LATEST NEWS

VIEW ALL
VMware fixed five memory corruption issues in vCenter Server
Pierluigi Paganini June 23, 2023

VMware addressed multiple memory corruption vulnerabilities in vCenter Server that can be exploited to achieve remote code execution. VMware released security updates to five memory corruption vul ...

Fortinet fixes critical FortiNAC RCE, install updates asap
Pierluigi Paganini June 23, 2023

Fortinet addressed a critical remote command execution vulnerability, tracked as CVE-2023-33299, affecting FortiNAC solution. FortiNAC is a network access control (NAC) solution designed by Fortin ...

More than a million GitHub repositories potentially vulnerable to RepoJacking
Pierluigi Paganini June 23, 2023

Researchers reported that millions of GitHub repositories are likely vulnerable to an attack called RepoJacking. A study conducted by Aqua researchers revealed that millions of GitHub repositories ...

New Mirai botnet targets tens of flaws in popular IoT devices
Pierluigi Paganini June 22, 2023

Since March 2023, Unit 42 researchers have observed a variant of the Mirai botnet spreading by targeting tens of flaws in D-Link, Zyxel, and Netgear devices. Since March 2023, researchers at Palo ...

recent articles

Hacking
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a cri ...

Pierluigi Paganini August 11, 2026
Security
ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad - ...

Pierluigi Paganini August 11, 2026
Hacking
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama

Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water ...

Pierluigi Paganini August 11, 2026
Artificial Intelligence
The inconvenient truth about AI pentesting: someone has to check all the work

AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a 'Sorcerer's Apprentice' problem. Enc ...

Pierluigi Paganini August 11, 2026
Security
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs

Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affe ...

Pierluigi Paganini August 11, 2026
Hacking
Gym Booking Task Turns Into Real-World AI Cyberattack

An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym cl ...

Pierluigi Paganini August 10, 2026
Security
Hackers Cross From IT to OT Through a Private APN in Poland

Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on ...

Pierluigi Paganini August 10, 2026
Cyber Crime
9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old

A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have bre ...

Pierluigi Paganini August 10, 2026
Artificial Intelligence
OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns

OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evalua ...

Pierluigi Paganini August 10, 2026
Artificial Intelligence
A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark

Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn't solving the puzzle, ...

Pierluigi Paganini August 10, 2026
Cyber Crime
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufa ...

Pierluigi Paganini August 09, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful ...

Pierluigi Paganini August 09, 2026
Security
Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini August 09, 2026
Hacking
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that ...

Pierluigi Paganini August 09, 2026
Intelligence
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) ann ...

Pierluigi Paganini August 08, 2026
Hacking
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor w ...

Pierluigi Paganini August 08, 2026
Hacking
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Secu ...

Pierluigi Paganini August 08, 2026
Data Breach
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems' data center. Unlimited Technology Systems disclosed a data breach affecting more than 3 ...

Pierluigi Paganini August 08, 2026
Hacking
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they're call ...

Pierluigi Paganini August 07, 2026
Security
Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, an ...

Pierluigi Paganini August 07, 2026