LATEST NEWS

VIEW ALL
Vxers abused legitimate VMware binary to spread Banking Trojan Distribution
Pierluigi Paganini October 01, 2017

Cisco researchers discovered a malware campaign abusing a legitimate VMware binary to spread a banking Trojan. The threat actor behind the campaign uses multiple methods of re-direction when infecti ...

High-severity flaw opens Siemens Industrial Switches to attacks
Pierluigi Paganini September 30, 2017

Siemens has started releasing security patches to fix a high severity access control vulnerability in its industrial switches tracked as CVE-2017-12736. The flaw was discovered by experts at Siemens ...

Phish For The Future - spear-phishing attacks target Internet Freedom Activists
Pierluigi Paganini September 30, 2017

EFF published the report on “Phish For The Future,” an advanced persistent spearphishing campaign targeting Freedom Activists. The Electronic Frontier Foundation (EFF) confirmed that a sophistic ...

Millions of Macs open to EFI Firmware Hacks even if they are up-to-date
Pierluigi Paganini September 30, 2017

A group of researchers with Duo Security demonstrated that millions of Up-to-Date Apple Macs are vulnerable to EFI Firmware attacks. In 2015, the security researcher Trammell Hudson demonstrated at t ...

recent articles

Security
Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident

Meta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed that one of its AI models breached an uni ...

Pierluigi Paganini August 06, 2026
Security
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Secur ...

Pierluigi Paganini August 06, 2026
Security
Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records

Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty ...

Pierluigi Paganini August 06, 2026
Artificial Intelligence
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something unc ...

Pierluigi Paganini August 05, 2026
Uncategorized
Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed ...

Pierluigi Paganini August 05, 2026
Hacking
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Inf ...

Pierluigi Paganini August 05, 2026
Hacking
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, ...

Pierluigi Paganini August 05, 2026
Uncategorized
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access

SMOKE#SCREEN uses fake Zoom updates to install ScreenConnect RMM, giving attackers persistent remote access while bypassing defenses. Securonix Threat Research has been tracking an active multi-wa ...

Pierluigi Paganini August 05, 2026
Hacking
SharePoint Flaws Used to Hack Switzerland's Federal IT Agency

Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland's Federal Office for Inf ...

Pierluigi Paganini August 04, 2026
Malware
INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero-Day Exploit

INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has ...

Pierluigi Paganini August 04, 2026
Security
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access

A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one's worth reading b ...

Pierluigi Paganini August 04, 2026
Security
U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ...

Pierluigi Paganini August 04, 2026
Cyber Crime
31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register

Cyberattack exposed data of 31,000 people in Liechtenstein's beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechte ...

Pierluigi Paganini August 04, 2026
Artificial Intelligence
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek

Unit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers at Palo Alto's Unit 42 got a front-row sea ...

Pierluigi Paganini August 03, 2026
Cyber Crime
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted

River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Ban ...

Pierluigi Paganini August 03, 2026
Data Breach
PNLD Confirms Data Breach Affecting UK Police and Justice Staff

UK police legal database breach exposed officers' names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used ...

Pierluigi Paganini August 03, 2026
Data Breach
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys

Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, ...

Pierluigi Paganini August 03, 2026
Security
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing

Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerabili ...

Pierluigi Paganini August 03, 2026
Cyber Crime
CareCloud Breach Exposes Medical and Financial Data of 345,000

CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tec ...

Pierluigi Paganini August 02, 2026
Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Mod ...

Pierluigi Paganini August 02, 2026