LATEST NEWS

VIEW ALL
VMware fixed a flaw in Avi Load Balancer
Pierluigi Paganini January 28, 2025

VMware fixed a high-risk blind SQL injection vulnerability in Avi Load Balancer, allowing attackers to exploit databases via crafted queries. VMware warns of a high-risk blind SQL injection vulner ...

Ransomware attack on ENGlobal compromised personal information
Pierluigi Paganini January 28, 2025

ENGlobal reported to the SEC that personal information was compromised in a ransomware attack that took place in November 2024. ENGlobal disclosed a ransomware attack that occurred in November, i ...

EU announced sanctions on three members of Russia's GRU Unit 29155
Pierluigi Paganini January 28, 2025

The EU sanctioned three members of Russia's GRU Unit 29155 for cyberattacks on Estonia's government agencies in 2020. The European Union announced sanctions for three members (Nikolay Korchagin, V ...

Chinese AI platform DeepSeek faced a "large-scale" cyberattack
Pierluigi Paganini January 28, 2025

Chinese AI company DeepSeek has disabled registrations for its DeepSeek-V3 chat platform following a "large-scale" cyberattack. DeepSeek has designed a new AI platform that quickly gained attentio ...

recent articles

Data Breach
'Korea’s Amazon' Coupang discloses a data breach impacting 34M customers

Coupang disclosed a five-month data breach that exposed the personal information of nearly 34 million South Korean customers. South Korean e-commerce giant disclosed a data breach affecting nearly ...

Pierluigi Paganini December 02, 2025
Security
Google’s latest Android security update fixes two actively exploited flaws

Google’s latest Android security update fixes 107 flaws across multiple components, including two vulnerabilities actively exploited in the wild. Google’s new Android update patches 107 vulner ...

Pierluigi Paganini December 02, 2025
Cyber Crime
Law enforcement shuts down Cryptomixer in major crypto crime takedown

Authorities seized $29M in Bitcoin after takedown of Cryptomixer, a service used to launder cybercrime proceeds. Europol announced the seizure of $29M in Bitcoin after shutting down Cryptomixer, a ...

Pierluigi Paganini December 02, 2025
Cyber Crime
Australian man jailed for 7+ years over airport and in-flight Wi-Fi attacks

Australian Michael Clapsis got 7 years and 4 months in prison for Wi-Fi attacks at airports and on flights, stealing sensitive data. Australian man Michael Clapsis (44) was sentenced to 7 years an ...

Pierluigi Paganini December 01, 2025
Malware
Emerging Android threat ‘Albiriox’ enables full On‑Device Fraud

Albiriox is new Android MaaS malware enabling on-device fraud and real-time control. It targets 400+ banking, fintech, crypto, and payment apps. Albiriox is a new Android malware sold under a malw ...

Pierluigi Paganini December 01, 2025
Security
U.S. CISA adds an OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ...

Pierluigi Paganini December 01, 2025
Uncategorized
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 73

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Analysis of ShadowPad Attack Exploiting ...

Pierluigi Paganini November 30, 2025
Breaking News
Security Affairs newsletter Round 552 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini November 30, 2025
APT
Contagious Interview campaign expands with 197 npm Ppackages spreading new OtterCookie malware

North Korea-linked actors behind Contagious Interview uploaded 197 new malicious npm packages to distribute a new OtterCookie malware version. North Korea-linked threat actors added 197 new malici ...

Pierluigi Paganini November 30, 2025
Data Breach
Attackers stole member data from French Soccer Federation

The French Soccer Federation (FFF) disclosed a data breach after hackers used a compromised account to steal member data. A compromised account allowed attackers to breach the French Soccer Federa ...

Pierluigi Paganini November 28, 2025
Security
Thousands of sensitive secrets published on JSONFormatter and CodeBeautify

Users of JSONFormatter and CodeBeautify leaked thousands of sensitive secrets, including credentials and private keys, WatchTowr warns. WatchTowr’s latest research reveals massive leaks of passw ...

Pierluigi Paganini November 28, 2025
Malware
New Mirai variant ShadowV2 tests IoT exploits amid AWS disruption

ShadowV2, a new Mirai-based botnet, briefly targeted vulnerable IoT devices during October’s AWS outage, likely as a test run. During the late-October AWS disruption, FortiGuard Labs researchers ...

Pierluigi Paganini November 28, 2025
Data Breach
Asahi says crooks stole data of approximately 2M customers and employees

Asahi says hackers stole data of approximately 2M customers and employees before a ransomware attack crippled its Japan operations. Threat actors hit Asahi with a ransomware attack in September, s ...

Pierluigi Paganini November 27, 2025
Data Breach
OpenAI data may have been exposed after a cyberattack on analytics firm Mixpanel

OpenAI warns some users that a cyberattack on analytics firm Mixpanel may have exposed their data. Mixpanel is a product analytics platform that companies use to understand how people interact wi ...

Pierluigi Paganini November 27, 2025
Internet of Things
New ASUS firmware patches critical AiCloud vulnerability

ASUS released new firmware to address multiple vulnerabilities, including a critical authentication bypass flaw in routers with AiCloud enabled. ASUS has issued new firmware addressing nine securi ...

Pierluigi Paganini November 27, 2025
Security
For the first time, a RomCom payload has been observed being distributed via SocGholish

RomCom malware used the SocGholish fake update loader to deliver Mythic Agent to a U.S. civil engineering firm. In September 2025, Arctic Wolf Labs observed RomCom threat actors delivering the Myt ...

Pierluigi Paganini November 26, 2025
Security
Multiple London councils faced a cyberattack

Multiple London councils, including Chelsea and Westminster, faced a cyberattack that may have exposed resident data. Authorities are actively investigating the incident. A cyberattack struck mult ...

Pierluigi Paganini November 26, 2025
Cyber Crime
Emergency alerts go dark after cyberattack on OnSolve CodeRED

Cyberattack on OnSolve CodeRED disrupted emergency alert services for U.S. state, local, police, and fire agencies. A cyberattack on the OnSolve CodeRED alert platform disrupted emergency notifica ...

Pierluigi Paganini November 26, 2025
Cyber Crime
Dissecting a new malspam chain delivering Purelogs infostealer

The AISI Research Center's Cybersecurity Observatory publishes the report "Dissecting a new malspam chain delivering Purelogs infostealer" - November 25, 2025. Organizational and personal security ...

Pierluigi Paganini November 26, 2025
Cyber Crime
FBI: bank impersonators fuel $262M surge in account takeover fraud

Cybercriminals posing as banks drove a major spike in account takeover fraud this year, stealing over $262 million, the FBI warned. The FBI warns of a surge in account takeover fraud, with crimina ...

Pierluigi Paganini November 25, 2025