domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.403 voci in archivio · mostrate 101–125 .

SilverFox Malware Deploys New Kernel Drivers to Blind Antivirus Before Installing ValleyRAT

SecureBulletin · 08/08/2026

Researchers at CATO Networks have caught the SilverFox threat group hiding behind trusted PDF software while quietly loading vulnerable, signed kernel drivers to knock out endpoint protection. The cam…

Snowflake, l’hacker Connor Moucka si dichiara colpevole: il conto finale di 165 aziende violate e miliardi di record rubati

inSicurezzaDigitale.com · 06/08/2026

Connor Riley Moucka si dichiara colpevole per l’attacco a Snowflake del 2024: 165 aziende violate, tra cui AT&T e Ticketmaster, miliardi di record rubati e un giro di estorsioni da milioni di dollari…

OctLurk e SilkLurk: la backdoor sinofona che si decifra solo sulla macchina della vittima

inSicurezzaDigitale.com · 06/08/2026

Kaspersky svela OctLurk e SilkLurk, due backdoor usate da un attore cinofono per colpire enti governativi e sanitari in Asia Centrale dal 2025. Il payload si decifra solo sul dispositivo del bersaglio…

Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN

SecureBulletin · 06/08/2026

Cisco has patched five vulnerabilities in Catalyst SD-WAN Software, three of them scoring 9.9 out of 10 on the CVSS scale. There is no evidence of active exploitation yet, but every deployment mode is…

Greatness Phishing Service Lets Attackers Slide Past MFA Into Microsoft 365 Inboxes

SecureBulletin · 06/08/2026

A phishing-as-a-service platform called Greatness is stealing live authentication tokens rather than passwords, letting attackers walk past multi-factor authentication and into Microsoft 365 mailboxes…

Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers

SecureBulletin · 06/08/2026

Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repo…

How Attackers Spent July Turning Microsoft, Zoom, and Government Sites Against Their Own Users

SecureBulletin · 06/08/2026

Threat intelligence from ANY.RUN shows attackers spent July 2026 weaponizing the everyday trust built into Microsoft logins, Zoom event pages, and government portals across the US, Europe, and Brazil…

Acqua sotto attacco: come hacker legati all’Iran hanno tentato di contaminare le reti idriche di sette stati USA

inSicurezzaDigitale.com · 05/08/2026

FBI ed EPA confermano un’ondata di attacchi contro PLC Rockwell esposti su internet in almeno sette stati americani, con l’obiettivo dichiarato di abbassare la pressione idrica fino a permettere l’ing…

OVERCAST PANDA: la Cina compromette fisicamente i laptop di giornalisti e scienziati in hotel

inSicurezzaDigitale.com · 05/08/2026

Il CrowdStrike 2026 Threat Hunting Report rivela come, tra marzo e maggio 2026, l’adversary china-nexus OVERCAST PANDA abbia installato il backdoor FlowCloud su laptop incustoditi di giornalisti e ric…

One Click, Total Takeover: The RCE Bug That Hid Inside Cursor, VS Code, and Google Antigravity

SecureBulletin · 05/08/2026

Security researchers at AISLE uncovered a one-click remote code execution flaw shared by Cursor, Microsoft VS Code, and Google Antigravity, all three built on the same underlying codebase. A single cl…

How a Rogue Prompt Could Turn Microsoft Copilot Into a $250,000 Wire Fraud Accomplice

SecureBulletin · 05/08/2026

A proof-of-concept from Barracuda researchers shows how attackers could weaponize Microsoft Copilot itself to escalate a single compromised inbox into full CEO account takeover and a quarter-million-d…

Six Ways to Break Flowise: New RCE Chain Puts AI Workflow Servers at Risk

SecureBulletin · 05/08/2026

Security researchers at Elttam disclosed six separate remote code execution flaws in the Flowise AI workflow platform, spanning CSV processing, sandboxed JavaScript, and database configuration. Severa…

DarkSword Exploit Kit Quietly Expands to 180 Sites, Turning iPhones Into Data-Theft Targets

SecureBulletin · 05/08/2026

A leaked iOS exploit chain known as DarkSword has grown into a sprawling, fast-changing network of malicious infrastructure, with researchers at Censys tracking 27 hosts and 180 web properties designe…

ShinyHunters Strikes Again: Brinks Home Confirms Breach Tied to Salesforce Systems

SecureBulletin · 04/08/2026

Brinks Home has confirmed attackers broke into systems connected to its Salesforce environment after the ShinyHunters extortion crew claimed to have stolen nearly five million records. The company say…

How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline

SecureBulletin · 04/08/2026

Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet add…

Arch Linux Freezes AUR Package Adoptions After Attackers Exploit Abandoned Projects

SecureBulletin · 04/08/2026

Arch Linux has temporarily disabled the ability to adopt orphaned AUR packages after security teams spotted a wave of hostile takeovers followed by malicious code injected through routine-looking comm…

FBI and Allied Governments Warn Companies Are Unknowingly Hiring North Korean Operatives

SecureBulletin · 04/08/2026

A joint advisory from the U.S. State Department, FBI, and partner nations including Japan, the UK, Germany, Canada, and South Korea warns that North Korean IT workers are using stolen identities and f…

865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records

SecureBulletin · 04/08/2026

A breach at Russian VPN provider SplitVPN, formerly NotVPN, has exposed the records of roughly 865,000 users despite the service’s long-standing ‘no logs’ promise. The leaked database reportedly inclu…

The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking

SecureBulletin · 04/08/2026

A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver can also…

SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login

SecureBulletin · 04/08/2026

SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform are urged to pa…

North Korean Hackers Hide Malware Instructions Inside Ethereum Smart Contracts to Drain Crypto Wallets

SecureBulletin · 04/08/2026

A North Korean-linked campaign is using fake macOS update screens to trick victims into pasting a malicious command into Terminal, kicking off an infection chain that hunts for cryptocurrency wallets…

SonicWall VPN Gateways Hit by Zero-Click Root Takeover Chain Tied to INC Ransomware

SecureBulletin · 04/08/2026

Attackers are chaining two SonicWall SMA 1000 series flaws to gain root access to VPN gateways without a password or any user interaction. Researchers at Resecurity tie the campaign to INC Ransomware…

Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw

SecureBulletin · 04/08/2026

A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions…

Dark Web Persona ‘ModernStealer’ Ties Together Alleged Military and Nuclear Regulator Data Leaks

SecureBulletin · 04/08/2026

Threat intelligence firm StealthMole has traced a web of dark forum and Telegram listings advertising alleged military, nuclear, and aerospace data back to a recurring set of contact identifiers tied…

New ‘Pass-ta-key’ Attacks Show How Malware Can Silently Hijack Google’s Synced Passkeys

SecureBulletin · 04/08/2026

Unit 42 researchers have detailed three escalating attack techniques that let malware already on a Windows PC take over Google-synced passkeys without ever triggering a password, PIN, or fingerprint p…