LATEST NEWS

VIEW ALL
1,000 ships impacted by a ransomware attack on maritime software supplier DNV
Pierluigi Paganini January 17, 2023

A ransomware attack against the maritime software supplier DNV impacted approximately 1,000 vessels. About 1,000 vessels have been impacted by a ransomware attack against DNV, one of the major mar ...

How to abuse GitHub Codespaces to deliver malicious content
Pierluigi Paganini January 17, 2023

Researchers demonstrated how to abuse a feature in GitHub Codespaces to deliver malware to victim systems. Trend Micro researchers reported that it is possible to abuse a legitimate feature in the ...

Patch your Zoho ManageEngine instance immediately! PoC Exploit for CVE-2022-47966 will be released soon
Pierluigi Paganini January 17, 2023

A PoC exploit code for the unauthenticated remote code execution vulnerability CVE-2022-47966 in Zoho ManageEngine will be released soon. The CVE-2022-47966 flaw is an unauthenticated remote code ...

Fortinet observed three rogue PyPI packages spreading malware
Pierluigi Paganini January 17, 2023

Researchers discovered three malicious packages that have been uploaded to the Python Package Index (PyPI) repository by Lolip0p group. FortiGuard Labs researchers discovered three malicious PyPI ...

recent articles

Security
Non-Zero-Day VPN Flaw Left Japan 's Government Shared Network Platform Exposed: 246,000 Records at Risk

Japan 's Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan 's Digital Agency disclos ...

Pierluigi Paganini September 15, 2026
Artificial Intelligence
ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race ...

Pierluigi Paganini September 14, 2026
Uncategorized
China Calls Amodei’s AI Proposal a New Cold War Playbook

China rejects Amodei’s AI slowdown proposal, calling it fearmongering and a US attempt to contain China’s technology sector. The debate over whether the world should slow down the development ...

Pierluigi Paganini September 14, 2026
Security
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecu ...

Pierluigi Paganini September 14, 2026
Security
Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabil ...

Pierluigi Paganini September 14, 2026
Artificial Intelligence
Anthropic CEO Calls for an AI Slowdown. Is It Possible?

Anthropic CEO calls for AI slowdown, proposes embedded evaluators and global coordination. Geopolitical competition with China makes a voluntary pause structurally fragile. Dario Amodei published ...

Pierluigi Paganini September 14, 2026
Breaking News
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal ...

Pierluigi Paganini September 13, 2026
Security
Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 13, 2026
Hacking
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read - Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path t ...

Pierluigi Paganini September 13, 2026
Cyber Crime
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly o ...

Pierluigi Paganini September 13, 2026
Artificial Intelligence
Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more t ...

Pierluigi Paganini September 12, 2026
Artificial Intelligence
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on ...

Pierluigi Paganini September 11, 2026
Cyber Crime
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently ...

Pierluigi Paganini September 11, 2026
Hacking
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council o ...

Pierluigi Paganini September 11, 2026
Security
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecu ...

Pierluigi Paganini September 10, 2026
Artificial Intelligence
More Capable AI, Not Enough Guardrails

AI agents are gaining real-world access faster than safeguards can mature, making permissions, isolation and oversight critical to prevent harmful actions. Jacob Coxon, a researcher who spent thre ...

Pierluigi Paganini September 10, 2026
Hacking
A New Claude 's Sandbox Failure Shows How AI Can Rationalize Real-World Harm

Claude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning, harmful actions and weak safeguards. Anthropic just published one of the mo ...

Pierluigi Paganini September 10, 2026
Hacking
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and In ...

Pierluigi Paganini September 10, 2026
APT
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit ...

Pierluigi Paganini September 10, 2026
Security
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA, CISA, and the FBI jointly published an adv ...

Pierluigi Paganini September 09, 2026