LATEST NEWS

VIEW ALL
Hackers are exploiting the CVE-2018-0101 CISCO ASA flaw in attacks in the wild
Pierluigi Paganini February 11, 2018

Hackers are exploiting the CVE-2018-0101 CISCO ASA flaw in attacks in the wild and a Proof-of-concept exploit code is available online. This week, Cisco has rolled out new security patches for a cr ...

FSB arrested researchers at the Russian Federation Nuclear Center for using a supercomputer to mine Bitcoins
Pierluigi Paganini February 11, 2018

Russian authorities have arrested some employees at the Russian Federation Nuclear Center facility because they are suspected for trying to using a supercomputer at the plant to mine Bitcoin. The pea ...

Online Auction Safety Tips for Buyers and Sellers
Pierluigi Paganini February 10, 2018

Buying or selling goods through online auctions is more popular than ever. Which are the best practices to follow for buyers and sellers for an online auction? Buying or selling goods through online ...

Lenovo patches critical flaws that affect Broadcom’s chipsets in dozens of Lenovo ThinkPad
Pierluigi Paganini February 10, 2018

According to a security advisory issued by Lenovo, two critical vulnerabilities in Broadcom chipsets affects at least 25 models of Lenovo ThinkPad. The affected models are ThinkPad 10,  ThinkPad ...

recent articles

Hacking
Brevo Supply-Chain Attack Infected Over 100,000 Websites

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-bas ...

Pierluigi Paganini September 18, 2026
Data Breach
Gyazo Data Breach Exposes 23 Million User Records

A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a da ...

Pierluigi Paganini September 18, 2026
Malware
RatHat Turns Android Accessibility Into an Attack Weapon

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know ...

Pierluigi Paganini September 18, 2026
Security
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS ...

Pierluigi Paganini September 18, 2026
Artificial Intelligence
OpenAI admits its models lie to cover their own mistakes

OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don't publish a document explaining how ...

Pierluigi Paganini September 17, 2026
Hacking
Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk

Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two T ...

Pierluigi Paganini September 17, 2026
APT
SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tig ...

Pierluigi Paganini September 17, 2026
Cyber Crime
NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown

The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as eas ...

Pierluigi Paganini September 17, 2026
Security
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity ...

Pierluigi Paganini September 17, 2026
Malware
Chosen Brick, Iran's Surveillance Malware

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint ...

Pierluigi Paganini September 17, 2026
Malware
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight ...

Pierluigi Paganini September 16, 2026
Hacking
Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September ...

Pierluigi Paganini September 16, 2026
Data Breach
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut ...

Pierluigi Paganini September 16, 2026
Data Breach
Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen

CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder ...

Pierluigi Paganini September 16, 2026
Security
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security ...

Pierluigi Paganini September 15, 2026
Hacking
Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS ...

Pierluigi Paganini September 15, 2026
Security
Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant

Critical LiteSpeed Enterprise flaw lets one shared hosting account gain root, bypassing CageFS; patch now to 6.3.7 via forced update. cPanel warned that a critical flaw in LiteSpeed Enterprise can ...

Pierluigi Paganini September 15, 2026
APT
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome's patch shipped, deploying different backdoors each. Two China-linked threat actors used the same ...

Pierluigi Paganini September 15, 2026
Security
Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have tu ...

Pierluigi Paganini September 15, 2026
Security
Non-Zero-Day VPN Flaw Left Japan 's Government Shared Network Platform Exposed: 246,000 Records at Risk

Japan 's Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan 's Digital Agency disclos ...

Pierluigi Paganini September 15, 2026