lunedì 31 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.409 voci in archivio · mostrate 251–275 .

PolinRider Supply Chain Campaign Hijacks Developer Packages and Uses Blockchain Dead Drops

Ransomfeed Daily News · 05/07/2026

Researchers reported a broad software supply chain campaign targeting developers and cryptocurrency users through hijacked packages, browser extensions, and compromised maintainer accounts across ecos…

Armored Likho: la APT che spia governi ed energia con il Python stealer BusySnake

inSicurezzaDigitale.com · 05/07/2026

Kaspersky svela Armored Likho, gruppo APT collegato a Eagle Werewolf, che colpisce enti governativi e il settore elettrico in Russia, Brasile e Kazakistan con BusySnake, un infostealer Python offuscat…

JADEPUFFER: il primo ransomware condotto interamente da un agente AI, dalla violazione al wipe del database

inSicurezzaDigitale.com · 05/07/2026

Il Threat Research Team di Sysdig documenta JADEPUFFER, il primo caso noto di estorsione digitale gestita end-to-end da un agente basato su LLM: dalla violazione di un server Langflow esposto alla cif…

Researcher Chains a Guardrail Bypass With a Path Traversal Flaw to Access System Files in ChatGPT

SecureBulletin · 04/07/2026

A proof-of-concept disclosed by researcher zer0dac combined social engineering against ChatGPT’s own safety logic with a path traversal bug to retrieve restricted system files through the platform’s f…

Ousaban Banking Trojan Resurfaces With Steganographic PDF Lures Targeting Spain and Portugal

SecureBulletin · 04/07/2026

Fortinet’s FortiGuard Labs has documented a fresh wave of the Ousaban banking trojan hitting Windows users in Spain and Portugal through fake corrupted PDFs and a spoofed tax portal. The campaign hide…

New ARToken Phishing Kit Abuses Microsoft’s OAuth Device Code Flow to Hijack Microsoft 365 Accounts

SecureBulletin · 04/07/2026

Cisco Talos has uncovered ARToken, a phishing panel that abuses Microsoft’s device code sign-in flow to steal Microsoft 365 session tokens without a password or MFA prompt. The kit shares code and inf…

Researchers Chain DLL Sideloading and an RPC Flaw to Gain Root Access Inside Claude Cowork’s Sandbox

SecureBulletin · 04/07/2026

Security researchers at Armadin found a way to chain DLL sideloading with a flaw in an internal RPC protocol to escalate privileges and execute commands as root inside Claude Cowork’s isolated Windows…

Pegasus spia chi indaga su Pegasus: il caso Kouloglou scuote il Parlamento Europeo

inSicurezzaDigitale.com · 03/07/2026

Il Citizen Lab conferma: l’eurodeputato greco Stelios Kouloglou, membro della commissione PEGA incaricata di indagare sugli abusi di spyware, è stato colpito da Pegasus nel 2022 e nel 2023 con un expl…

Google Dismantles NetNut-Linked “Popa” Residential Proxy Botnet That Hijacked 2 Million Home Devices

SecureBulletin · 03/07/2026

Google, working with the FBI, Lumen Technologies, and other partners, has taken action against the NetNut residential proxy network – also tracked as “Popa” – estimated to have compromised at least 2…

AsyncRAT Trojan Hidden in 90+ Fake Software Download Sites via DLL Sideloading and ScreenConnect

SecureBulletin · 03/07/2026

A stealthy campaign is hiding the AsyncRAT trojan inside fake installers for popular free software, using DLL sideloading and the legitimate ScreenConnect remote-access tool to slip past security cont…

New CitrixBleed-Class Vulnerability in Citrix NetScaler Exploited Within 24 Hours of Disclosure

SecureBulletin · 03/07/2026

CVE-2026-8451, the latest entry in the CitrixBleed family of NetScaler memory-disclosure flaws, came under active exploitation less than a day after public disclosure. Decoy infrastructure operator Lu…

DHS Confirms Hackers Breached HSIN, the Government’s Emergency Information-Sharing Platform

SecureBulletin · 03/07/2026

The Department of Homeland Security has confirmed a breach of the Homeland Security Information Network (HSIN), the unclassified platform used by federal, state, local, and international partners to c…

PamStealer macOS Infostealer Uses Fake Maccy Apps and PAM Password Validation

Ransomfeed Daily News · 03/07/2026

Researchers have identified PamStealer, a previously unseen macOS malware family distributed through fake websites impersonating the legitimate Maccy clipboard manager. The infection begins with a tro…

Pegasus Infected European Parliament Spyware Investigator’s iPhone

Ransomfeed Daily News · 03/07/2026

Citizen Lab found that the iPhone of former European Parliament member Stelios Kouloglou was infected twice with NSO Group’s Pegasus spyware, in October 2022 and March 2023, while he served on the Par…

Anthropic Publishes Claude Fable 5 Cyber Safeguards and Jailbreak Severity Framework

Ransomfeed Daily News · 03/07/2026

Anthropic said it has globally re-deployed Claude Fable 5 with updated cybersecurity controls and released new technical details on how the model handles cyber-related prompts. The company said the sy…

ChocoPoC RAT Spread Through Trojanized GitHub PoC Exploit Repositories

Ransomfeed Daily News · 03/07/2026

A malware campaign dubbed ChocoPoC used fake or trojanized GitHub proof-of-concept exploit repositories for newly disclosed CVEs to infect cybersecurity researchers, penetration testers, and bug hunte…

Apple Hide My Email Flaw Exposes Users’ Real Email Addresses

Ransomfeed Daily News · 03/07/2026

A reported vulnerability in Apple’s iCloud+ Hide My Email service allows an attacker with only a relay alias to uncover the user’s real email address, defeating a privacy feature widely used to mask i…

DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk

SecureBulletin · 02/07/2026

Two critical zero-click RCE vulnerabilities (CVE-2026-50548, CVE-2026-50549) in Cursor IDE, dubbed DuneSlide, allow attackers to escape the AI coding agent sandbox via prompt injection with no user in…

Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year

SecureBulletin · 02/07/2026

An unpatched vulnerability in Apple’s Hide My Email feature can expose users’ real email addresses behind their iCloud+ anonymization aliases, researcher Tyler Murphy and 404 Media have confirmed. App…

Four New CVEs in Fluentd Expose Millions of Cloud and Kubernetes Logging Pipelines to RCE and Data Leaks

SecureBulletin · 02/07/2026

Four new CVEs in the widely deployed Fluentd log collector — including a critical RCE vulnerability (CVE-2026-44024) exploitable via crafted log entries — put cloud and Kubernetes logging pipelines at…

81 Million Login Attempts: Massive Password Spray Campaign Bypasses MFA to Compromise Azure and Microsoft 365 Accounts

SecureBulletin · 02/07/2026

A massive automated campaign made 81 million login attempts against Microsoft 365 and Azure CLI accounts between June 12 and June 26, 2026, successfully compromising 78 accounts across 64 organization…

L’intelligence russa punta a Signal e WhatsApp: USA offre 10 milioni per i gruppi UNC5792 e UNC4221

inSicurezzaDigitale.com · 02/07/2026

Il Dipartimento di Stato USA ha lanciato un bounty da 10 milioni di dollari per i gruppi russi UNC5792 e UNC4221, responsabili di campagne di phishing contro Signal e WhatsApp. FBI e CISA documentano…

ShinyHunters e lo zero-day PeopleSoft: il regolatore assicurativo USA tra le 100+ vittime di UNC6240

inSicurezzaDigitale.com · 02/07/2026

Sfruttando CVE-2026-35273, una RCE non autenticata in Oracle PeopleSoft, il collettivo ShinyHunters/UNC6240 ha colpito oltre 100 organizzazioni prima ancora del rilascio della patch. Tra le vittime la…

Da un runner Jenkins ad Amazon Redshift: come il worm Shai-Hulud trasforma una CI/CD in una breach cloud

inSicurezzaDigitale.com · 02/07/2026

FortiGuard Labs ricostruisce una compromissione partita da un pacchetto npm infetto da Shai-Hulud: in poche ore l’attaccante passa da un Jenkins runner a pieni privilegi amministrativi su AWS, fino a…

Anubis Ransomware Expanded Through Forum Branding and CitrixBleed 2 Intrusions

Ransomfeed Daily News · 01/07/2026

The Anubis ransomware operation has grown into a structured cybercriminal ecosystem that combines public branding, affiliate recruitment, and multi-platform extortion services. Researchers linked the…