LATEST NEWS

VIEW ALL
A regular GitHub user accidentally triggered a flaw Ethereum Parity Wallet that locked up $280 million in Ether
Pierluigi Paganini November 08, 2017

A GitHub user accidentally triggered a flaw in the Parity Wallet library contract of the standard multi-sig contract that locked up $280 million in Ether. Ethereum made again the headlines, someone ...

Symantec uncovered a new APT, the cyber espionage Sowbug group
Pierluigi Paganini November 08, 2017

Malware researchers from Symantec have spotted a new cyber espionage APT dubbed Sowbug group that has been active at least since 2015. A new cyber espionage group dubbed Sowbug appeared in the thre ...

Owners have found a built-in Keylogger in MantisTek GK2 Keyboards that send some data to China
Pierluigi Paganini November 07, 2017

One of the most popular Keyboards in the gaming industry, 104-key Mantistek GK2 Mechanical Gaming Keyboard send data back to China. A wrong keyboard could represent an entry point for any organizati ...

Vietnamese APT32 group is one of the most advanced APTs in the threat landscape
Pierluigi Paganini November 07, 2017

According to the incident response firm Volexity, Vietnamese APT32 group is today one of the most advanced APTs in the threat landscape According to the incident response firm Volexity, the cyber e ...

recent articles

Security
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabil ...

Pierluigi Paganini September 27, 2026
Artificial Intelligence
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, ...

Pierluigi Paganini September 27, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: ...

Pierluigi Paganini September 27, 2026
Breaking News
Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 27, 2026
Uncategorized
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools

Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo ...

Pierluigi Paganini September 27, 2026
Artificial Intelligence
OpenAI Agents Accessed US Government Websites Without Authorization

OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed on Friday that its AI agents had interacte ...

Pierluigi Paganini September 26, 2026
Cyber Crime
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Exploit.in data shows how a 2005 cybercrime forum helped shape today's ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database ...

Pierluigi Paganini September 26, 2026
Security
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CIS ...

Pierluigi Paganini September 26, 2026
Hacking
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and ...

Pierluigi Paganini September 25, 2026
Cyber Crime
Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million

Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North ...

Pierluigi Paganini September 25, 2026
Malware
ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed thr ...

Pierluigi Paganini September 25, 2026
Malware
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been act ...

Pierluigi Paganini September 25, 2026
Hacking
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (C ...

Pierluigi Paganini September 25, 2026
Cyber Crime
Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison

Ryuk member Karen Vardanyan was sentenced to 24 months in U.S. prison after extradition from Ukraine and ordered to pay $1.2M in restitution. Karen Vardanyan, a 35-year-old Armenian citizen who we ...

Pierluigi Paganini September 24, 2026
Hacking
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS

MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 fo ...

Pierluigi Paganini September 24, 2026
Artificial Intelligence
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research

OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australi ...

Pierluigi Paganini September 24, 2026
Malware
CLOSEDQUORUM, the malware that asks four AI models what to do next

Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vot ...

Pierluigi Paganini September 24, 2026
Hacking
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. ...

Pierluigi Paganini September 23, 2026
Security
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerabi ...

Pierluigi Paganini September 23, 2026
Cyber Crime
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. F ...

Pierluigi Paganini September 23, 2026