LATEST NEWS

VIEW ALL
Memento Labs, the ghost of Hacking Team, has returned — or maybe it was never gone at all.
Pierluigi Paganini October 27, 2025

Kaspersky links the first Chrome zero-day of 2025 to tools used in attacks attributed to Memento Labs, formerly known as the Hacking Team. The actor behind Operation ForumTroll used the same tools ...

Crafted URLs can trick OpenAI Atlas into running dangerous commands
Pierluigi Paganini October 27, 2025

Attackers can trick OpenAI Atlas browser via prompt injection, treating malicious instructions disguised as URLs in the omnibox as trusted commands. Attackers can exploit the OpenAI Atlas browser ...

Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVD
Pierluigi Paganini October 27, 2025

Qilin ransomware group used Linux binaries on Windows to evade EDRs, steal backups, and disable defenses via BYOVD attacks. Trend Research found that the Qilin ransomware group (aka Agenda) used a ...

Wordfence blocks 8.7M attacks exploiting old GutenKit and Hunk Companion flaws
Pierluigi Paganini October 27, 2025

Hackers exploited old RCE flaws in WordPress GutenKit and Hunk Companion plugins. Wordfence firm blocked 8.7M attacks in two days. In September and October 2024, submissions revealed Arbitrary Plu ...

recent articles

Uncategorized
Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest. Germany has arrested a Russian national believed to be a ...

Pierluigi Paganini October 09, 2026
Artificial Intelligence
Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning

Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability s ...

Pierluigi Paganini October 09, 2026
Security
US Disrupts China-Linked Integrity Tech 's Cyber Espionage Tools

DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide. The Justice Department and FBI took down two hacking ...

Pierluigi Paganini October 09, 2026
Hacking
AI-Driven tool ARTEX used in attacks against South Korean Banks

CrowdStrike analyzes open directories left by an attacker who used the ARTEX AI pentest tool and LLMs to breach South Korean financial firms. CrowdStrike published a research on a campaign against ...

Pierluigi Paganini October 09, 2026
Cyber warfare
Italy's Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review

Italy's Foreign Ministry is defending its website against a cyberattack, checking embassy sites and pushing for EU action to identify attackers. On the morning of October 8, Italy's Ministry of Fo ...

Pierluigi Paganini October 08, 2026
Cyber Crime
Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure

Hunt.io traced BraZetsu 's infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. Group-IB researchers published a detailed write ...

Pierluigi Paganini October 08, 2026
Cyber Crime
MonsterCloud Owner Charged With Secretly Paying Ransomware Demands

MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterC ...

Pierluigi Paganini October 08, 2026
Intelligence
U.S. Offers $10 Million Reward for Alleged HAFNIUM Hacker Zhang Yu

The U.S. offers $10M for Zhang Yu, accused of helping run HAFNIUM attacks that compromised thousands of organizations worldwide. The U.S. State Department is offering a $10 million reward for info ...

Pierluigi Paganini October 08, 2026
Security
Atlassian Vulnerability Comes Under Attack Hours After Details Go Public

Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (C ...

Pierluigi Paganini October 08, 2026
Security
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances

SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four vulnerabilities in its ...

Pierluigi Paganini October 07, 2026
Cyber Crime
FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away

FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins. The FBI and the U.S. Secret Service i ...

Pierluigi Paganini October 07, 2026
Hacking
CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware

Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudf ...

Pierluigi Paganini October 07, 2026
Artificial Intelligence
Anthropic Creates Three Tiers for Claude Cyber Access

Anthropic created three access tiers for Claude's offensive security use, matching cyber capabilities and safeguards to the user's level of trust. Anthropic is trying to solve the difficult balanc ...

Pierluigi Paganini October 07, 2026
Artificial Intelligence
Wikimedia Finds Unauthorized OpenAI Agent Activity on Wikipedia

Wikimedia found unauthorized OpenAI agent activity on its platforms, including unapproved edits, proxy attempts and millions of automated API requests. Wikimedia ran its own investigation after ot ...

Pierluigi Paganini October 07, 2026
Security
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security upda ...

Pierluigi Paganini October 06, 2026
Data Breach
FBI Drops Accenture Contractor After Sensitive Data Breach

Accenture lost an FBI contract after a missed security patch exposed sensitive employee data, raising serious concerns over operational security. The FBI pulled an Accenture contractor off its acc ...

Pierluigi Paganini October 06, 2026
Security
Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible. Dell urged customers to patch a critical flaw, tracked a ...

Pierluigi Paganini October 06, 2026
Uncategorized
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT. FortiGuard Labs researchers spotted a Linux malware family ...

Pierluigi Paganini October 06, 2026
Data Breach
Denmark ’s Population Registry Breached, 8.8 Million Affected

Hackers accessed names, addresses and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access. A hacker broke into the database that holds basically e ...

Pierluigi Paganini October 05, 2026
Security
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (C ...

Pierluigi Paganini October 05, 2026