LATEST NEWS

VIEW ALL
330K stolen payment cards and 895K stolen gift cards sold on dark web
Pierluigi Paganini April 09, 2021

A threat actor has sold almost 900,000 gift cards and over 300,000 payment cards on a cybercrime forum on the dark web. A crook has sold 895,000 gift cards and over 300,000 payment cards, for a t ...

Moodle flaw exposed users to account takeover
Pierluigi Paganini April 08, 2021

Wizcase experts discovered a security flaw in the open-source learning platform Moodle that could allow accounts takeover. At the beginning of October 2020, the Wizcase cyber research te ...

Swarmshop - What goes around comes around: hackers leak other hackers’ data online
Pierluigi Paganini April 08, 2021

Group-IB, a global threat hunting and adversary-centric cyber intelligence company, discovered that user data of the Swarmshop card shop have been leaked online on March 17, 2021. The d ...

Pwn2Own 2021 Day 2 – experts earned $200K for a zero-interaction Zoom exploit
Pierluigi Paganini April 08, 2021

Pwn2Own 2021 - Day 2: a security duo earned $200,000 for a zero-interaction Zoom exploit allowing remote code execution. One of the most interesting working exploits of the second day of the Pwn2O ...

recent articles

Security
WatchGuard fixes critical Fireware OS flaw allowing remote code execution

WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has released security updates for Fireware OS ...

Pierluigi Paganini September 30, 2026
Intelligence
Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments

DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last week's Justice Department indictment of Ox ...

Pierluigi Paganini September 30, 2026
Artificial Intelligence
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT

Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT's Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and H ...

Pierluigi Paganini September 30, 2026
Security
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Ag ...

Pierluigi Paganini September 30, 2026
Security
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught ...

Pierluigi Paganini September 30, 2026
Data Breach
Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches

Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporation, one of Japan’s major private railw ...

Pierluigi Paganini September 29, 2026
Uncategorized
Three Million Affected in Pentagon Personnel Agency Data Breach

Pentagon personnel agency breach exposed data of 3 million people after attackers accessed a file-sharing server for about nine months. The U.S. Defense Manpower Data Center (DMDC), which maintain ...

Pierluigi Paganini September 29, 2026
Hacking
Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks

Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix ...

Pierluigi Paganini September 29, 2026
Cyber Crime
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters

Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterd ...

Pierluigi Paganini September 29, 2026
Artificial Intelligence
GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch

UK AISI finds GPT-6 Astra launches unsanctioned supply-chain attacks in simulations far more than earlier OpenAI models, even when told not to. The UK's AI Security Institute tested GPT-6 Astra be ...

Pierluigi Paganini September 29, 2026
Artificial Intelligence
AI Accounts Are Becoming the New Target for Infostealers

Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 9 ...

Pierluigi Paganini September 28, 2026
Data Breach
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure

Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website. The District of Columbia Department of Health Car ...

Pierluigi Paganini September 28, 2026
Cyber Crime
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look ...

Pierluigi Paganini September 28, 2026
Hacking
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ( ...

Pierluigi Paganini September 28, 2026
Security
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild

Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026- ...

Pierluigi Paganini September 28, 2026
Security
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabil ...

Pierluigi Paganini September 27, 2026
Artificial Intelligence
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, ...

Pierluigi Paganini September 27, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: ...

Pierluigi Paganini September 27, 2026
Breaking News
Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 27, 2026
Uncategorized
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools

Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo ...

Pierluigi Paganini September 27, 2026