LATEST NEWS

VIEW ALL
A zero-day exploit for Log4j Java library could have a tsunami impact on IT giants
Pierluigi Paganini December 10, 2021

Experts publicly disclose Proof-of-concept exploits for a critical zero-day vulnerability in the Apache Log4j Java-based logging library. Experts publicly disclose Proof-of-concept exploits for a ...

1.6 million WordPress sites targeted in the last couple of days
Pierluigi Paganini December 10, 2021

Wordfence experts detected a massive wave of attacks in the last couple of days that targeted over 1.6 million WordPress sites. Wordfence researchers spotted a massive wave of atta ...

BlackCat ransomware, a very sophisticated malware written in Rust
Pierluigi Paganini December 10, 2021

BlackCat is the first professional ransomware strain that was written in the Rust programming language, researchers reported. Malware researchers from Recorded Future and MalwareHunterTeam discov ...

Dark Mirai botnet spreads targeting RCE on TP-Link routers
Pierluigi Paganini December 09, 2021

A botnet tracked as Dark Mirai spreads by exploiting a new vulnerability affecting TP-Link TL-WR840N EU V5 home routers. Dark Mirai botnet spreads by exploiting a new vulnerability, tracked as CVE ...

recent articles

Security
Check Point Fixes a New Actively Exploited Critical Security Flaw

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for C ...

Pierluigi Paganini September 22, 2026
Hacking
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIG ...

Pierluigi Paganini September 22, 2026
Security
Public PoC Exposes Critical Veeam Agent Privilege Escalation

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you're running Veeam Agent on a Windows endpoi ...

Pierluigi Paganini September 22, 2026
Hacking
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ...

Pierluigi Paganini September 22, 2026
Uncategorized
Contagious Interview: 30,000 devices infected by a fake job interview

North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan's National Police Agency, the FBI, the US Depa ...

Pierluigi Paganini September 22, 2026
Laws and regulations
Google Fined €403 Million Over Location Data Practices

Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland's Data Protection Commission (DPC) just fined Google € ...

Pierluigi Paganini September 21, 2026
ICS-SCADA
Foreign Hackers Target Two Colorado Water Utilities

Hackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT ...

Pierluigi Paganini September 21, 2026
Malware
ChainScript: the RAT that hides its command server inside a blockchain contract

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint's Adversary Pursuit Group was chasing a ClickFix campaign spr ...

Pierluigi Paganini September 21, 2026
Hacking
A BYD Shark 6 Hack Shows the Risks of Connected Cars

A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country ro ...

Pierluigi Paganini September 21, 2026
Artificial Intelligence
The Target Is No Longer the Model. It’s the Agent.

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single m ...

Pierluigi Paganini September 21, 2026
Uncategorized
UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then ...

Pierluigi Paganini September 21, 2026
Security
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CIS ...

Pierluigi Paganini September 20, 2026
Artificial Intelligence
AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the ep ...

Pierluigi Paganini September 20, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click ...

Pierluigi Paganini September 20, 2026
Security
Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 20, 2026
Artificial Intelligence
Google Gemini also Broke Out of Its Test Environment

Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into ...

Pierluigi Paganini September 19, 2026
Artificial Intelligence
AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Cod ...

Pierluigi Paganini September 19, 2026
Hacking
Brevo Supply-Chain Attack Infected Over 100,000 Websites

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-bas ...

Pierluigi Paganini September 18, 2026
Data Breach
Gyazo Data Breach Exposes 23 Million User Records

A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a da ...

Pierluigi Paganini September 18, 2026
Malware
RatHat Turns Android Accessibility Into an Attack Weapon

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know ...

Pierluigi Paganini September 18, 2026