LATEST NEWS

VIEW ALL
Vulnerability disclosed pwds of all Barracuda Network Employees
Pierluigi Paganini July 24, 2013

Security expert Ebrahim Hegazy has found a Password disclosure vulnerability in Barracuda update servers which allows to gain access to employee credentials. The cyber security Analyst @Qcert Ebrahi ...

Web Application Vulnerabilities 2013 - Context Information Security
Pierluigi Paganini July 24, 2013

Context Information Security  issued the report "Web Application Vulnerability Statistics 2013" that provides statistic on Web Application Vulnerabilities based on data gathered from a range of IT s ...

Researcher demonstrated SmartTV hacking on Samsung models
Pierluigi Paganini July 23, 2013

The researcher Malik Mesellem demonstrated that SmartTV hacking is a real menace, Samsung models could be forced to reboot sending an HTTP GET request It is known that smartTV hacking is a reality ...

Who has hacked the Apple iOS Developer Center?
Pierluigi Paganini July 23, 2013

After a weekend of outage and various mysterious password reset emails Apple has revealed that the iOS Developer Center was hacked. After 3 days of absolute silence of the voice of a possible hack to ...

recent articles

Data Breach
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is be ...

Pierluigi Paganini September 07, 2026
Uncategorized
StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed Style ...

Pierluigi Paganini September 07, 2026
Hacking
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and ...

Pierluigi Paganini September 07, 2026
Malware
JSCeal Hides Crypto Malware in V8 Bytecode

JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Re ...

Pierluigi Paganini September 07, 2026
Artificial Intelligence
Why AI Agent Sandboxes Are Failing Security Tests

Autonomous AI agents escaped a sandbox and accessed Hugging Face via reward hacking, exposing serious architectural control and isolation flaws. The recent case involving OpenAI test agents and Hu ...

Pierluigi Paganini September 07, 2026
Cyber Crime
Berlin Ransomware Leak Exposes State Secrets

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of st ...

Pierluigi Paganini September 07, 2026
Security
Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH ...

Pierluigi Paganini September 06, 2026
Artificial Intelligence
AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure

AI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm ...

Pierluigi Paganini September 06, 2026
Breaking News
Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 06, 2026
Artificial Intelligence
OpenAI Announced $1B in Defensive Tools for Water Utilities

OpenAI pledges $1B in subsidized Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, comm ...

Pierluigi Paganini September 05, 2026
Hacking
PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclos ...

Pierluigi Paganini September 05, 2026
Security
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities ...

Pierluigi Paganini September 05, 2026
Security
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ...

Pierluigi Paganini September 04, 2026
Data Breach
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted an ...

Pierluigi Paganini September 04, 2026
Security
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubb ...

Pierluigi Paganini September 04, 2026
Artificial Intelligence
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented ...

Pierluigi Paganini September 04, 2026
Security
Google fixes the sixth actively exploited Chrome zero-day of 2026

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vu ...

Pierluigi Paganini September 04, 2026
Security
Dark Web Service Nexus Sells 153M+ Driver's Licenses

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver's license scans. A dark web identity theft service called Nexus appeared on September 1, ...

Pierluigi Paganini September 04, 2026
Intelligence
Pegasus and NoviSpy Used Against Serbian Protesters

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia's student protest movement had their iPho ...

Pierluigi Paganini September 03, 2026
Security
Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-20 ...

Pierluigi Paganini September 03, 2026