Sicurezza
Cybersecurity, ransomware, privacy
- inSicurezzaDigitale.com — Cybersecurity in italiano IT
- SecureBulletin — Cybersecurity news in English EN
- Ransomfeed Daily News — Daily cybersecurity news EN
2.403 voci in archivio · mostrate 176–200 .
HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel
Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical…
Gig Economy Platform Paidwork Leaks Banking and Personal Data of 23 Million Users
A data breach at gig-economy platform Paidwork has exposed banking details, payout histories, and personal information for more than 23 million users, with the stolen dataset publicly leaked in July a…
Qilin Ransomware Affiliates Exploit Palo Alto Firewall Bypass to Skip Straight Past Perimeter Defenses
A critical PAN-OS authentication bypass, CVE-2026-0257, is being actively exploited by Qilin ransomware affiliates to gain direct VPN access to corporate networks. Arctic Wolf Labs traced multiple Jun…
Un ordine su Uber Eats incastra la banda dietro i giochi-malware PirateFi e BlockBlasters su Steam
L’FBI arresta Zyaire Wilkins, 21 anni, primo indagato pubblicamente noto per una rete di giochi Steam infetti (BlockBlasters, PirateFi, Dashverse, Lunara) che ha rubato 220.000 dollari da 8.000 vittim…
Hugging Face violata da un agente AI autonomo: quando l’attaccante non ha bisogno di un umano
Per la prima volta un grande provider di infrastruttura AI conferma un’intrusione condotta end-to-end da un framework di agenti autonomi: dataset malevolo, escalation e movimento laterale in un intero…
Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution
A remote code execution flaw that has quietly lived inside nginx’s script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious request chain can a…
wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In
A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configurati…
HollowByte: How 11 Bytes Can Quietly Starve an OpenSSL Server to Death
A newly disclosed OpenSSL weakness, dubbed HollowByte, lets an unauthenticated attacker trigger a slow, memory-fragmenting denial-of-service condition using a payload as small as 11 bytes. Because it…
This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire
A packed week in cybersecurity saw Microsoft ship roughly 570 patches including two actively exploited zero-days, a WordPress RCE bug threatening hundreds of millions of sites, and a wave of research…
Scattered Spider smascherata: 5 anni e mezzo di carcere per l’attacco da 29 milioni di sterline a Transport for London
Owen Flowers e Thalha Jubair, membri di Scattered Spider, condannati dalla Woolwich Crown Court per l’intrusione 2024 in Transport for London: 148 sistemi bloccati, 27.000 dipendenti senza credenziali…
Coca-Cola ferma la produzione di Fairlife dopo un attacco ransomware: quando il cybercrime arriva in tavola
Un attacco ransomware ai sistemi produttivi di Fairlife, controllata di Coca-Cola, ha bloccato la produzione statunitense di latte ultrafiltrato. Il caso si inserisce in un pattern crescente di attacc…
Spirals Ransomware: From First Foothold to Full Encryption in Under 24 Hours
A newly identified ransomware strain called Spirals encrypted an entire IT services company’s network in South Asia within a single day, using an IIS web shell, tunneling tools, and PsExec for rapid l…
Hugging Face Breach Reveals a New Front: AI Agents Attacking, AI Agents Defending
Hugging Face has confirmed a production infrastructure intrusion driven by an autonomous AI agent, exploiting two flaws in its dataset processing pipeline. The company’s own AI-based forensic analysis…
Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control
Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local use…
Inside NadMesh: The Shodan-Powered Botnet Hunting Exposed AI Servers
Researchers at XLab have identified NadMesh, a Go-based botnet that uses Shodan to hunt down exposed AI and MCP infrastructure before hijacking it with more than 20 exploitation techniques. The malwar…
EY Notifies Clients After Breach of IT Support Platform Exposes Tax Documents
Ernst & Young is notifying clients that attackers accessed a third-party IT support ticketing platform for roughly two weeks this spring, downloading documents containing sensitive tax and investment…
Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems
Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary suffered a ransomware attack that forced a temporary halt of US production, while Canadian operations continued unaffected. The…
Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts
A newly disclosed Windows zero-day called LegacyHive abuses the User Profile Service to let a low-privileged user tamper with an administrator’s registry hive, opening a path to persistence and code e…
CISA Confirms Active Exploitation of Critical SharePoint Deserialization Flaw
CISA has added CVE-2026-58644, a critical unauthenticated remote code execution flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog after confirming real-world attacks. Federa…
OkoBot: il framework che si inietta in Ledger Live e Trezor Suite per rubare le seed phrase
Kaspersky documenta OkoBot, un framework modulare con oltre venti impianti attivo da aprile 2025: si inietta nei processi Electron di Ledger Live e Trezor Suite mostrando pagine di phishing hard-coded…
GoSerpent: la backdoor Go che spia governi e diplomazie del Sud-Est asiatico
Kaspersky GReAT svela GoSerpent, un RAT scritto in Go usato dal 2021 contro enti governativi e diplomatici del Sud-Est asiatico. La campagna 2026 mostra un’architettura in due fasi — raccolta silenzio…
SonicWall SMA1000 Zero-Days Under Active Attack: Perfect-10 Flaw Chained for Root Access
Attackers were exploiting a maximum-severity SonicWall SMA1000 flaw before the vendor’s advisory even landed, chaining it with a privilege-escalation bug to seize root and pivot into corporate Active…
CISA Sounds Alarm as Attackers Exploit Critical FortiSandbox Command Injection Flaws
CISA has confirmed active exploitation of two OS command injection vulnerabilities in Fortinet’s FortiSandbox product line, adding both to its Known Exploited Vulnerabilities catalog and giving federa…
Critical 7-Zip Flaw Lets Booby-Trapped Archives Hijack Your System
A newly patched 7-Zip vulnerability lets attackers achieve remote code execution simply by getting a victim to open a maliciously crafted compressed file. With 7-Zip installed on millions of machines…
Scattered Spider Duo Sentenced Over £29 Million Transport for London Cyberattack
Two young members of the Scattered Spider hacking collective have been jailed for over five years each after a 2024 breach knocked out 148 Transport for London systems and forced 27,000 staff to reset…