martedì 1 settembre 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.409 voci in archivio · mostrate 376–400 .

JS.MonoGlyphRAT: Stealthy New Malware Hidden in Fake Purchase Orders Targets US Enterprises

SecureBulletin · 08/06/2026

A previously unknown remote access trojan called JS.MonoGlyphRAT is spreading through US businesses disguised as routine purchase orders and business quotes. It evades all major antivirus tools by usi…

HTTP/2 Bomb: Single-Attacker Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

SecureBulletin · 08/06/2026

A newly disclosed exploit called the ‘HTTP/2 Bomb’ can exhaust tens of gigabytes of server memory in seconds using just a home internet connection. Five of the world’s most widely deployed web servers…

VerdantBamboo (UNC5221): il gruppo APT cinese che resta invisibile per 18 mesi con tre backdoor inedite

inSicurezzaDigitale.com · 07/06/2026

Volexity ricostruisce un’intrusione durata 18 mesi da parte del gruppo APT cinese VerdantBamboo/UNC5221. Tre backdoor inedite — BRICKSTORM, PLENET e AGENTPSD — deployate su appliance senza EDR per byp…

Campagna Hades colpisce PyPI: 37 pacchetti malevoli della famiglia Shai-Hulud/Miasma rubano credenziali sviluppatori

inSicurezzaDigitale.com · 07/06/2026

Socket Research Team ha scoperto 37 wheel artifact malevoli su 19 pacchetti PyPI, parte della campagna Hades — ramo evolutivo di Shai-Hulud/Miasma. Il vettore è un file *-setup.pth che esegue silenzio…

ClickFix si mette in cerca di lavoro: falsi annunci LinkedIn e Indeed per distribuire CastleLoader e RAT Python

inSicurezzaDigitale.com · 05/06/2026

LevelBlue SpiderLabs analizza una nuova variante ClickFix (maggio 2026) che usa siti typosquattati imitanti LinkedIn e Indeed, il protocollo Finger e runtime Python portatili per distribuire il framew…

Spie cinesi su LinkedIn: il Five Eyes documenta le campagne di recruiters falsi dell’intelligence militare di Pechino

inSicurezzaDigitale.com · 05/06/2026

FBI, MI5, ASIO, CSIS e NZSIS emettono un alert congiunto: ufficiali dell’intelligence militare cinese si fingono recruiter su LinkedIn, Indeed e Upwork per sottrarre informazioni classificate a person…

Iran-Linked Black Shadow Group Obliterates IT, Backups and Recovery Systems Across US and Middle East

SecureBulletin · 05/06/2026

Operating under the cover name Ababil of Minab, Iran-linked APT group Black Shadow launched a wave of destructive attacks against US transit agencies, Israeli firms, and Middle East organizations, wip…

Google Gemini Voice Assistant Hijacked via WhatsApp, Slack and SMS: Researchers Bypass All Google Defenses

SecureBulletin · 05/06/2026

SafeBreach researchers demonstrate how attackers can silently hijack Google Gemini through malicious payloads in WhatsApp, Slack, SMS, and other messaging app notifications, bypassing all of Google pa…

TA4922: Chinese Cybercrime Group Deploys Atlas RAT, ValleyRAT and AI-Assisted Malware in Global Phishing Blitz

SecureBulletin · 05/06/2026

Proofpoint exposes TA4922, a Chinese-speaking cybercrime group conducting more unique campaigns than any other tracked actor in 2026, deploying Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT…

The Gentlemen Ransomware Group: Fortinet Exploits, AI Operations, and Custom C2 Make Them 2026’s Most Dangerous Crew

SecureBulletin · 05/06/2026

Russian-speaking ransomware group The Gentlemen ranks second in 2026 activity, exploiting Fortinet vulnerabilities, deploying the custom G-BOT C2 framework, using AI for negotiations, and linking oper…

Sophos scopre il laboratorio AI per testare l’evasione degli EDR: così il ransomware si evolve

inSicurezzaDigitale.com · 05/06/2026

Sophos ha scoperto un laboratorio malware automatizzato usato da un gruppo ransomware attivo: agenti AI tra cui Claude Opus 4.5 e Cursor testavano tecniche di evasione EDR contro Sophos, CrowdStrike e…

CVE-2026-8206 (CVSS 9.8): Kirki WordPress Plugin Flaw Lets Attackers Steal Admin Accounts on 500,000+ Sites

SecureBulletin · 04/06/2026

A critical unauthenticated privilege escalation flaw (CVE-2026-8206, CVSS 9.8) in the Kirki WordPress plugin allows attackers to redirect password reset emails and take over administrator accounts. Ov…

Threat Actors Use AI Agents and Cursor IDE to Automate Active Directory Attacks and Beat EDR

SecureBulletin · 04/06/2026

Sophos has uncovered a Russian-speaking threat actor using AI-assisted tools, Cobalt Strike, and a purpose-built automated lab to develop EDR bypass malware targeting Active Directory environments — w…

Five OpenClaw Zero-Days Let Attackers Silently Hijack AI Agent Access on Slack, Teams, and Discord

SecureBulletin · 04/06/2026

Researcher Philip Garabandic disclosed five zero-day vulnerabilities in OpenClaw allowing identity spoofing to hijack trusted AI agent access across Slack, Discord, Microsoft Teams, Matrix, and Zalo…

CVE-2025-48595: Android 0-Day Actively Exploited — Patch Your Devices Now

SecureBulletin · 04/06/2026

Google has confirmed active exploitation of CVE-2025-48595, a zero-click Android Framework privilege escalation flaw affecting Android 14-16. Devices without the June 2026 patch remain at risk of comp…

Ciao Carola

inSicurezzaDigitale.com · 03/06/2026

Ci sono notizie che arrivano come un pugno nello stomaco. Quella della morte di Carola Frediani è una di quelle. Per chi vive e lavora nel mondo della cybersecurity italiana, Carola non era sempliceme…

DriveSurge e il sistema zTDS: migliaia di siti dirottati per distribuire ClickFix e FakeUpdates su Windows e macOS

inSicurezzaDigitale.com · 03/06/2026

Il gruppo DriveSurge usa il Traffic Distribution System zTDS per selezionare dinamicamente le vittime sui siti web compromessi e veicolare campagne ClickFix e FakeUpdates. L’operazione si estende ora…

Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina

inSicurezzaDigitale.com · 03/06/2026

Sekoia documenta una campagna di gennaio 2026 del gruppo APT russo Gamaredon: sfruttando CVE-2025-8088 in WinRAR, gli operatori dell’FSB distribuiscono GammaPhish, GammaLoad, GammaWorm e GammaSteel co…

WordPress Sites Turned Into Spy Networks: Malware Hides C2 Commands in Steam Profile Comments Using Unicode Steganography

SecureBulletin · 03/06/2026

A sophisticated malware campaign has compromised approximately 1,900 WordPress sites using Steam Community profile pages as a covert C2 channel. The malware employs Unicode steganography to hide comma…

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog as Active Exploitation Confirmed — Patch by June 4

SecureBulletin · 03/06/2026

CISA has added CVE-2024-21182, a critical unauthenticated Oracle WebLogic Server vulnerability, to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild exploitation. Federal…

FSB Claims Foreign Spyware Found on Russian Officials’ Phones in Targeted Espionage Campaign

SecureBulletin · 03/06/2026

Russia’s FSB announced the disruption of a foreign intelligence campaign implanting advanced spyware on senior officials’ mobile phones, enabling silent surveillance, communication interception, and d…

1-Click GitHub Token Theft: VSCode Webview Flaw Exposes OAuth Tokens for All Private Repositories

SecureBulletin · 03/06/2026

A critical VSCode webview vulnerability lets attackers steal GitHub OAuth tokens with a single click, granting full access to all private repositories. Researcher Ammar Askar published a complete five…

Miasma colpisce Red Hat: 33 pacchetti npm avvelenati per rubare credenziali cloud e segreti CI/CD

inSicurezzaDigitale.com · 02/06/2026

Trentatré pacchetti npm del namespace @redhat-cloud-services sono stati compromessi dalla campagna Miasma, variante evoluta del worm Shai-Hulud. Il malware usa hook preinstall, crittografia AES-GCM e…

Critical Supply Chain Attack: 31 Red Hat Cloud Services npm Packages Backdoored to Steal Cloud and Dev Credentials

SecureBulletin · 02/06/2026

A sophisticated supply chain attack dubbed “Miasma: The Spreading Blight” has backdoored over 30 official @redhat-cloud-services npm packages, deploying credential-stealing malware that targets AWS, A…

SmartApeSG Campaign Exploits ClickFix Fake Verification Pages to Deliver NetSupport RAT

SecureBulletin · 02/06/2026

The SmartApeSG campaign is using ClickFix scripts disguised as fake browser verification pages to deploy a two-stage infection chain, culminating in a persistent NetSupport Manager RAT installation on…