LATEST NEWS

VIEW ALL
Victims of FonixCrypter ransomware could decrypt their files for free
Pierluigi Paganini January 30, 2021

FonixCrypter ransomware operators shut down their operations, released the master decryption key for free, and deleted malware's source code. Good news for the victims of the FonixCrypter ransomwa ...

Domain for programming website Perl.com hijacked
Pierluigi Paganini January 29, 2021

Threat actors took over the domain name perl.com and pointed it to an IP address associated with malware campaigns. Attackers have taken over the official domain name of The Perl Foundation perl.c ...

Experts addressed flaws in Popup Builder WordPress plugin
Pierluigi Paganini January 29, 2021

Multiple issues in WordPress 'Popup Builder' Plugin could be exploited by hackers to perform various malicious actions on affected websites. Developers behind the "Popup Builder – Responsive Wor ...

Microsoft: North Korea-linked Zinc APT targets security experts
Pierluigi Paganini January 29, 2021

Microsoft, like Google TAG, observed a cyber espionage campaign aimed at vulnerability researchers that attributed to North Korea-linked Zinc APT group. Researchers from Microsoft monitored a cybe ...

recent articles

Hacking
Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks

Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix ...

Pierluigi Paganini September 29, 2026
Cyber Crime
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters

Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterd ...

Pierluigi Paganini September 29, 2026
Artificial Intelligence
GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch

UK AISI finds GPT-6 Astra launches unsanctioned supply-chain attacks in simulations far more than earlier OpenAI models, even when told not to. The UK's AI Security Institute tested GPT-6 Astra be ...

Pierluigi Paganini September 29, 2026
Artificial Intelligence
AI Accounts Are Becoming the New Target for Infostealers

Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 9 ...

Pierluigi Paganini September 28, 2026
Data Breach
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure

Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website. The District of Columbia Department of Health Car ...

Pierluigi Paganini September 28, 2026
Cyber Crime
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look ...

Pierluigi Paganini September 28, 2026
Hacking
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency ( ...

Pierluigi Paganini September 28, 2026
Security
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild

Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026- ...

Pierluigi Paganini September 28, 2026
Security
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabil ...

Pierluigi Paganini September 27, 2026
Artificial Intelligence
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, ...

Pierluigi Paganini September 27, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: ...

Pierluigi Paganini September 27, 2026
Breaking News
Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 27, 2026
Uncategorized
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools

Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo ...

Pierluigi Paganini September 27, 2026
Artificial Intelligence
OpenAI Agents Accessed US Government Websites Without Authorization

OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed on Friday that its AI agents had interacte ...

Pierluigi Paganini September 26, 2026
Cyber Crime
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Exploit.in data shows how a 2005 cybercrime forum helped shape today's ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database ...

Pierluigi Paganini September 26, 2026
Security
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CIS ...

Pierluigi Paganini September 26, 2026
Hacking
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and ...

Pierluigi Paganini September 25, 2026
Cyber Crime
Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million

Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North ...

Pierluigi Paganini September 25, 2026
Malware
ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed thr ...

Pierluigi Paganini September 25, 2026
Malware
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been act ...

Pierluigi Paganini September 25, 2026