi Paganini September 22, 2026
Hacking
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIG ...

Pierluigi Paganini September 22, 2026
Security
Public PoC Exposes Critical Veeam Agent Privilege Escalation

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you're running Veeam Agent on a Windows endpoi ...

Pierluigi Paganini September 22, 2026
Hacking
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ...

Pierluigi Paganini September 22, 2026
Uncategorized
Contagious Interview: 30,000 devices infected by a fake job interview

North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan's National Police Agency, the FBI, the US Depa ...

Pierluigi Paganini September 22, 2026
Laws and regulations
Google Fined €403 Million Over Location Data Practices

Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland's Data Protection Commission (DPC) just fined Google € ...

Pierluigi Paganini September 21, 2026
ICS-SCADA
Foreign Hackers Target Two Colorado Water Utilities

Hackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT ...

Pierluigi Paganini September 21, 2026
Malware
ChainScript: the RAT that hides its command server inside a blockchain contract

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint's Adversary Pursuit Group was chasing a ClickFix campaign spr ...

Pierluigi Paganini September 21, 2026
Hacking
A BYD Shark 6 Hack Shows the Risks of Connected Cars

A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country ro ...

Pierluigi Paganini September 21, 2026
Artificial Intelligence
The Target Is No Longer the Model. It’s the Agent.

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single m ...

Pierluigi Paganini September 21, 2026
Uncategorized
UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then ...

Pierluigi Paganini September 21, 2026
Security
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CIS ...

Pierluigi Paganini September 20, 2026
Artificial Intelligence
AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the ep ...

Pierluigi Paganini September 20, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click ...

Pierluigi Paganini September 20, 2026
Security
Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 20, 2026
Artificial Intelligence
Google Gemini also Broke Out of Its Test Environment

Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into ...

Pierluigi Paganini September 19, 2026
Artificial Intelligence
AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Cod ...

Pierluigi Paganini September 19, 2026
Hacking
Brevo Supply-Chain Attack Infected Over 100,000 Websites

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-bas ...

Pierluigi Paganini September 18, 2026
Data Breach
Gyazo Data Breach Exposes 23 Million User Records

A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a da ...

Pierluigi Paganini September 18, 2026
Malware
RatHat Turns Android Accessibility Into an Attack Weapon

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know ...

Pierluigi Paganini September 18, 2026