Sicurezza
Cybersecurity, ransomware, privacy
- inSicurezzaDigitale.com — Cybersecurity in italiano IT
- SecureBulletin — Cybersecurity news in English EN
- Ransomfeed Daily News — Daily cybersecurity news EN
2.403 voci in archivio · mostrate 151–175 .
Email bombing, finto IT support e un’estensione Edge che evade la sandbox: la tradecraft di UNC6692
eSentire TRU ricostruisce la catena d’attacco dell’initial access broker UNC6692: email bombing, impersonificazione IT su Microsoft Teams, Quick Assist e l’estensione malevola Edgecution, capace di ev…
Un agente IA in modalità YOLO contro il Ministero delle Finanze thailandese: dentro l’operazione Hermes/Hades
Un server esposto a Hong Kong ha rivelato i log di Hermes, un agente IA open source lasciato operare senza supervisione umana contro il Ministero delle Finanze thailandese, e Hades, un impianto Go ine…
Funky Mantis: la gang ransomware DevMan si dota di un CRM per gestire estorsioni contro ospedali e fabbriche
Le chat interne del gruppo ransomware-as-a-service Funky Mantis (DevMan), analizzate da Catalyst Prodaft, rivelano una piattaforma centralizzata con funzioni da CRM per coordinare affiliati, reti comp…
How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers
Three critical, now-patched vulnerabilities in Microsoft’s infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Resear…
Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory
A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain Controller…
Cl0p Affiliates Are Breaching PTC Windchill Servers to Steal Product Blueprints Before Extortion
Cl0p-linked attackers are chaining an unauthenticated information disclosure bug with a critical deserialization flaw in PTC Windchill and FlexPLM to steal engineering and product-design data from man…
Fake Claude Desktop Ads on Bing Are Delivering SectopRAT to Corporate Networks
A campaign dubbed FakeAgent used paid Bing search ads and a malicious public Claude Artifact to trick corporate employees into installing a disguised remote access trojan. At least 29 organizations we…
Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs
Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, an…
Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel
Cisco Talos has identified msaRAT, a Rust-based tool tied to the Chaos ransomware group that quietly launches Chrome or Edge in headless mode and turns the browser into a covert command-and-control ch…
Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server’s directory listing wide open. The exposed files revealed a prev…
Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum
A threat actor is advertising what they claim is a Decathlon customer database of roughly 160 million records on an underground forum, seeking cryptocurrency payment. Decathlon has not confirmed the b…
Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco
Proofpoint svela Cruciferra, servizio di crypter venduto su forum underground che combina BYOVD, syscall indiretti e una variante di Process Ghosting per proteggere AsyncRAT, Agent Tesla, Remcos e alt…
Cl0p sfrutta una falla critica in PTC Windchill e FlexPLM: webshell ed estorsioni nella supply chain del manufacturing
La gang Cl0p, nota per gli attacchi di massa a MOVEit e GoAnywhere, sta ora sfruttando CVE-2026-12569 in PTC Windchill e FlexPLM per compromettere aziende manifatturiere, automotive, aerospaziali e re…
ASUS Rushes Out Router Patch After Discovery of Unauthenticated Remote Command Execution Flaw
ASUS has issued firmware updates for a high-severity vulnerability, tracked as CVE-2026-13385, that could let remote attackers run arbitrary commands on widely deployed router models without authentic…
RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root
Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel’s XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no trace…
HermeticReader: How a Bug in Adobe’s PDF Browser Extension Could Expose WhatsApp Chats to Any Website
Researchers at Guardio Labs disclosed a flaw in the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, that let a malicious website silently read a victim’s open WhatsApp Web c…
Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access
A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial s…
Fake Game Downloads Are Quietly Installing Amatera Stealer Through a Disguised RenPy Loader
A malware campaign is hiding behind fake games, cracks, and mods to install Amatera Stealer, a multi-stage infostealer that harvests browser credentials, messaging data, and cryptocurrency wallets. Th…
Operation Olympus Blade: BKA e FBI smantellano Kratos, il phishing-as-a-service da 1.800 clienti in 35 paesi
Le autorità tedesche e statunitensi hanno sequestrato oltre 200 server e arrestato in Indonesia lo sviluppatore di Kratos, piattaforma PhaaS con tecniche AiTM usata da 1.800 clienti per 15.000 campagn…
PhantomEnigma: How a Malware Crew Turned Brazilian Government Sites Into Trusted Malware Hubs
A campaign tracked as PhantomEnigma has compromised more than 20 official Brazilian government websites, using them to host and deliver malware that passes email authentication checks and slips past a…
Chrome’s Latest Patch Closes 12 Security Holes, Nine of Them Rated High Severity
Google has shipped a new Stable Chrome release fixing 12 vulnerabilities, nine of them high severity, touching core components like V8, ANGLE, and the GPU stack. Several of the bugs involve memory-cor…
Unauthenticated Attackers Are Actively Exploiting a ServiceNow Sandbox-Escape Flaw
A critical ServiceNow vulnerability that lets unauthenticated attackers break out of the platform’s scripting sandbox is now being exploited in the wild. ServiceNow has shipped patches, but self-hoste…
HollowGraph: la backdoor che trasforma il calendario di Microsoft 365 in un canale C2 cifrato
Group-IB ha scoperto HollowGraph, un impianto legato al framework iraniano Cavern che usa eventi di calendario Microsoft 365 datati al 2050 come dead drop per comandi e dati rubati, mascherando tutto…
World Leaks nel cuore del nucleare indiano: 19.000 file della centrale di Kudankulam in vendita sul dark web
La gang di data extortion World Leaks, erede di Hunters International, ha pubblicato quasi 19.000 file riservati dell’appaltatore Reliance Infrastructure legati alla più grande centrale nucleare india…
New Windows ‘Bind Link’ Trick Lets Attackers Fool EDR, AMSI, and AppLocker Without Touching a File
Bitdefender researchers have detailed how Windows ‘bind links’ — a legitimate feature behind containers and Sandbox — can be abused by an attacker with local admin rights to redirect trusted file path…