sabato 29 agosto 2026 Privacy RSS Admin
ITAGORA!
Il portale italiano · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.403 voci in archivio · mostrate 1–25 .

Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths

SecureBulletin · 09:30

ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of…

APT28’s New HOOKEDGE Backdoor Targets European Defense and Diplomatic Networks

SecureBulletin · 09:30

The Russia-linked APT28 group is using a lightweight backdoor called HOOKEDGE against defense, government and diplomatic targets in Europe. The campaign combines malicious Word macros, scheduled tasks…

UniBLEed Flaws Put Unitree G1 Humanoid Robots at Risk of Root Takeover

SecureBulletin · 09:30

Researchers demonstrated a multi-stage attack that can give a nearby adversary root-level control of Unitree G1 humanoid robots. The UniBLEed chain combines unauthenticated Bluetooth writes, a cloud a…

Cyber Incident Halts Small UK Power Plant for Four Days as Attribution Remains Unclear

SecureBulletin · 09:30

A cyber incident reportedly stopped a small British peaking power plant for roughly four days without disrupting customers or the wider grid. Officials confirmed the event, while key technical details…

Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release

SecureBulletin · ieri 10:36

PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate…

Houston Healthcare Company Nutex Health Confirms Data Breach and Exfiltration

SecureBulletin · ieri 10:36

Nutex Health, a Houston-based healthcare operator, has disclosed in an SEC filing that an unknown third party accessed its network and exfiltrated data, potentially including patient and employee reco…

Critical Veeam ONE Flaw Lets Unauthenticated Attackers Steal Backup Credentials (CVSS 9.3)

SecureBulletin · ieri 10:36

A newly disclosed flaw in Veeam ONE, tracked as CVE-2026-65641 with a CVSS score of 9.3, lets a remote attacker with no credentials trick the monitoring service into leaking authentication material. V…

Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control

SecureBulletin · ieri 10:36

CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately…

Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate

SecureBulletin · ieri 10:36

CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems…

CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild

SecureBulletin · ieri 10:36

CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services…

FBI Dismantles Chinese State-Sponsored Botnet That Powered a Global Hacking Platform

SecureBulletin · ieri 08:36

The FBI and Department of Justice have seized the domains behind QScan and QTRouter, a pair of linked platforms that a Chinese state-sponsored group allegedly used to hijack vulnerable IoT devices and…

Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries

SecureBulletin · ieri 08:36

An exposed staging server has given researchers an unusually detailed look at how a Russian-speaking Aurora ransomware affiliate used the AI coding assistant Cursor to help plan and refine intrusions…

QTFY, il quartiermastro cinese del cyberspionaggio: otto anni di intrusioni contro NASA, Fed e Senato USA

inSicurezzaDigitale.com · 27/08/2026

FBI e DOJ hanno sequestrato l'infrastruttura di QTFY, gruppo hacker-for-hire legato al MSS cinese che dal 2018 ha colpito NASA, Federal Reserve, Dipartimento di Giustizia e Senato USA tramite il botne…

Black Axe: Interpol smaschera la mafia digitale nigeriana, 58 arresti in 22 Paesi e 143 milioni di euro di truffe smantellate

inSicurezzaDigitale.com · 27/08/2026

Operation Jackal IV, la quarta offensiva Interpol contro Black Axe e le confraternite criminali dell'Africa occidentale, ha portato a 58 arresti tra Sud Africa, Romania, Argentina e Italia. Focus su r…

CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution

SecureBulletin · 27/08/2026

CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook and execute…

Ubiquiti Fixes 21 Critical UniFi Flaws Across Routers, Cameras and Access Systems

SecureBulletin · 27/08/2026

Ubiquiti has patched 21 critical vulnerabilities across a broad range of UniFi products, including flaws rated a maximum 10.0. The bugs enable outcomes including authentication bypass, command injecti…

Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE

SecureBulletin · 27/08/2026

Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, w…

Iran-Linked Tortoiseshell Expands Espionage With TWOSTROKE Backdoor and Reverse SSH Tunnels

SecureBulletin · 27/08/2026

Researchers have linked new Windows malware and reverse SSH infrastructure to the Iran-associated Tortoiseshell threat group. The tools masquerade as a legitimate Windows library and support covert tu…

Mirage2FA Phishing Kit Hijacks Microsoft 365 Sessions at 3,500+ Organizations, Sidestepping MFA Entirely

SecureBulletin · 27/08/2026

A phishing-as-a-service kit called Mirage2FA has compromised thousands of Microsoft 365 accounts by stealing live session cookies through an adversary-in-the-middle proxy, letting attackers walk past…

Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs

SecureBulletin · 27/08/2026

Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are known to be under active…

28,000 Public .git Folders Left AWS Keys, Stripe Tokens, and HR Files Wide Open, Researchers Find

SecureBulletin · 27/08/2026

A large-scale internet scan uncovered 28,000 publicly accessible .git directories exposing hundreds of live cloud and payment credentials, along with sensitive employee records — a reminder that scrub…

One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw

SecureBulletin · 27/08/2026

A critical flaw in NVIDIA’s NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS rebinding, poison its instructions…

Actively Exploited SharePoint Flaw Combines With RCE for Server Takeover

SecureBulletin · 26/08/2026

Two on-premises SharePoint vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. With the authentication flaw already listed as exploited, administrators shou…

Core Werewolf Deploys Custom CoreRAT Against Russian Defense Targets

SecureBulletin · 26/08/2026

The Core Werewolf threat group is using a newly documented Windows remote access trojan in campaigns aimed at Russian public-sector and defense organizations. Telegram lures and forged official docume…

OpenSSL Updates Close Heap Corruption and Remote Crash Weaknesses

SecureBulletin · 26/08/2026

OpenSSL has released patched builds for a broad set of vulnerabilities affecting CMS, CMP, DTLS, QUIC and cryptographic operations. Several weaknesses are remotely triggerable, making dependency disco…