LATEST NEWS

VIEW ALL
Ivanti Cloud Service Appliance flaw is being actively exploited in the wild
Pierluigi Paganini September 14, 2024

Ivanti warned that recently patched flaw CVE-2024-8190 in Cloud Service Appliance (CSA) is being actively exploited in the wild. Ivanti warned that a newly patched vulnerability, tracked as CVE-20 ...

GitLab fixed a critical flaw in GitLab CE and GitLab EE
Pierluigi Paganini September 14, 2024

GitLab addressed multiple vulnerabilities impacting GitLab CE/EE, including a critical pipeline execution issue. GitLab released security patches for 17 vulnerabilities in GitLab CE (Community Ed ...

New Linux malware called Hadooken targets Oracle WebLogic servers
Pierluigi Paganini September 13, 2024

A new Linux malware called Hadooken targets Oracle WebLogic servers, it has been linked to several ransomware families. Aqua Security Nautilus researchers discovered a new Linux malware, called H ...

Lehigh Valley Health Network hospital network has agreed to a $65 million settlement after data breach
Pierluigi Paganini September 13, 2024

Lehigh Valley Health Network ’s (LVHN) hospital network has agreed to a $65 million settlement in a class action lawsuit related to a data breach. Lehigh Valley Health Network (LVHN) is a large ...

recent articles

Hacking
Cisco fixed actively exploited zero-day in Cisco IOS and IOS XE software

Cisco addressed a high-severity zero-day in Cisco IOS and IOS XE Software that is being actively exploited in attacks in the wild. Cisco fixed an actively exploited zero-day, tracked as CVE-2025-2 ...

Pierluigi Paganini September 25, 2025
Hacking
Nation-State hackers exploit Libraesva Email Gateway flaw

State-sponsored hackers exploited a vulnerability, tracked as CVE-2025-59689, in Libraesva Email Gateway via malicious attachments. Nation-state actors exploited a command injection flaw, tracked ...

Pierluigi Paganini September 24, 2025
Security
SolarWinds fixed a critical RCE flaw in its Web Help Desk software

SolarWinds fixed a critical flaw in its Web Help Desk software that could allow attackers to execute arbitrary commands on vulnerable systems. SolarWinds has released hot fixes to address a critic ...

Pierluigi Paganini September 24, 2025
Hacking
How threat actors breached a U.S. federal civilian agency by exploiting a GeoServer flaw

US CISA revealed that threat actors exploited an unpatched vulnerability in GeoServer to breach a U.S. federal civilian agency’s network. Threat actors breached a U.S. federal agency via unpatch ...

Pierluigi Paganini September 24, 2025
Security
Cloudflare mitigates largest-ever DDoS attack at 22.2 Tbps

Cloudflare blocked a new record-breaking DDoS attack peaking at 22.2 Tbps and 10.6 billion packets per second. Cloudflare announced it has mitigated a new record-breaking distributed denial-of-ser ...

Pierluigi Paganini September 24, 2025
Security
U.S. CISA adds Google Chromium flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (C ...

Pierluigi Paganini September 23, 2025
Intelligence
US Secret Service dismantled covert communications network near the U.N. in New York

Secret Service seizes a covert communications network near U.N. composed of sophisticated equipment, including 100K SIMs and 300 servers The U.S. Secret Service uncovered a covert communications n ...

Pierluigi Paganini September 23, 2025
Cyber Crime
A suspected Scattered Spider member suspect detained for casino network attacks

A suspected Scattered Spider member linked to cyber attacks on Las Vegas casinos was arrested on September 17. The Las Vegas Metropolitan Police Department arrested on September 17 a suspected Sca ...

Pierluigi Paganini September 23, 2025
Security
$150K awarded for L1TF Reloaded exploit that bypasses cloud mitigations

Researchers earned $150K for “L1TF Reloaded,” combining L1TF and half-Spectre to leak VM memory from public clouds despite mitigations. Researchers from Vrije Universiteit Amsterdam earned $15 ...

Pierluigi Paganini September 23, 2025
Cyber Crime
Canada's RCMP closes TradeOgre, seizes $40M in country’s largest crypto bust

RCMP shuts down TradeOgre, seizing $40M from crime, the first crypto exchange closure and largest asset seizure in Canada’s history. The Royal Canadian Mounted Police shut down the crypto exchan ...

Pierluigi Paganini September 23, 2025
Data Breach
Stellantis probes data breach linked to third-party provider

Stellantis is investigating a data breach after unauthorized access to a third-party provider’s platform potentially exposed customer data. Car maker giant Stellantis announced it is investigati ...

Pierluigi Paganini September 22, 2025
Cyber Crime
FBI alerts public to spoofed IC3 site used in fraud schemes

The FBI warns that criminals are spoofing the IC3 site to steal personal data and commit fraud targeting cybercrime reporters. The FBI warned that attackers are spoofing the official Crime Complai ...

Pierluigi Paganini September 22, 2025
Security
EU agency ENISA says ransomware attack behind airport disruptions

The EU cybersecurity agency ENISA confirmed that airport check-in disruptions were caused by a cyberattack, and law enforcement is investigating. A cyber attack on Collins Aerospace disrupted chec ...

Pierluigi Paganini September 22, 2025
Malware
Researchers expose MalTerminal, an LLM-enabled malware pioneer

SentinelOne uncovered MalTerminal, the earliest known malware with built-in LLM capabilities, and presented it at LABScon 2025. SentinelLABS researchers discovered MalTerminal, the earliest known ...

Pierluigi Paganini September 22, 2025
Malware
Beware: GitHub repos distributing Atomic Infostealer on macOS

LastPass warns macOS users of fake GitHub repos distributing Atomic infostealer malware disguised as legitimate tools. LastPass warns macOS users about fake GitHub repositories spreading malware d ...

Pierluigi Paganini September 22, 2025
APT
ESET uncovers Gamaredon–Turla collaboration in Ukraine cyberattacks

ESET found evidence that Russia-linked groups Gamaredon and Turla collaborated in cyberattacks on Ukraine between February and April 2025. ESET reported Russia-linked groups Gamaredon and Turla co ...

Pierluigi Paganini September 21, 2025
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 63

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter SmokeLoader Rises From the Ashes  Hi ...

Pierluigi Paganini September 21, 2025
Breaking News
Security Affairs newsletter Round 542 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini September 21, 2025
Hacking
A cyberattack on Collins Aerospace disrupted operations at major European airports

A cyberattack on Collins Aerospace disrupted operations at major European airports, with Heathrow, Brussels, and Berlin most affected. A cyber attack on Collins Aerospace disrupted check-in and b ...

Pierluigi Paganini September 20, 2025
Security
Fortra addressed a maximum severity flaw in GoAnywhere MFT software

Fortra addressed a critical flaw in GoAnywhere Managed File Transfer (MFT) software that could result in the execution of arbitrary commands. Fortra addressed a critical vulnerability, tracked as ...

Pierluigi Paganini September 19, 2025