LATEST NEWS

VIEW ALL
Facebook inadvertently revealed moderators' identities to suspected terrorists
Pierluigi Paganini June 18, 2017

A bug in the software used by Facebook moderators to review inappropriate content resulted in the disclosure of identities of moderators to suspected terrorists. According to the Guardian, the socia ...

Security Affairs newsletter Round 115 – News of the week
Pierluigi Paganini June 18, 2017

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Critical kernel command line injection flaw found in Motorola handse ...

BAE Systems accused of selling mass surveillance software Evident across the Middle East
Pierluigi Paganini June 18, 2017

BC Arabic and the Danish newspaper Dagbladet accuse British BAE Systems of selling mass surveillance software called Evident across the Middle East. The British company BAE Systems has been selling m ...

Kasperagent malware used in a new campaign leveraging Palestine-Themed decoy files
Pierluigi Paganini June 18, 2017

Researchers uncovered a new cyber espionage campaign involving the Kasperagent spyware delivered with Palestine-Themed decoy files. In March, experts at security firm Qihoo 360 have spotted a cyber ...

recent articles

Hacking
A BYD Shark 6 Hack Shows the Risks of Connected Cars

A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country ro ...

Pierluigi Paganini September 21, 2026
Artificial Intelligence
The Target Is No Longer the Model. It’s the Agent.

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single m ...

Pierluigi Paganini September 21, 2026
Uncategorized
UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then ...

Pierluigi Paganini September 21, 2026
Security
U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CIS ...

Pierluigi Paganini September 20, 2026
Artificial Intelligence
AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the ep ...

Pierluigi Paganini September 20, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click ...

Pierluigi Paganini September 20, 2026
Security
Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 20, 2026
Artificial Intelligence
Google Gemini also Broke Out of Its Test Environment

Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into ...

Pierluigi Paganini September 19, 2026
Artificial Intelligence
AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Cod ...

Pierluigi Paganini September 19, 2026
Hacking
Brevo Supply-Chain Attack Infected Over 100,000 Websites

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-bas ...

Pierluigi Paganini September 18, 2026
Data Breach
Gyazo Data Breach Exposes 23 Million User Records

A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a da ...

Pierluigi Paganini September 18, 2026
Malware
RatHat Turns Android Accessibility Into an Attack Weapon

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know ...

Pierluigi Paganini September 18, 2026
Security
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS ...

Pierluigi Paganini September 18, 2026
Artificial Intelligence
OpenAI admits its models lie to cover their own mistakes

OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don't publish a document explaining how ...

Pierluigi Paganini September 17, 2026
Hacking
Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk

Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two T ...

Pierluigi Paganini September 17, 2026
APT
SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tig ...

Pierluigi Paganini September 17, 2026
Cyber Crime
NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown

The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as eas ...

Pierluigi Paganini September 17, 2026
Security
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity ...

Pierluigi Paganini September 17, 2026
Malware
Chosen Brick, Iran's Surveillance Malware

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint ...

Pierluigi Paganini September 17, 2026
Malware
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight ...

Pierluigi Paganini September 16, 2026