LATEST NEWS

VIEW ALL
Valve is going to fix a serious vulnerability in Steam online gaming platform
Pierluigi Paganini February 08, 2017

The online game platform Steam is fixing a serious bug that could be exploited to redirect users to malicious websites and take over their profile. The popular online game platform Steam is going t ...

Smart TV vendor Vizio fined $2.2M for spying on 11 million customers
Pierluigi Paganini February 08, 2017

Smart TV vendor Vizio makes the headlines because it has been caught while secretly collecting consumers' data through over 11 Million devices. IoT devices are privileged vectors for surveillance act ...

WordPress content injection flaw abused in defacement campaigns
Pierluigi Paganini February 07, 2017

According to experts at the security firm Sucuri, a critical content injection flaw in WordPress recently disclosed has already been exploited to deface thousands of websites. Recently a critical vu ...

76 Popular iOS apps are vulnerable to man-in-the-middle (MITM) attacks
Pierluigi Paganini February 07, 2017

A study conducted on iOS mobile apps revealed that many of them are affected by security vulnerabilities that expose users to man-in-the-middle (MitM) attacks. A new study confirms that dozens of iO ...

recent articles

Data Breach
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company ...

Pierluigi Paganini September 01, 2026
Hacking
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIG ...

Pierluigi Paganini September 01, 2026
Cyber Crime
Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt

Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty ...

Pierluigi Paganini September 01, 2026
APT
North Korea-linked IT Workers Are Getting Hired Inside Western Companies

Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea ...

Pierluigi Paganini September 01, 2026
Hacking
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also kn ...

Pierluigi Paganini September 01, 2026
Security
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CI ...

Pierluigi Paganini September 01, 2026
Security
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn't always need to disguise itself as ...

Pierluigi Paganini August 31, 2026
APT
China-linked Fire Ant Hides Inside Trusted Infrastructure

Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has ...

Pierluigi Paganini August 31, 2026
Artificial Intelligence
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions

Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malwar ...

Pierluigi Paganini August 31, 2026
Security
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers

A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely use ...

Pierluigi Paganini August 31, 2026
Cyber Crime
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a dat ...

Pierluigi Paganini August 30, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor ...

Pierluigi Paganini August 30, 2026
Uncategorized
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in sc ...

Pierluigi Paganini August 30, 2026
Security
Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini August 30, 2026
Hacking
Hack One Robot, Reach the Next: Unitree G1 Security Flaws

A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months ...

Pierluigi Paganini August 29, 2026
Cyber Crime
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

Berlin 's government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin's state government confirmed this week it ...

Pierluigi Paganini August 29, 2026
Intelligence
Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nucl ...

Pierluigi Paganini August 29, 2026
Data Breach
Love Electric Breach: 877,000 Driver Records Offered for $600

Love Electric's alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach f ...

Pierluigi Paganini August 28, 2026
Security
Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technolo ...

Pierluigi Paganini August 28, 2026
Hacking
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Inf ...

Pierluigi Paganini August 28, 2026