LATEST NEWS

VIEW ALL
Meteor was the wiper used against Iran’s national railway system
Pierluigi Paganini July 30, 2021

The recent attack against Iran’s national railway system was caused by a wiper malware dubbed Meteor and not by a ransomware as initially thought. According to research from ...

BlackMatter and Haron, two new ransomware gangs in the threat landscape
Pierluigi Paganini July 29, 2021

The cyber threat landscape change continuously, recently two new ransomware-as-service (RaaS) operations named BlackMatter and Haron made the headlines. Recently, two new ransomware gangs, named B ...

LockBit 2.0, the first ransomware that uses group policies to encrypt Windows domains
Pierluigi Paganini July 29, 2021

A new variant of the LockBit 2.0 ransomware is now able to encrypt Windows domains by using Active Directory group policies. Researchers from MalwareHunterTeam and BleepingComputer, along wit ...

Critical flaw in Microsoft Hyper-V could allow RCE and DoS
Pierluigi Paganini July 29, 2021

Experts disclose details about a critical flaw in Microsoft Hyper-V, tracked as CVE-2021-28476, that can allow executing arbitrary code on it. Researchers Peleg Hadar of SafeBreach  ...

recent articles

Security
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (C ...

Pierluigi Paganini October 05, 2026
Intelligence
MI5 Raises Alarm Over Chinese Funding of UK Academic Research

MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS. On September 30, MI5 published a formal warning naming th ...

Pierluigi Paganini October 05, 2026
Security
Iranian hacker accused of draining 31TB from university inboxes extradited to the US

Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and thi ...

Pierluigi Paganini October 05, 2026
Security
Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

OpenAI safety veteran David Robinson resigns, warning that the company’s culture and fast AI development model could create bigger risks. OpenAI safety veteran David Robinson knows how his resig ...

Pierluigi Paganini October 05, 2026
Artificial Intelligence
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, ...

Pierluigi Paganini October 04, 2026
Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Steale ...

Pierluigi Paganini October 04, 2026
Cyber Crime
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group

A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to ...

Pierluigi Paganini October 04, 2026
Breaking News
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini October 04, 2026
Malware
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 ...

Pierluigi Paganini October 04, 2026
Malware
Fake Zoom installer hides macOS backdoor CloudSyncD

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine ...

Pierluigi Paganini October 03, 2026
Hacking
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulner ...

Pierluigi Paganini October 03, 2026
APT
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity ...

Pierluigi Paganini October 03, 2026
Security
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ...

Pierluigi Paganini October 02, 2026
Artificial Intelligence
AI Agents Attempt SQL Injection While Searching Government Data

AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, working on what looks li ...

Pierluigi Paganini October 02, 2026
Artificial Intelligence
Investigators trace an AI agent 's path from research task to reconnaissance

Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over ...

Pierluigi Paganini October 02, 2026
Security
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ...

Pierluigi Paganini October 02, 2026
Cyber Crime
Operation KillSwitch: Police Dismantle KillSec Ransomware Group

Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec 's d ...

Pierluigi Paganini October 01, 2026
Artificial Intelligence
Inside Gemini 4 Argon, the model Google is testing on its own infrastructure first

Google unveils Gemini 4 Argon, a frontier AI model built for coding, enterprise work, and autonomous cybersecurity defense, rolling out to trusted testers. Google announced Gemini 4 Argon, and it' ...

Pierluigi Paganini October 01, 2026
Hacking
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950

Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-8695 ...

Pierluigi Paganini October 01, 2026
Security
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Secur ...

Pierluigi Paganini October 01, 2026