LATEST NEWS

VIEW ALL
Facebook Zeus malware targeting bank accounts
Pierluigi Paganini June 07, 2013

Principal security firms detected a new variant of Facebook Zeus malware that is exploiting the popular social network to target user's bank accounts. A Facebook Zeus malware variant (aka ZeuS/ZBO ...

NSA collecting phone records of millions of US citizens daily
Pierluigi Paganini June 06, 2013

The U.S. NSA is collecting phone records of millions of Verizon Communications customers, according to a secret court order obtained by the Guardian. The U.S. NSA is collecting phone records of mill ...

The business behind a cashout service for cybercriminals
Pierluigi Paganini June 06, 2013

An interesting post by Brian Krebs is food for thought on the business behind a cashout service for cybercriminals. Brian Krebs has recently published an interesting post on his KrebsOnSecurity blog ...

NetTraveler, new global cyber espionage campaign from Kaspersky
Pierluigi Paganini June 05, 2013

NetTraveler cyber espionage campaign, revealed by Kaspersky's team, targeted over 350 high profile victims from 40 countries. NetTraveler, this is the name of a new global cyber espionage campai ...

recent articles

Hacking
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score ...

Pierluigi Paganini August 13, 2026
Uncategorized
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infr ...

Pierluigi Paganini August 13, 2026
Hacking
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 ( ...

Pierluigi Paganini August 13, 2026
Malware
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Stor ...

Pierluigi Paganini August 13, 2026
Uncategorized
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave o ...

Pierluigi Paganini August 13, 2026
Data Breach
CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments

CEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA Logistics suffered a cyberattack on July 29 that d ...

Pierluigi Paganini August 12, 2026
APT
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented wh ...

Pierluigi Paganini August 12, 2026
Malware
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum

Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats fol ...

Pierluigi Paganini August 12, 2026
Security
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE

Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday securi ...

Pierluigi Paganini August 12, 2026
Hacking
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a cri ...

Pierluigi Paganini August 11, 2026
Security
ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad - ...

Pierluigi Paganini August 11, 2026
Hacking
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama

Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water ...

Pierluigi Paganini August 11, 2026
Artificial Intelligence
The inconvenient truth about AI pentesting: someone has to check all the work

AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a 'Sorcerer's Apprentice' problem. Enc ...

Pierluigi Paganini August 11, 2026
Security
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs

Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affe ...

Pierluigi Paganini August 11, 2026
Hacking
Gym Booking Task Turns Into Real-World AI Cyberattack

An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym cl ...

Pierluigi Paganini August 10, 2026
Security
Hackers Cross From IT to OT Through a Private APN in Poland

Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on ...

Pierluigi Paganini August 10, 2026
Cyber Crime
9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old

A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have bre ...

Pierluigi Paganini August 10, 2026
Artificial Intelligence
OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns

OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evalua ...

Pierluigi Paganini August 10, 2026
Artificial Intelligence
A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark

Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn't solving the puzzle, ...

Pierluigi Paganini August 10, 2026
Cyber Crime
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufa ...

Pierluigi Paganini August 09, 2026