LATEST NEWS

VIEW ALL
Fileless cryptocurrency miner CoinMiner uses NSA EternalBlue exploit to spread
Pierluigi Paganini August 22, 2017

A new fileless miner dubbed CoinMiner appeared in the wild, it uses NSA EternalBlue exploit and WMI tool to spread. A new strain of Cryptocurrency Miner dubbed CoinMiner appeared in the wild and a ...

Experts at ZDI reported two critical Zero-Day flaws in Foxit PDF Reader
Pierluigi Paganini August 22, 2017

Experts found two critical zero-day flaws in the Foxit PDF Reader that could be exploited by attackers to execute arbitrary code on a targeted computer Security researchers have discovered two crit ...

Ourmine hacked PlayStation Social Media Accounts to announce the theft of PSN Database
Pierluigi Paganini August 22, 2017

Ourmine hacker crew hijacked the official Twitter and Facebook accounts for Sony PlayStation Network (PSN) on Sunday and claims to have stolen PSN database. The dreaded Ourmine hacker crew is back, ...

Mr.Smith, HBO hackers threaten to leak final episode of Game of Thrones 7
Pierluigi Paganini August 21, 2017

The bad actors behind the HBO hack are back and are threatening to leak the final episode of the seventh season of Game of Thrones. The threat actor that has hacked into the HBO announced that it wil ...

recent articles

Security
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CIS ...

Pierluigi Paganini September 26, 2026
Hacking
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and ...

Pierluigi Paganini September 25, 2026
Cyber Crime
Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million

Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North ...

Pierluigi Paganini September 25, 2026
Malware
ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed thr ...

Pierluigi Paganini September 25, 2026
Malware
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been act ...

Pierluigi Paganini September 25, 2026
Hacking
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (C ...

Pierluigi Paganini September 25, 2026
Cyber Crime
Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison

Ryuk member Karen Vardanyan was sentenced to 24 months in U.S. prison after extradition from Ukraine and ordered to pay $1.2M in restitution. Karen Vardanyan, a 35-year-old Armenian citizen who we ...

Pierluigi Paganini September 24, 2026
Hacking
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS

MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 fo ...

Pierluigi Paganini September 24, 2026
Artificial Intelligence
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research

OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australi ...

Pierluigi Paganini September 24, 2026
Malware
CLOSEDQUORUM, the malware that asks four AI models what to do next

Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vot ...

Pierluigi Paganini September 24, 2026
Hacking
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. ...

Pierluigi Paganini September 23, 2026
Security
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerabi ...

Pierluigi Paganini September 23, 2026
Cyber Crime
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. F ...

Pierluigi Paganini September 23, 2026
Cyber Crime
EvilTokens made phishing-as-a-service look easy. Then it got taken down

Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fa ...

Pierluigi Paganini September 23, 2026
Malware
Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools

Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download ...

Pierluigi Paganini September 23, 2026
Hacking
CVE-2026-87902: how close is your WordPress to remote code execution?

WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unaut ...

Pierluigi Paganini September 23, 2026
Security
Check Point Fixes a New Actively Exploited Critical Security Flaw

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for C ...

Pierluigi Paganini September 22, 2026
Hacking
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIG ...

Pierluigi Paganini September 22, 2026
Security
Public PoC Exposes Critical Veeam Agent Privilege Escalation

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you're running Veeam Agent on a Windows endpoi ...

Pierluigi Paganini September 22, 2026
Hacking
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ...

Pierluigi Paganini September 22, 2026