Sicurezza
Cybersecurity, ransomware, privacy
- inSicurezzaDigitale.com — Cybersecurity in italiano IT
- SecureBulletin — Cybersecurity news in English EN
- Ransomfeed Daily News — Daily cybersecurity news EN
2.415 voci in archivio · mostrate 1.176–1.200 .
The evolving threat of Latrodectus malware: a closer look at version 1.4
In the ever-changing landscape of cybersecurity, new threats emerge regularly, demanding constant vigilance and adaptation from professionals in the field. One such threat is the Latrodectus malware…
Cybersecurity concerns rise as BMW Hong Kong faces data breach
In a troubling development for the automotive sector, a well-known threat actor identified as “888” has claimed responsibility for leaking sensitive customer data from BMW Hong Kong. The breach, which…
North Korean hackers targeting NPM packages
In recent weeks, the cybersecurity landscape has witnessed a concerning uptick in malicious activities targeting developers through compromised NPM (Node Package Manager) packages. Researchers from Ph…
Zero-day vulnerability CVE-2024-7971 and the threat posed by Citrine Sleet
Recent findings by Microsoft have shed light on a significant cybersecurity threat emerging from North Korea. The discovery of a zero-day vulnerability in the Chromium browser, labeled CVE-2024-7971…
Hacktivist group exploits WinRAR vulnerability to launch attacks
The hacktivist group Head Mare has made headlines for exploiting a vulnerability in WinRAR to infiltrate and encrypt systems across both Windows and Linux platforms. Active since the start of the Russ…
Voldemort: new wave of Google Sheets exploits
In a concerning development within the cybersecurity landscape, researchers from Proofpoint have identified a sophisticated campaign leveraging Google Sheets as a covert platform for data exfiltration…
The emergence of ManticoraLoader: a new threat in the cybersecurity landscape
In recent weeks, the cybersecurity community has been alerted to the rise of a new Malware-as-a-Service (MaaS) offering known as ManticoraLoader. Developed by the notorious group DeadXInject, which pr…
Intelligenza Artificiale e politica, necessario recuperare gap di conoscenza. Attenzione al dato
Alla recente Festa Nazionale dell’Unità in Emilia Romagna, ho avuto modo di seguire il dibattito politico che anche in Italia, come nel resto del mondo sta impattando sulla società: quello sull’Intell…
La digitalizzazione impatta banche, aziende e PA: ma rivediamo i processi partendo dall’autenticazione con le Passkey
Nell’era della digitalizzazione, la sicurezza delle informazioni e l’accesso ai servizi online sono diventati temi di primaria importanza per banche, aziende e pubbliche amministrazioni. Con l’aumento…
Indagini francesi su Durov e problemi tra Israele e data leak scomodi su Telegram. Si tiene tutto, tranne Israele?
Pavel Durov, il fondatore di Telegram, è stato recentemente fermato in Francia, suscitando un acceso dibattito su motivazioni e implicazioni legate alla sua detenzione. La questione si complica ulteri…
A critical vulnerability in Mirai botnet: remote DoS exploit discovered
Recent investigations into the Mirai botnet have unveiled a significant remote denial-of-service (DoS) exploit, identified as CVE-2024-45163. This vulnerability was discovered within the source code o…
E-commerce vulnerabilities exposed: the Magento skimmer incident
A recent cyberattack targeting Magento, a widely used e-commerce platform, has raised significant concerns within the cybersecurity community. Hackers have successfully injected a malicious skimmer in…
Pavel Durov, fondatore di Telegram, fermato in Francia. Perché questo può essere un problema per Internet
Questo articolo è stato sottoposto a revisione al fine di specificare lo stato di fermo che pende su Durov, rispetto all’arresto, come precedentemente affermato. Pavel Durov, cofondatore miliardario e…
Emergence of PG_MEM malware targeting PostgreSQL databases
Aqua Nautilus researchers have uncovered a dangerous new malware strain named PG_MEM, specifically designed to exploit the PostgreSQL database management system for illicit cryptocurrency mining. The…
Overview of the August 12, 2024 Google Cloud Platform outage in London
On August 12, 2024, Google experienced a power outage at its London data center, leading to a notable disruption of Google Cloud Platform (GCP) and Workspace services for UK users. The outage, which l…
Disruption of the Radar/Dispossessor ransomware operation: a major victory against cybercrime
In a significant breakthrough for global cybersecurity, the FBI, in collaboration with law enforcement agencies from the UK and Germany, has successfully dismantled the notorious Radar/Dispossessor ra…
L’intervista di Elon Musk a Donald Trump ha sviluppato un self DDoS sulla sua stessa piattaforma
Un’intervista attesa da molti (per lo più sovranisti americani) tra il CEO di Twitter, Elon Musk, e l’ex Presidente Donald Trump ha subito una breve interruzione a causa di un attacco DDoS che ha colp…
AMOS stealer campaign targeting Mac users via fake Loom website
Recent research from Moonlock Lab has unveiled a sophisticated cybercriminal operation, potentially connected to a group dubbed “Crazy Evil,” that is honing in on Mac users. This operation exploits th…
Vulnerabilities in Google’s Quick Share could lead to remote code execution
Recent findings have spotlighted significant security vulnerabilities in Google’s Quick Share, a file-sharing tool that works across Android, Windows, and Chrome OS devices. Identified as “QuickShell”…
Fenice exposes 1.4 billion Tencent records
A recent data breach attributed to the threat actor known as “Fenice” has resulted in the exposure of approximately 1.4 billion records from Tencent’s database. This alarming incident was disclosed on…
Il pericolo silenzioso del Sitting Duck Attack
Tra le minacce emergenti che stanno attirando l’attenzione degli esperti di cybersecurity c’è il cosiddetto “Sitting Duck Attack”, una forma di attacco che, pur essendo relativamente semplice, può ave…
Critical zero-day vulnerability in Microsoft Office: CVE-2024-38200
On August 8th, Microsoft revealed a significant zero-day vulnerability, tracked as CVE-2024-38200, affecting multiple versions of its Office suite with a CVSS score of 7.5. This information disclosure…
Escalating iranian cyber influence operations ahead of the 2024 US elections
As the 2024 US presidential election looms, the Microsoft Threat Analysis Center (MTAC) has unveiled an alarming uptick in cyber-enabled influence operations orchestrated by Iranian actors, marking a…
Nexera suffers $1.8 million breach amidst security vulnerabilities
Nexera, a blockchain infrastructure protocol known for its tokenization solutions, recently experienced a significant security breach that resulted in the theft of $1.8 million, as revealed by cyberse…
SharpRhino: the emerging C# RAT from Hunters International
In late 2023, the ransomware group Hunters International emerged on the cyber threat landscape, drawing attention due to their sophisticated tactics and tools. Recently, researchers at Quorum Cyber re…