LATEST NEWS

VIEW ALL
1,000 ships impacted by a ransomware attack on maritime software supplier DNV
Pierluigi Paganini January 17, 2023

A ransomware attack against the maritime software supplier DNV impacted approximately 1,000 vessels. About 1,000 vessels have been impacted by a ransomware attack against DNV, one of the major mar ...

How to abuse GitHub Codespaces to deliver malicious content
Pierluigi Paganini January 17, 2023

Researchers demonstrated how to abuse a feature in GitHub Codespaces to deliver malware to victim systems. Trend Micro researchers reported that it is possible to abuse a legitimate feature in the ...

Patch your Zoho ManageEngine instance immediately! PoC Exploit for CVE-2022-47966 will be released soon
Pierluigi Paganini January 17, 2023

A PoC exploit code for the unauthenticated remote code execution vulnerability CVE-2022-47966 in Zoho ManageEngine will be released soon. The CVE-2022-47966 flaw is an unauthenticated remote code ...

Fortinet observed three rogue PyPI packages spreading malware
Pierluigi Paganini January 17, 2023

Researchers discovered three malicious packages that have been uploaded to the Python Package Index (PyPI) repository by Lolip0p group. FortiGuard Labs researchers discovered three malicious PyPI ...

recent articles

Data Breach
Data breach at Canada’s Investment Watchdog Canadian Investment Regulatory Organization impacts 750,000 people

A data breach at Canada’s investment watchdog, Canadian Investment Regulatory Organization (CIRO), impacted about 750,000 people. The Canadian Investment Regulatory Organization (CIRO) is Canada ...

Pierluigi Paganini January 16, 2026
APT
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bug

Cisco fixed a maximum severity AsyncOS flaw in Secure Email products, previously exploited as a zero-day by China-linked APT group UAT-9686. Cisco fixed a critical AsyncOS flaw, tracked as CVE-202 ...

Pierluigi Paganini January 16, 2026
Security
Actively exploited critical flaw in Modular DS WordPress plugin enables admin takeover

A critical Modular DS WordPress flaw (CVE-2026-23550) is actively exploited, enabling unauthenticated privilege escalation. Threat actors are actively exploiting a critical Modular DS WordPress vu ...

Pierluigi Paganini January 16, 2026
Data Breach
A ransomware attack disrupted operations at South Korean conglomerate Kyowon

South Korean conglomerate Kyowon confirmed a ransomware attack that disrupted operations and may have exposed customer data. Kyowon Group is a major South Korean conglomerate with diverse business ...

Pierluigi Paganini January 15, 2026
Uncategorized
Central Maine Healthcare data breach impacted over 145,000 patients

A cyberattack on Central Maine Healthcare exposed the personal, medical, and insurance data of about 145,000 patients. Central Maine Healthcare notified patients affected by a data security incide ...

Pierluigi Paganini January 15, 2026
Hacking
Palo Alto Networks addressed a GlobalProtect flaw, PoC exists

Palo Alto Networks addressed a flaw impacting GlobalProtect Gateway and Portal, for which a proof-of-concept (PoC) exploit exists. Palo Alto Networks addressed a high-severity vulnerability, track ...

Pierluigi Paganini January 15, 2026
Cyber Crime
Lumen disrupts AISURU and Kimwolf botnet by blocking over 550 C2 servers

Lumen’s Black Lotus Labs blocked over 550 C2 servers tied to the AISURU/Kimwolf botnet used for DDoS attacks and proxy abuse. Lumen’s Black Lotus Labs disrupted over 550 command-and-control se ...

Pierluigi Paganini January 15, 2026
Intelligence
China bans U.S. and Israeli cybersecurity software over security concerns

China has told domestic firms to stop using U.S. and Israeli cybersecurity software, citing national security concerns amid rising tech tensions. Reuters reported that China has ordered domestic c ...

Pierluigi Paganini January 15, 2026
Intelligence
CERT-UA reports PLUGGYAPE cyberattacks on defense forces

CERT-UA reported PLUGGYAPE malware attacks on Ukraine’s defense forces, linked with medium confidence to Russia’s Void Blizzard group. The Computer Emergency Response Team of Ukraine (CERT-UA) ...

Pierluigi Paganini January 14, 2026
Security
Fortinet fixed two critical flaws in FortiFone and FortiSIEM

Fortinet fixed six security flaws, including two critical bugs in FortiFone and FortiSIEM that attackers could exploit without authentication. Fortinet released patches for six vulnerabilities, in ...

Pierluigi Paganini January 14, 2026
Security
U.S. CISA adds a flaw in Microsoft Windows to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw impacting Microsoft Windows to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure S ...

Pierluigi Paganini January 14, 2026
Hacking
Microsoft Patch Tuesday security updates for January 2026 fixed actively exploited zero-day

Microsoft Patch Tuesday addressed 112 security flaws across Windows, Office, Azure, Edge, and more, including eight critical vulnerabilities, kicking off the new year with a major patch update. Mi ...

Pierluigi Paganini January 14, 2026
Cyber Crime
AZ Monica hospital in Belgium shuts down servers after cyberattack

A cyberattack hit AZ Monica hospital in Belgium, forcing it to shut down servers, cancel procedures, and transfer critical patients. A cyberattack forced Belgian hospital AZ Monica to shut down al ...

Pierluigi Paganini January 13, 2026
Cyber Crime
Threat actor claims the theft of full customer data from Spanish energy firm Endesa

Endesa disclosed a data breach exposing full customer data, including contact details, national ID numbers, and payment information. Spanish energy firm Endesa disclosed a data breach, threat acto ...

Pierluigi Paganini January 13, 2026
Cyber Crime
Dutch court convicts hacker who exploited port networks for drug trafficking

Dutch appeals court jails a 44-year-old hacker for 7 years for hacking port systems to help smuggle cocaine through European logistics hubs. A Dutch appeals court sentenced a 44-year-old hacker to ...

Pierluigi Paganini January 13, 2026
Hacking
U.S. CISA adds a flaw in Gogs to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw impacting Gogs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agenc ...

Pierluigi Paganini January 12, 2026
Security
Meta fixes Instagram password reset flaw, denies data breach

Meta fixed an Instagram password reset flaw that let third parties send reset emails, while denying a data breach despite leak claims. Meta confirmed fixing an Instagram password reset vulnerabili ...

Pierluigi Paganini January 12, 2026
Security
Europol and Spanish Police arrest 34 in crackdown on Black Axe criminal network

Europol announced the arrest of 34 suspected Black Axe members in Spain during a joint operation with Spanish and European law enforcement. Europol announced the arrest of 34 suspects in Spain lin ...

Pierluigi Paganini January 12, 2026
APT
Credential-harvesting attacks by APT28 hit Turkish, European, and Central Asian organizations

Russia-linked cyberespionage group APT28 targets energy, nuclear, and policy staff in Turkey, Europe, North Macedonia, and Uzbekistan with credential-harvesting attacks. Between February and Septe ...

Pierluigi Paganini January 12, 2026
Security
The ideals of Aaron Swartz in an age of control

Today marks Aaron Swartz ’s death anniversary. His fight for open knowledge and digital rights continues as the forces he opposed grow stronger. Today marks the anniversary of the death of Aaron ...

Pierluigi Paganini January 11, 2026