LATEST NEWS

VIEW ALL
SpoofedMe attacks exploit popular websites social login flaws
Pierluigi Paganini December 06, 2014

The experts at IBM have found several problems in implementation of the social login authentication of several identity providers. The researchers at IBM's X Force security discovered a way to gain a ...

Op AURORAGOLD - NSA hacks cellphone networks worldwide
Pierluigi Paganini December 05, 2014

The Intercept revealed the Op AURORAGOLD run by the NSA to spy on hundreds of companies and organizations to hack cellphone networks worldwide. The Intercept has uncovered details of the operation ...

DeathRing, a new Pre-loaded mobile trojan in the wild
Pierluigi Paganini December 05, 2014

The number of Pre-loaded mobile trojan in the wild is increasing, DeathRing is the last one discovered by the experts at Lookout firm. It's not first the time that Android handsets come preloade ...

TrendMicro analyzed the wiper malware that infected Sony Pictures
Pierluigi Paganini December 04, 2014

TrendLabs has analyzed the Destructive malware mentioned in the FBI warnings recently issued and they have linked it to cyber attack against Sony Pictures. Researchers at TrendLabs announced that the ...

recent articles

Security
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed

Oracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed. This week, Defused Cyber researchers warned that a critical v ...

Pierluigi Paganini July 01, 2026
Uncategorized
Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs

81 Million Login Attempts, 78 Compromised Accounts: The LSHIY Password Spray Hitting Azure CLI Huntress researchers have been tracking a massive automated password spray campaign against Microsoft ...

Pierluigi Paganini July 01, 2026
Security
CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks

CISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-con ...

Pierluigi Paganini July 01, 2026
Malware
RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow

RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin's XLab ha ...

Pierluigi Paganini July 01, 2026
Artificial Intelligence
GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents

Researchers found a shell injection flaw in 10 of 11 popular open-source AI agents, allowing attackers to bypass command filters. Adversa AI just published a survey, titled "GuardFall: a universal ...

Pierluigi Paganini July 01, 2026
Security
XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn't

Police arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38- ...

Pierluigi Paganini June 30, 2026
Security
U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a SimpleHelp flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ( ...

Pierluigi Paganini June 30, 2026
Data Breach
Hackers Steal Data of 4.38 Million Aflac Japan Customers

Hackers stole data from 4.38 million Aflac Japan customers after accessing its systems for 10 days before the breach was detected. Aflac Japan disclosed that hackers stole the personal information ...

Pierluigi Paganini June 30, 2026
Security
Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools

Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, mac ...

Pierluigi Paganini June 30, 2026
Security
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817

Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments. A critical vulnerability in Oracle ...

Pierluigi Paganini June 30, 2026
Security
WhatsApp Usernames Are Coming. You Can Reserve Yours Right Now

WhatsApp will introduce usernames later this year, letting its 3 billion users connect without sharing phone numbers. WhatsApp has over three billion users, and it's finally letting them talk to e ...

Pierluigi Paganini June 29, 2026
Security
U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks

The U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists. The U.S. government is offering rewards of up to $10 million for ...

Pierluigi Paganini June 29, 2026
Malware
StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years

Microsoft shut down the StegoAd campaign, which used 119 malicious Edge extensions, hit 2.6M installs, and ran undetected for two years. Microsoft just shut down one of the more technically clever ...

Pierluigi Paganini June 29, 2026
Intelligence
SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel

Ukraine's SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years. The Security Service of Ukraine (SSU), working jointly with the FBI, has ...

Pierluigi Paganini June 29, 2026
Data Breach
KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs

KDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exp ...

Pierluigi Paganini June 28, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter More Than 4,000 Legacy Routers Compromis ...

Pierluigi Paganini June 28, 2026
Security
Security Affairs newsletter Round 583 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini June 28, 2026
Intelligence
New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages

FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian i ...

Pierluigi Paganini June 27, 2026
Uncategorized
Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails

Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed a ...

Pierluigi Paganini June 27, 2026
Uncategorized
DirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to Root

DirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on J ...

Pierluigi Paganini June 27, 2026