domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.403 voci in archivio · mostrate 226–250 .

Critical BeyondTrust Flaws (CVSS 9.2) in Remote Support and PRA Let Attackers Bypass Access Controls

SecureBulletin · 07/07/2026

BeyondTrust disclosed critical flaws (advisory BT26-03, CVSS 9.2) in Remote Support and Privileged Remote Access that let limited-privilege users bypass access controls. Cloud customers were auto-patc…

Multiple Open Source Projects Disclose High-Impact RCE, Injection, and Traversal Flaws

Ransomfeed Daily News · 07/07/2026

Several open source projects disclosed serious vulnerabilities affecting developer and infrastructure tooling, including remote code execution, SQL injection, server-side request forgery, prompt-drive…

Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup

inSicurezzaDigitale.com · 07/07/2026

JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, fur…

Adobe ColdFusion RDS File-Write Flaw Faces Active Exploitation

Ransomfeed Daily News · 07/07/2026

Adobe ColdFusion is facing active exploitation of CVE-2026-48282, a maximum-severity flaw tied to RDS arbitrary file write that can be abused without privileges on unpatched servers. The Canadian Cent…

France to End Certification of Non-Quantum-Safe Encryption Products

Ransomfeed Daily News · 07/07/2026

France's cybersecurity agency, ANSSI, said it will stop certifying security products that lack post-quantum or quantum-resistant encryption beginning in 2027. Because ANSSI certification is required f…

Teen Arrested for Bandai Channel Attack That Canceled 46,000 Subscriptions

Ransomfeed Daily News · 07/07/2026

Japanese police arrested a 15-year-old high school student from Saitama Prefecture for allegedly carrying out a sustained cyberattack against Bandai Channel, the anime streaming service operated by Ba…

OpenSSH 10.4 fixes multiple flaws and adds optional post-quantum signatures

Ransomfeed Daily News · 07/07/2026

OpenSSH has released version 10.4 with eight security fixes affecting both client and server components, including sftp, scp, sshd, ssh, ssh-agent, and cryptographic verification logic. The update add…

New “Bad Epoll” Linux Zero-Day Lets Local Users Root Servers and Android Devices

SecureBulletin · 06/07/2026

A newly disclosed Linux kernel flaw dubbed “Bad Epoll” (CVE-2026-46242) lets a local, unprivileged user escalate to root on Linux servers, desktops, and Android devices via a use-after-free in the epo…

Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk

SecureBulletin · 06/07/2026

runZero has disclosed seven new CVEs in FatFs, the FAT/exFAT filesystem driver used across ESP-IDF, STM32Cube, Zephyr, MicroPython, and countless other embedded platforms. The bugs range from CVSS Med…

PamStealer: New macOS Infostealer Disguises Itself as the Maccy Clipboard Manager

SecureBulletin · 06/07/2026

PamStealer is a newly discovered macOS infostealer that impersonates the Maccy clipboard manager, using a two-stage AppleScript-to-Rust infection chain to steal Keychain data, browser credentials, and…

Apache ActiveMQ Patches Three Vulnerabilities Enabling DoS, Data Leakage, and Privilege Escalation

SecureBulletin · 06/07/2026

Apache ActiveMQ users should urgently patch three newly disclosed vulnerabilities — CVE-2026-53917, CVE-2026-54475, and CVE-2026-49877 — that can crash brokers, break temporary-destination isolation…

New T3MP3ST Framework Turns AI Coding Agents Into Autonomous 0-Day Hunters

SecureBulletin · 06/07/2026

T3MP3ST, a new open-source framework, turns AI coding agents like Claude Code and Codex into autonomous red-teaming operators, claiming strong results on benchmark suites and a set of real 2026 CVEs.

Flipper Zero Maker Overhauls Firmware Contribution Rules After Community Backlash

SecureBulletin · 06/07/2026

Flipper Devices has rolled out new firmware contribution rules, including GitHub Discussions-based feature voting and mandatory integration testing, after community backlash over a perceived firmware…

Microsoft Ships KB5095189 Cumulative Update to Patch the Windows 11 Setup Experience

SecureBulletin · 06/07/2026

Microsoft’s KB5095189 update patches the Windows 11 setup experience for versions 24H2 and 25H2. It carries no CVE, but enterprises relying on Autopilot-style provisioning should confirm devices aren’…

Cybersecurity Week in Review: AI Model Redeployment, a Linux Root Zero-Day, and Hundreds of Chrome Patches

SecureBulletin · 06/07/2026

This week: Anthropic’s Claude Mythos 5 returns to critical infrastructure use, a near-100%-reliable Linux root zero-day emerges, Chrome patches 382 bugs, and Scattered Spider notches another extraditi…

Microsoft Edge Patches Multiple High-Severity RCE and Security Bypass Flaws

Ransomfeed Daily News · 06/07/2026

Microsoft Edge (Chromium-based) has received fixes for multiple high-severity vulnerabilities, including remote code execution flaws CVE-2026-58289, CVE-2026-58293, CVE-2026-58285, CVE-2026-58288, CVE…

Malicious npm Rollup Polyfills Linked to Lazarus Target Developer Environments

Ransomfeed Daily News · 06/07/2026

Researchers identified a malicious npm supply-chain campaign that impersonated Rollup polyfill tooling to compromise developer workstations and CI/build systems. The primary packages, rollup-packages-…

Medtronic Data Breach Exposed Personal and Health Information in ShinyHunters Attack

Ransomfeed Daily News · 05/07/2026

Medtronic disclosed that unauthorized actors accessed certain corporate IT systems between April 13 and April 19, exposing personal and health-related information tied to 3,834,294 individuals. The co…

Linux Kernel Flaws Expose Systems to Local Root Escalation

Ransomfeed Daily News · 05/07/2026

Researchers disclosed two separate Linux kernel privilege-escalation flaws that can give local attackers root access across a wide range of systems, including servers, desktops, and Android devices. O…

PolinRider Supply Chain Campaign Hijacks Developer Packages and Uses Blockchain Dead Drops

Ransomfeed Daily News · 05/07/2026

Researchers reported a broad software supply chain campaign targeting developers and cryptocurrency users through hijacked packages, browser extensions, and compromised maintainer accounts across ecos…

Armored Likho: la APT che spia governi ed energia con il Python stealer BusySnake

inSicurezzaDigitale.com · 05/07/2026

Kaspersky svela Armored Likho, gruppo APT collegato a Eagle Werewolf, che colpisce enti governativi e il settore elettrico in Russia, Brasile e Kazakistan con BusySnake, un infostealer Python offuscat…

JADEPUFFER: il primo ransomware condotto interamente da un agente AI, dalla violazione al wipe del database

inSicurezzaDigitale.com · 05/07/2026

Il Threat Research Team di Sysdig documenta JADEPUFFER, il primo caso noto di estorsione digitale gestita end-to-end da un agente basato su LLM: dalla violazione di un server Langflow esposto alla cif…

Researcher Chains a Guardrail Bypass With a Path Traversal Flaw to Access System Files in ChatGPT

SecureBulletin · 04/07/2026

A proof-of-concept disclosed by researcher zer0dac combined social engineering against ChatGPT’s own safety logic with a path traversal bug to retrieve restricted system files through the platform’s f…

Ousaban Banking Trojan Resurfaces With Steganographic PDF Lures Targeting Spain and Portugal

SecureBulletin · 04/07/2026

Fortinet’s FortiGuard Labs has documented a fresh wave of the Ousaban banking trojan hitting Windows users in Spain and Portugal through fake corrupted PDFs and a spoofed tax portal. The campaign hide…

New ARToken Phishing Kit Abuses Microsoft’s OAuth Device Code Flow to Hijack Microsoft 365 Accounts

SecureBulletin · 04/07/2026

Cisco Talos has uncovered ARToken, a phishing panel that abuses Microsoft’s device code sign-in flow to steal Microsoft 365 session tokens without a password or MFA prompt. The kit shares code and inf…