LATEST NEWS

VIEW ALL
Exclusive: MalwareMustDie analyzes a new IoT malware dubbed Linux/ AirDropBot
Pierluigi Paganini September 30, 2019

After 2 years of waiting, MalwareMustDie returns with an excellent page of malware analysis of a new IoT malware: Linux/AirDropBot. Yes, I have to confess, it was hard to wait all this time, but t ...

Iran's oil minister orders 'Full Alert' for oil sector on against attacks
Pierluigi Paganini September 30, 2019

Iran 's oil minister on Sunday ordered representatives of the energy sector to be on 'full alert' to the threat of "physical and cyber" attacks. Iran's oil minister, Bijan Namdar Zanganeh, ordered ...

Arcane Stealer V, a threat for lower-skilled adversaries that scares experts
Pierluigi Paganini September 30, 2019

Experts recently analyzed an information-stealing malware tracked as Arcane Stealer V that is very cheap and easy to buy in the Dark Web. In July 2019, researchers at Fidelis Threat Research Team ...

Microsoft will add new file types to the list of blocked ones in Outlook on the Web
Pierluigi Paganini September 30, 2019

Microsoft announced last week it is going to expand the list of file extensions that are blocked in Outlook on the web. Microsoft announced that it will immediately block other file extensions for ...

recent articles

Artificial Intelligence
OpenAI Announced $1B in Defensive Tools for Water Utilities

OpenAI pledges $1B in subsidized Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, comm ...

Pierluigi Paganini September 05, 2026
Hacking
PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclos ...

Pierluigi Paganini September 05, 2026
Security
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities ...

Pierluigi Paganini September 05, 2026
Security
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ...

Pierluigi Paganini September 04, 2026
Data Breach
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted an ...

Pierluigi Paganini September 04, 2026
Security
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubb ...

Pierluigi Paganini September 04, 2026
Artificial Intelligence
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented ...

Pierluigi Paganini September 04, 2026
Security
Google fixes the sixth actively exploited Chrome zero-day of 2026

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vu ...

Pierluigi Paganini September 04, 2026
Security
Dark Web Service Nexus Sells 153M+ Driver's Licenses

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver's license scans. A dark web identity theft service called Nexus appeared on September 1, ...

Pierluigi Paganini September 04, 2026
Intelligence
Pegasus and NoviSpy Used Against Serbian Protesters

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia's student protest movement had their iPho ...

Pierluigi Paganini September 03, 2026
Security
Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-20 ...

Pierluigi Paganini September 03, 2026
Data Breach
412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-tradin ...

Pierluigi Paganini September 03, 2026
Hacking
Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, M ...

Pierluigi Paganini September 03, 2026
Intelligence
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

2,000 leaked files expose Bauman University's hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University's ...

Pierluigi Paganini September 03, 2026
Artificial Intelligence
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI

OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersec ...

Pierluigi Paganini September 02, 2026
Security
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs

SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in i ...

Pierluigi Paganini September 02, 2026
APT
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware

Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely ...

Pierluigi Paganini September 02, 2026
Hacking
Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tr ...

Pierluigi Paganini September 02, 2026
Data Breach
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company ...

Pierluigi Paganini September 01, 2026
Hacking
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIG ...

Pierluigi Paganini September 01, 2026