martedì 1 settembre 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.409 voci in archivio · mostrate 676–700 .

Attacco SCADA nel mirino: le APT iraniane prendono di mira i controllori Unitronics negli Stati Uniti

inSicurezzaDigitale.com · 13/04/2026

A partire da marzo 2026, attori APT affiliati all’Iran hanno compromesso almeno 75 controllori programmabili Unitronics negli USA, utilizzando il software legittimo Studio 5000 Logix Designer per modi…

Supply Chain Attack Backdoors Smart Slider 3 Pro: 800,000+ WordPress Sites at Risk

SecureBulletin · 13/04/2026

Attackers compromised Nextend’s update infrastructure to distribute a weaponized version of Smart Slider 3 Pro (v3.5.1.35) for approximately six hours on April 7, 2026. Sites that auto-updated receive…

Fortinet Issues Emergency Patch for Actively Exploited FortiClient EMS Zero-Day CVE-2026-35616

SecureBulletin · 13/04/2026

A critical zero-day vulnerability (CVE-2026-35616, CVSS 9.1) in Fortinet FortiClient EMS was exploited in the wild before Fortinet published its advisory. The pre-authentication flaw allows remote cod…

PoC Exploit Leaked for Unpatched Windows Privilege Escalation Zero-Day ‘BlueHammer’

SecureBulletin · 13/04/2026

A disgruntled researcher has published a working exploit for BlueHammer, an unpatched Windows local privilege escalation zero-day that abuses Windows Defender’s update mechanism. Fully patched Windows…

Adobe Patches Actively Exploited Acrobat Reader Zero-Day CVE-2026-34621 — Exploited Since December 2025

SecureBulletin · 13/04/2026

Adobe has issued an emergency patch for CVE-2026-34621 (CVSS 8.6), a prototype pollution zero-day in Acrobat Reader actively exploited since December 2025. Attackers can achieve code execution by deli…

ShinyHunters colpisce Rockstar Games attraverso Anodot: la campagna Salesforce-Snowflake mette a rischio 400 aziende

inSicurezzaDigitale.com · 12/04/2026

ShinyHunters ha violato l’infrastruttura Snowflake di Rockstar Games sfruttando Anodot, un fornitore SaaS terzo di monitoraggio cloud, per sottrarre token di autenticazione. La campagna è parte di un’…

CISA Warning: Iranian-Affiliated Hackers Targeting US Critical Infrastructure PLCs to Cause Disruption

SecureBulletin · 12/04/2026

CISA has issued an urgent advisory (AA26-097A) warning that Iranian-affiliated APT actors have been actively targeting internet-exposed Programmable Logic Controllers across U.S. critical infrastructu…

Russia’s APT28 Deploys New PRISMEX Malware in Espionage Campaign Targeting Ukraine and NATO Allies

SecureBulletin · 12/04/2026

Russia-linked APT28 (Fancy Bear) has launched a new spear-phishing espionage campaign deploying PRISMEX, a previously undocumented malware suite combining steganography, COM hijacking, and cloud-based…

APT Iran Claims 375TB Breach of Lockheed Martin — F-35 Blueprints and Source Code Allegedly Stolen

SecureBulletin · 12/04/2026

Pro-Iranian hacktivist group APT Iran claims to have stolen 375 terabytes of data from Lockheed Martin, including alleged F-35 blueprints and internal source code. The group is demanding over $400 mil…

Google Patches Actively Exploited Chrome Zero-Day CVE-2026-5281 — Update Now

SecureBulletin · 12/04/2026

Google has confirmed that CVE-2026-5281, a high-severity use-after-free vulnerability in Chrome’s Dawn WebGPU implementation, is being actively exploited in the wild. CISA has added the flaw to its Kn…

UNC1069 trasforma Axios in un vettore di spionaggio: WAVESHAPER.V2 colpisce la supply chain npm

inSicurezzaDigitale.com · 12/04/2026

Il 31 marzo 2026, UNC1069 — il gruppo APT nordcoreano noto anche come Sapphire Sleet — ha compromesso l’account di un maintainer di Axios per distribuire il backdoor cross-platform WAVESHAPER.V2 trami…

GlassWorm: il worm che infetta tutti gli IDE tramite un’estensione OpenVSX contraffatta

inSicurezzaDigitale.com · 11/04/2026

Un dropper compilato in Zig si propaga da un’estensione fake WakaTime su OpenVSX verso tutti gli IDE VS Code-compatibili presenti sulla macchina, deployando un RAT con C2 su blockchain Solana e un’est…

Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente

inSicurezzaDigitale.com · 11/04/2026

Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in R…

Payload Ransomware Group Hits Egyptian Oil Giant WASCO in Double-Extortion Attack

SecureBulletin · 11/04/2026

The Payload ransomware group has claimed a cyberattack against El Wastani Petroleum Company (WASCO), a major Egyptian oil and gas operator, using a double-extortion model that threatens to publish exf…

CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure

SecureBulletin · 11/04/2026

A pre-authentication remote code execution flaw (CVSS 9.3) in the Marimo Python notebook framework was weaponized by attackers within just 10 hours of public disclosure. The vulnerability allows any u…

Adobe Breach: Threat Actor Claims 13 Million Support Tickets Stolen via BPO Hack — HackerOne Data at Risk

SecureBulletin · 11/04/2026

A threat actor known as “Mr. Raccoon” claims to have exfiltrated 13 million Adobe customer support tickets, 15,000 employee records, and unpublished HackerOne vulnerability reports through a compromis…

Smart Slider 3 Pro Plugin Backdoored via Supply Chain Attack — 800,000+ Sites at Risk

SecureBulletin · 11/04/2026

Threat actors compromised the update infrastructure of Nextend, the vendor behind Smart Slider 3 Pro, and pushed a fully backdoored plugin version to hundreds of thousands of WordPress and Joomla site…

Stryker Corporation Discloses Material Cybersecurity Incident Disrupting Global Manufacturing Operations

SecureBulletin · 10/04/2026

Stryker Corporation has disclosed a material cybersecurity incident that disrupted its global manufacturing, commercial, ordering, and distribution systems in March 2026. The medical device giant file…

LockBit 5.0 Ransomware-as-a-Service Platform Claims 207 Victims After Criminal Relaunch

SecureBulletin · 10/04/2026

LockBit has relaunched with a new LockBit 5.0 Ransomware-as-a-Service platform, already claiming 207 victims across manufacturing, healthcare, government, and construction sectors. The upgrade demonst…

Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk

SecureBulletin · 10/04/2026

Exploit code has been publicly released for BlueHammer, a Windows zero-day privilege escalation vulnerability that allows attackers to gain full SYSTEM or administrator access. The availability of wor…

Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited — Patch Now

SecureBulletin · 10/04/2026

A critical zero-day in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.8) is being actively exploited in the wild. CISA has added it to its Known Exploited Vulnerabilities catalog, mandating federal…

Il colloquio di lavoro come arma: Lazarus Group e la campagna Graphalgo contro gli sviluppatori crypto

inSicurezzaDigitale.com · 10/04/2026

Da maggio 2025, Lazarus Group conduce la campagna Graphalgo: 192 pacchetti npm e PyPI malevoli distribuiti tramite finti colloqui di lavoro tecnici per sviluppatori blockchain. Il malware a tre stadi…

TeamPCP: la gang che ha avvelenato la supply chain del software e violato la Commissione Europea

inSicurezzaDigitale.com · 10/04/2026

Un gruppo criminale noto come TeamPCP ha compromesso strumenti di sicurezza open-source largamente diffusi — Trivy, LiteLLM, Checkmarx — rubando credenziali da 500.000 sistemi. La chiave AWS sottratta…

CVSS 10.0: Critical Flowise AI Vulnerability Is Being Actively Exploited — 15,000+ Instances Still Exposed

SecureBulletin · 09/04/2026

A maximum-severity RCE vulnerability (CVE-2025-59528, CVSS 10.0) in the popular Flowise AI agent builder is under active attack. Over 15,000 instances are still exposed online. Here’s what you need to…

Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15

SecureBulletin · 09/04/2026

Google has patched CVE-2026-5281, a use-after-free zero-day in Chrome’s WebGPU engine already exploited in the wild. It’s the fourth Chrome zero-day of 2026. CISA has mandated federal agencies to patc…