LATEST NEWS

VIEW ALL
Russia-linked APT Sofacy leverages BREXIT lures in recent attacks
Pierluigi Paganini December 04, 2018

Russia-linked cyber-espionage group Sofacy, (aka APT28, Pawn Storm, Fancy Bear, Sednit, Tsar Team, and Strontium) use BREXIT lures in recent attacks. The APT group used Brexit-themed bai ...

Experts found data belonging to 82 Million US Users exposed on unprotected Elasticsearch Instances
Pierluigi Paganini December 03, 2018

Security experts at HackenProof are warning Open Elasticsearch instances expose over 82 million users in the United States. Experts from HackenProof discovered Open Elasticsearch instances that exp ...

New Zealand Security Bureau halts Spark from using Huawei 5G equipment
Pierluigi Paganini December 03, 2018

New Zealand intelligence agency asked mobile company Spark to avoid using Huawei equipment for 5G infrastructure. According to New Zealand's Government Communications Security Bureau, Huawei equipm ...

Hacker hijacks printers worldwide to promote popular YouTube channel
Pierluigi Paganini December 03, 2018

The TheHackerGiraffe used the Printer Exploitation Toolkit (PRET) to hijack +50k vulnerable printers to Promote PewDiePie YouTube Channel. An anonymous hacker hijacked over 50,000 internet-connect ...

recent articles

Security
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances

SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four vulnerabilities in its ...

Pierluigi Paganini October 07, 2026
Cyber Crime
FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away

FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins. The FBI and the U.S. Secret Service i ...

Pierluigi Paganini October 07, 2026
Hacking
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware

Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudf ...

Pierluigi Paganini October 07, 2026
Artificial Intelligence
Anthropic Creates Three Tiers for Claude Cyber Access

Anthropic created three access tiers for Claude's offensive security use, matching cyber capabilities and safeguards to the user's level of trust. Anthropic is trying to solve the difficult balanc ...

Pierluigi Paganini October 07, 2026
Artificial Intelligence
Wikimedia Finds Unauthorized OpenAI Agent Activity on Wikipedia

Wikimedia found unauthorized OpenAI agent activity on its platforms, including unapproved edits, proxy attempts and millions of automated API requests. Wikimedia ran its own investigation after ot ...

Pierluigi Paganini October 07, 2026
Security
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security upda ...

Pierluigi Paganini October 06, 2026
Data Breach
FBI Drops Accenture Contractor After Sensitive Data Breach

Accenture lost an FBI contract after a missed security patch exposed sensitive employee data, raising serious concerns over operational security. The FBI pulled an Accenture contractor off its acc ...

Pierluigi Paganini October 06, 2026
Security
Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible. Dell urged customers to patch a critical flaw, tracked a ...

Pierluigi Paganini October 06, 2026
Uncategorized
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT. FortiGuard Labs researchers spotted a Linux malware family ...

Pierluigi Paganini October 06, 2026
Data Breach
Denmark ’s Population Registry Breached, 8.8 Million Affected

Hackers accessed names, addresses and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access. A hacker broke into the database that holds basically e ...

Pierluigi Paganini October 05, 2026
Security
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (C ...

Pierluigi Paganini October 05, 2026
Intelligence
MI5 Raises Alarm Over Chinese Funding of UK Academic Research

MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS. On September 30, MI5 published a formal warning naming th ...

Pierluigi Paganini October 05, 2026
Security
Iranian hacker accused of draining 31TB from university inboxes extradited to the US

Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and thi ...

Pierluigi Paganini October 05, 2026
Security
Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

OpenAI safety veteran David Robinson resigns, warning that the company’s culture and fast AI development model could create bigger risks. OpenAI safety veteran David Robinson knows how his resig ...

Pierluigi Paganini October 05, 2026
Artificial Intelligence
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, ...

Pierluigi Paganini October 04, 2026
Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Steale ...

Pierluigi Paganini October 04, 2026
Cyber Crime
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group

A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to ...

Pierluigi Paganini October 04, 2026
Breaking News
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini October 04, 2026
Malware
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 ...

Pierluigi Paganini October 04, 2026
Malware
Fake Zoom installer hides macOS backdoor CloudSyncD

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine ...

Pierluigi Paganini October 03, 2026