LATEST NEWS

VIEW ALL
Marcus Hutchins sentenced to supervised release, no jail for the expert
Pierluigi Paganini July 27, 2019

Marcus Hutchins has been sentenced to "time served" and one year of supervised release his role in developing and selling the Kronos banking malware. The popular researcher Marcus Hutchins, also k ...

A flaw in LibreOffice could allow the hack of your PC
Pierluigi Paganini July 26, 2019

LibreOffice users have to know that their unpatched computers could be hacked by simply opening a specially crafted document. Bad news for LibreOffice users, the popular free and open-source offic ...

Irish Silk Road admin sentenced to 78 months in federal prison
Pierluigi Paganini July 26, 2019

An Irish national has been sentenced to 78 months in jail for his role as one of the administrators and forum moderators of Silk Road dark web marketplace. Gary Davis (31), of Wicklow, Ireland, ha ...

Johannesburg residents left in the dark after a ransomware attack at City Power
Pierluigi Paganini July 26, 2019

South African electric utility City Power that provides energy to the city of Johannesburg, has suffered serious disruptions after a ransomware attack. A ransomware infected systems at City Power, ...

recent articles

Data Breach
412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-tradin ...

Pierluigi Paganini September 03, 2026
Hacking
Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, M ...

Pierluigi Paganini September 03, 2026
Intelligence
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

2,000 leaked files expose Bauman University's hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University's ...

Pierluigi Paganini September 03, 2026
Artificial Intelligence
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI

OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersec ...

Pierluigi Paganini September 02, 2026
Security
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs

SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in i ...

Pierluigi Paganini September 02, 2026
APT
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware

Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely ...

Pierluigi Paganini September 02, 2026
Hacking
Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tr ...

Pierluigi Paganini September 02, 2026
Data Breach
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company ...

Pierluigi Paganini September 01, 2026
Hacking
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIG ...

Pierluigi Paganini September 01, 2026
Cyber Crime
Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt

Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty ...

Pierluigi Paganini September 01, 2026
APT
North Korea-linked IT Workers Are Getting Hired Inside Western Companies

Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea ...

Pierluigi Paganini September 01, 2026
Hacking
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also kn ...

Pierluigi Paganini September 01, 2026
Security
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CI ...

Pierluigi Paganini September 01, 2026
Security
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn't always need to disguise itself as ...

Pierluigi Paganini August 31, 2026
APT
China-linked Fire Ant Hides Inside Trusted Infrastructure

Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has ...

Pierluigi Paganini August 31, 2026
Artificial Intelligence
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions

Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malwar ...

Pierluigi Paganini August 31, 2026
Security
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers

A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely use ...

Pierluigi Paganini August 31, 2026
Cyber Crime
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a dat ...

Pierluigi Paganini August 30, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor ...

Pierluigi Paganini August 30, 2026
Uncategorized
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in sc ...

Pierluigi Paganini August 30, 2026