domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.403 voci in archivio · mostrate 126–150 .

Un attacco informatico spegne 21 milioni di angolani alla vigilia della più grande IPO del paese: cosa sappiamo su Unitel

inSicurezzaDigitale.com · 02/08/2026

Poche ore prima del debutto in borsa di Unitel, il maggiore operatore telco dell’Angola, un attacco informatico ha messo fuori uso voce, dati mobili e SMS per oltre 21 milioni di persone. La telemetri…

Flying Eagle: il RAT Android che spiava per conto della «polizia cinese» finisce nelle mani sbagliate

inSicurezzaDigitale.com · 02/08/2026

Il codice sorgente del framework spyware Flying Eagle, dietro una finta app della polizia cinese, è trapelato su Telegram. Hunt.io mappa 170 server attivi mentre tra i criminali scoppia una guerra int…

BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server

SecureBulletin · 01/08/2026

China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the v…

Fake macOS Update Screens Are Tricking Mac Users Into Handing Over Crypto Wallets

SecureBulletin · 01/08/2026

A North Korea-linked campaign is using fake ‘Installing System Update’ overlays to trick victims into pasting malicious commands into Terminal, deploying a backdoor that raids 157 cryptocurrency walle…

Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope

SecureBulletin · 01/08/2026

A broken access control bug (CVE-2026-17059) in Keycloak’s Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue is fixed…

Unauthenticated RCE Flaw in JetBrains TeamCity Puts Software Supply Chains at Risk

SecureBulletin · 01/08/2026

JetBrains has patched a critical, unauthenticated remote code execution flaw (CVE-2026-63077) in TeamCity On-Premises that could let attackers hijack build servers and tamper with software releases. A…

Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns

SecureBulletin · 31/07/2026

CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intr…

Claude Broke Out of a Sandboxed Security Test and Hit Three Real Companies, Anthropic Admits

SecureBulletin · 31/07/2026

Anthropic says a review of 141,000 evaluation transcripts turned up three cases where Claude models, told they were operating in an isolated capture-the-flag simulation, instead reached the live inter…

Chipmaker Analog Devices Confirms Breach as Extortion Group Claims 570,000 Stolen Records

SecureBulletin · 31/07/2026

Analog Devices has confirmed unauthorized access to internal systems and file exfiltration in an SEC filing, weeks after a group calling itself ExfilSquad listed the semiconductor giant on its leak si…

GenieLocker: A New Cross-Platform Ransomware Hitting Windows, Linux and ESXi Alike

SecureBulletin · 31/07/2026

Researchers have identified GenieLocker, a new ransomware strain built by the financially motivated Toy Ghouls group to hit Windows, Linux and VMware ESXi environments in one campaign. The group has u…

RedRelay: la società fantasma cinese che nasconde le operazioni cyber del PLA dietro un brevetto per spiare Telegram

inSicurezzaDigitale.com · 30/07/2026

Il collettivo Intrusion Truth ha identificato Guangdong Chanming, una società invisibile online che avrebbe costruito RedRelay (ORBWEAVER), l’ORB network usata da APT15/Ke3chang e da altri cluster leg…

Operation Double Barrel: quando lo spionaggio di stato nordcoreano condivide l’infrastruttura con il ransomware Gunra

inSicurezzaDigitale.com · 30/07/2026

Un’advisory congiunta di NIS, NPA, KISA e FSI, basata su AhnLab ASEC, svela un anno e mezzo di attacchi state-sponsored contro la Corea del Sud tramite i backdoor Struggle/SIGNBT 3.0 e Brandoor/COPPER…

Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm

SecureBulletin · 30/07/2026

A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself into every new file it touche…

Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads

SecureBulletin · 30/07/2026

A critical vulnerability in Rails’ Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on ap…

FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys

SecureBulletin · 30/07/2026

The FBI says Russian intelligence-linked hacking clusters are impersonating Signal support to trick high-value targets — officials, military personnel, journalists, and Ukrainian leadership — into rev…

Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware

SecureBulletin · 30/07/2026

Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords…

JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia

inSicurezzaDigitale.com · 27/07/2026

Un server Alibaba Cloud lasciato esposto ha rivelato JadeProx, cluster China-nexus dietro intrusioni contro un ospedale vietnamita, il Ministero degli Esteri malese e l’ateneo di Hong Kong. Al centro…

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab

SecureBulletin · 27/07/2026

Researchers chained two long-dormant memory-safety bugs in Ruby’s Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and a cra…

Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows

SecureBulletin · 27/07/2026

A privilege-escalation flaw in Foxit PDF Reader’s updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all the way to full SYSTE…

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity

SecureBulletin · 27/07/2026

JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git rep…

A Booby-Trapped Git Repository Can Quietly Leak Files Through Claude Code, Researchers Show

SecureBulletin · 27/07/2026

Security firm Tego AI says an ordinary-looking repository file can trick Anthropic’s Claude Code into reading a file from outside the project and silently including it in its first request to the mode…

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

SecureBulletin · 27/07/2026

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin panels, and t…

OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents

SecureBulletin · 27/07/2026

Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI agent inside a vi…

Claude AI’s Shared Chat Links Briefly Turned Up in Google Search, Exposing Private Conversations

SecureBulletin · 27/07/2026

Hundreds of Claude AI shared-chat links reportedly became publicly searchable on Google over the weekend, exposing legal advice, proprietary code, and personal conversations to anyone who searched for…

Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict

SecureBulletin · 27/07/2026

A new analysis maps the loosely coordinated network of pro-Iran hacktivist groups, state-aligned actors, and opportunistic allies that have ramped up disruptive cyber campaigns since US and Israeli st…