LATEST NEWS

VIEW ALL
Indonesia Soon to Become the Fifth ASEAN Country to Adapt Data Privacy Laws
Pierluigi Paganini October 07, 2020

Earlier this year, Indonesia joined the ranks with the first four ASEAN countries including Malaysia, Singapore, Philippines and Thailand to have enacted laws relating to personal data protection. ...

New HEH botnet wipes devices potentially bricking them
Pierluigi Paganini October 07, 2020

A new botnet, tracked as HEH, discovered botnet implements a disk-wiping feature that allows it to wipe all data from the infected systems. Researchers from from Netlab, the network security divis ...

CISA alert warns of Emotet attacks on US govt entities
Pierluigi Paganini October 07, 2020

The CISA agency is warning of a surge in Emotet attacks targeting multiple state and local governments in the US since August. The Cybersecurity and Infrastructure Security Agency (CISA) issued an ...

Using a WordPress flaw to leverage Zerologon vulnerability and attack companies’ Domain Controllers
Pierluigi Paganini October 07, 2020

Using a WordPress flaw (File-Manager plugin–CVE-2020-25213) to leverage Zerologon (CVE-2020-1472) and attack companies’ Domain Controllers. Recently, a critical vulnerability called Zerologon ...

recent articles

APT
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it at ...

Pierluigi Paganini August 01, 2026
Security
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2 ...

Pierluigi Paganini August 01, 2026
APT
South Korea Warns of State-Backed Watering Hole Attacks

South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the Nat ...

Pierluigi Paganini July 31, 2026
Artificial Intelligence
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs

Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google's Chrome Security team published a detailed ac ...

Pierluigi Paganini July 31, 2026
Artificial Intelligence
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery

An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergo ...

Pierluigi Paganini July 31, 2026
Security
Anthropic Finds Claude Breached Real Companies During Security Evaluations

Anthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic disclosed that Claude models had accessed the rea ...

Pierluigi Paganini July 31, 2026
APT
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign

SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL documented a new SilverFox campaign target ...

Pierluigi Paganini July 31, 2026
Hacking
Why brand impersonation is becoming an initial access vector

Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites ...

Pierluigi Paganini July 30, 2026
Artificial Intelligence
Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents

Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as ...

Pierluigi Paganini July 30, 2026
Data Breach
Analog Devices Discloses Data Breach After Unauthorized System Access

Chipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data ...

Pierluigi Paganini July 30, 2026
Security
FCC Restricts New Foreign Robots and Inverters Over Security Risks

The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this ...

Pierluigi Paganini July 30, 2026
Security
U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and In ...

Pierluigi Paganini July 30, 2026
Security
eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds

Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps available in EU app stores, Nicegram, with o ...

Pierluigi Paganini July 30, 2026
Artificial Intelligence
Claude Mythos Shows AI Can Outpace Human Cryptography Research

Claude Mythos found new flaws in HAWK and reduced AES, proving AI can autonomously advance cryptography research. Anthropic published two cryptographic research results achieved by Claude Mythos P ...

Pierluigi Paganini July 29, 2026
Hacking
Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline

Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in ...

Pierluigi Paganini July 29, 2026
Data Breach
ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data

ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibi ...

Pierluigi Paganini July 29, 2026
Security
Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address f ...

Pierluigi Paganini July 29, 2026
Hacking
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach

OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached ...

Pierluigi Paganini July 29, 2026
Artificial Intelligence
OpenAI's Rogue AI Agent Breached Second Company, Report Says

Reuters says OpenAI's rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hack ...

Pierluigi Paganini July 29, 2026
Security
VPN Breach Exposes 58 Million Connection Logs Despite "No-Logs" Claims

A breached "no-logs" VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is d ...

Pierluigi Paganini July 29, 2026