Sicurezza
Cybersecurity, ransomware, privacy
- inSicurezzaDigitale.com — Cybersecurity in italiano IT
- SecureBulletin — Cybersecurity news in English EN
- Ransomfeed Daily News — Daily cybersecurity news EN
2.409 voci in archivio · mostrate 451–475 .
2026 FIFA World Cup Phishing Fraud Triples in Scope: 222 Fake Domains, Four Criminal Clusters
A massive phishing operation targeting 2026 FIFA World Cup fans has grown nearly three times larger than initially reported, now spanning 222 fraudulent domains across 203 unique IP addresses and oper…
CISA Flags Actively Exploited Langflow Flaw CVE-2025-34291 — AI Workflow Deployments at Risk
CISA has added CVE-2025-34291, a critical CORS misconfiguration in the Langflow AI workflow platform, to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Organizations usin…
AI Discovers 10,000+ Zero-Days: Anthropic’s Claude Mythos Preview Transforms Cybersecurity Defense
Anthropic’s Claude Mythos Preview AI model has autonomously discovered over 10,000 critical zero-day vulnerabilities across major software systems as part of Project Glasswing, revealing both the extr…
Webworm evolve: i backdoor EchoCreep e GraphWorm trasformano Discord e Microsoft Graph in canali C2
Webworm, APT di allineamento cinese attivo dal 2022, ha aggiornato il suo arsenale con due nuovi backdoor: EchoCreep, che usa Discord come canale C2, e GraphWorm, che sfrutta Microsoft Graph API e One…
Whatsapp compromesso su iPhone, la ricerca di Forenser sullo 0-click
Una premessa prima di iniziare: se hai un iPhone con iOS inferiore a 16.7.12, aggiorna, è già tardi e un miracolo che non sia ancora successo niente di brutto. Detto questo, per anni l’ecosistema Appl…
Showboat e JFMBackdoor: il gruppo cinese Calypso spia le telecomunicazioni del Medio Oriente con malware Linux e Windows
Lumen Technologies Black Lotus Labs ha identificato due nuovi impianti malevoli, Showboat per Linux e JFMBackdoor per Windows, utilizzati dal gruppo APT cinese Calypso (Red Lamassu) per infiltrarsi ne…
Ukrainian Intelligence Report: Russian APT Groups Intensify Cyber Operations — 5,927 Incidents, 37% Rise in 2025
A new intelligence report from Ukraine’s National Security and Defense Council reveals Russian state-sponsored threat groups dramatically escalated cyber operations in 2025, with CERT-UA recording 5,9…
Ubiquiti Issues Emergency Patches for Five Critical UniFi OS Vulnerabilities, Three Rated Maximum CVSS 10.0
Ubiquiti Networks has released urgent firmware updates addressing five critical vulnerabilities in its UniFi OS platform, including three flaws rated CVSS 10.0 — the maximum severity score. The unauth…
CISA Adds Two Actively Exploited Microsoft Defender Zero-Days to KEV Catalog — Patch by June 3
CISA has added two critical Microsoft Defender vulnerabilities — CVE-2026-45498 and CVE-2026-41091 — to its Known Exploited Vulnerabilities catalog following evidence of active exploitation in the wil…
LiteSpeed cPanel Plugin Zero-Day (CVE-2026-48172) Actively Exploited to Gain Server Root Access
LiteSpeed has disclosed and patched a critical zero-day privilege escalation flaw (CVE-2026-48172) in its cPanel user-end plugin that is already being actively exploited in the wild to gain root acces…
L’uscita di Tulsi Gabbard dall’intelligence USA e gli scenari di sicurezza nazionale
Le dimissioni di Tulsi Gabbard dalla guida dell’intelligence americana non sono più soltanto indiscrezioni filtrate da ambienti politici di Washington. Dopo ore di speculazioni, la conferma è arrivata…
Google Patches Two Critical Chrome RCE Flaws in Urgent Update — Update to 148.0.7778.178 Now
Google has released an emergency Chrome security update addressing 16 vulnerabilities including two Critical-rated remote code execution flaws in WebRTC and Chrome’s UI layer. Users should update to v…
Operation Saffron: International Authorities Dismantle ‘First VPN’ Criminal Network Linked to Global Ransomware Attacks
A coordinated international law enforcement operation led by France, the Netherlands, Europol, and Eurojust has dismantled First VPN — a criminal VPN service explicitly marketed to cybercriminals and…
WantToCry Ransomware Encrypts Files Remotely Over SMB — No Malware Required
A ransomware operation called WantToCry is exploiting exposed SMB file-sharing services to encrypt business data without ever installing malware on victim machines. SophosLabs researchers warn that ov…
Dark Web Brokers Flood Forums With Recycled Breach Data Disguised as Fresh Corporate Leaks
Cybercriminals operating in Chinese-language dark web ecosystems are repackaging data from old breaches and selling it as fresh corporate intelligence, according to new research from Group-IB. The sca…
Una riunione urgente su Teams e il conto svuotato: la nuova truffa che sfrutta il panico da videocall
C’è un dettaglio interessante nelle nuove campagne cyber che stanno circolando nelle ultime ore: non cercano più di sembrare sofisticate. Cercano di sembrare normali. Una notifica su Microsoft Teams…
“Patchato” non significa protetto: attaccanti bypassano l’MFA sui VPN SonicWall Gen6 e raggiungono i file server in 30 minuti
CVE-2024-12802 sulle appliance SonicWall Gen6 SSL-VPN viene sfruttata attivamente nonostante la patch disponibile. Il motivo: il fix firmware non basta — richiede sei passaggi manuali aggiuntivi che l…
TeamPCP viola GitHub dall’interno: 3.800 repository sottratti in 18 minuti tramite un’estensione VS Code malevola
GitHub ha confermato la sottrazione di circa 3.800 repository interni da parte del gruppo TeamPCP, che ha compromesso il device di un dipendente tramite una versione backdoor dell’estensione VS Code N…
DevilNFC: New Android Malware Traps Victims in Kiosk Mode During NFC Card Relay Attacks
DevilNFC is a new Android malware that combines NFC relay attacks with Android Kiosk Mode to trap victims inside a fake banking screen while stealing card PINs in real time. Targeting Europe and LATAM…
Void Botnet Weaponizes Ethereum Smart Contracts for Seizure-Proof Command-and-Control Infrastructure
The Void Botnet uses Ethereum smart contracts as a seizure-resistant C2 channel, making traditional law enforcement takedowns impossible. Sold on Russian-language forums since March 2026 for $600, the…
Gremlin Stealer Evolves: New Variant Hides C2 URLs in Encrypted Resources and Adds Discord Token Theft
A newly analyzed Gremlin stealer variant hides C2 URLs inside XOR-encrypted .NET resource sections, making it invisible to static scanners. The malware now targets Discord tokens and adds a clipboard…
Claude Code’s Five-Month Network Sandbox Bypass Silently Exposed Developer Credentials and Source Code
Anthropic’s Claude Code harbored a critical SOCKS5 null-byte injection sandbox bypass for over five months, allowing attackers to silently exfiltrate developer credentials, source code, and API keys…
FamousSparrow spia l’Azerbaigian: il gruppo APT cinese colpisce l’industria petrolifera del corridoio energetico europeo
Bitdefender ha documentato un’operazione di cyberspionaggio attribuita a FamousSparrow (APT cinese) contro un’azienda petrolifera azera: tre ondate di attacco tra dicembre 2025 e febbraio 2026, con Pr…
Intelligenza artificiale, responsabilità e cybersicurezza: il punto sul convegno di Cagliari
Nel grande auditorium dell’ARNAS G. Brotzu di Cagliari, si parla di intelligenza artificiale, responsabilità e cybersicurezza nel sistema sanitario nazionale. Sul palco si alternano dirigenti pubblici…
Kimsuky APT Runs Four Simultaneous Spear-Phishing Campaigns Targeting Recruiters, Crypto Users, and Defense Officials
North Korea’s Kimsuky threat group has been operating four parallel spear-phishing campaigns targeting corporate recruiters, cryptocurrency developers, defense sector officials, and graduate school st…