LATEST NEWS

VIEW ALL
Researcher discloses VirtualBox Zero-Day without reporting it to Oracle
Pierluigi Paganini November 07, 2018

Security expert disclosed the details of a zero-day flaw affecting Oracle’s VirtualBox virtualization software without waiting for a patch from Oracle The security expert Sergey Zelenyuk has discl ...

HSBC Bank USA notified customers of a security breach
Pierluigi Paganini November 07, 2018

HSBC Bank USA notified customers of a data breach that has happened between Oct 4 and Oct 14, unknown attackers were able to access their online accounts. HSBC Bank USA notified customers of a dat ...

Apache Struts users have to update FileUpload library to fix years-old flaws
Pierluigi Paganini November 07, 2018

Apache Struts Users have to update the Commons FileUpload library in Struts 2 that is affected by two vulnerabilities. Apache Struts developers have addressed two vulnerabilities in the Commons ...

Group-IB and CryptoIns introduce the world’s first insurance against cyber threats for cryptocurrency exchanges
Pierluigi Paganini November 06, 2018

Group-IB and Swiss insurance broker ASPIS that owns CryptoIns project, have developed the world’s first scoring model for assessing cryptocurrency exchanges Group-IB, an international company  ...

recent articles

Artificial Intelligence
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research

OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australi ...

Pierluigi Paganini September 24, 2026
Malware
CLOSEDQUORUM, the malware that asks four AI models what to do next

Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vot ...

Pierluigi Paganini September 24, 2026
Hacking
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. ...

Pierluigi Paganini September 23, 2026
Security
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerabi ...

Pierluigi Paganini September 23, 2026
Cyber Crime
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. F ...

Pierluigi Paganini September 23, 2026
Cyber Crime
EvilTokens made phishing-as-a-service look easy. Then it got taken down

Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fa ...

Pierluigi Paganini September 23, 2026
Malware
Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools

Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download ...

Pierluigi Paganini September 23, 2026
Hacking
CVE-2026-87902: how close is your WordPress to remote code execution?

WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unaut ...

Pierluigi Paganini September 23, 2026
Security
Check Point Fixes a New Actively Exploited Critical Security Flaw

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for C ...

Pierluigi Paganini September 22, 2026
Hacking
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIG ...

Pierluigi Paganini September 22, 2026
Security
Public PoC Exposes Critical Veeam Agent Privilege Escalation

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you're running Veeam Agent on a Windows endpoi ...

Pierluigi Paganini September 22, 2026
Hacking
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ...

Pierluigi Paganini September 22, 2026
Uncategorized
Contagious Interview: 30,000 devices infected by a fake job interview

North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan's National Police Agency, the FBI, the US Depa ...

Pierluigi Paganini September 22, 2026
Laws and regulations
Google Fined €403 Million Over Location Data Practices

Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland's Data Protection Commission (DPC) just fined Google € ...

Pierluigi Paganini September 21, 2026
ICS-SCADA
Foreign Hackers Target Two Colorado Water Utilities

Hackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT ...

Pierluigi Paganini September 21, 2026
Malware
ChainScript: the RAT that hides its command server inside a blockchain contract

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint's Adversary Pursuit Group was chasing a ClickFix campaign spr ...

Pierluigi Paganini September 21, 2026
Hacking
A BYD Shark 6 Hack Shows the Risks of Connected Cars

A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country ro ...

Pierluigi Paganini September 21, 2026
Artificial Intelligence
The Target Is No Longer the Model. It’s the Agent.

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single m ...

Pierluigi Paganini September 21, 2026
Uncategorized
UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then ...

Pierluigi Paganini September 21, 2026
Security
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CIS ...

Pierluigi Paganini September 20, 2026