domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza

Sicurezza

Cybersecurity, ransomware, privacy

Fonti in questa categoria

2.403 voci in archivio · mostrate 201–225 .

SS7, il protocollo del 1970 che ha tradito i soldati USA: come l’Iran ha tracciato le truppe americane in Medio Oriente

inSicurezzaDigitale.com · 16/07/2026

Un’indagine di Mobile Surveillance Monitor, ripresa dal Financial Times, sostiene che l’Iran abbia sfruttato le debolezze del protocollo SS7 e dati di ad-tech commerciale per localizzare personale mil…

Le telecamere spia di Mosca: come l’intelligence russa sorveglia le rotte NATO verso l’Ucraina

inSicurezzaDigitale.com · 16/07/2026

AIVD e MIVD, le agenzie di intelligence olandesi, hanno rivelato una campagna russa che sfrutta telecamere IP e videocitofoni smart con password di default per monitorare in tempo reale il trasporto d…

Mustang Panda Deploys SolidPDFCreator Stage-1 Backdoor Against India Targets

Ransomfeed Daily News · 13/07/2026

Researchers identified a Windows DLL backdoor dubbed SolidPDFCreator and attributed it to the China-linked threat group Mustang Panda, describing the malware as a stage-1 backdoor used in a campaign t…

OAuth Client ID Spoofing Enables Stealthy Microsoft Entra Account Enumeration

Ransomfeed Daily News · 13/07/2026

Proofpoint reported that attackers are increasingly abusing OAuth client ID spoofing against Microsoft Entra ID to enumerate accounts and validate credentials without registering a legitimate OAuth ap…

Ghostcommit Uses PNG-Hidden Prompts to Make AI Coding Agents Leak Secrets

Ransomfeed Daily News · 13/07/2026

Researchers disclosed Ghostcommit, a proof-of-concept software supply-chain attack that hides prompt-injection instructions inside a PNG image referenced by an AGENTS.md file, allowing malicious pull…

Allies Attribute Turla Espionage and Router Intrusions to Russia’s FSB Centre 16

Ransomfeed Daily News · 13/07/2026

The UK, France, the EU, and partner cyber agencies publicly attributed a broad cyber-espionage campaign to FSB Centre 16, linking the Russian intelligence unit to both the long-running Turla intrusion…

CERT Polska Discloses Four Vulnerabilities in GNU gawk

Ransomfeed Daily News · 13/07/2026

CERT Polska disclosed four vulnerabilities in GNU gawk, tracked as CVE-2026-40467, CVE-2026-40468, CVE-2026-40469, and CVE-2026-40553. The issues were highlighted in a CERT Polska advisory and later a…

Basta un npm install: la 8.14.0 di jscrambler distribuiva un infostealer Rust nelle pipeline di sviluppo

inSicurezzaDigitale.com · 13/07/2026

La versione 8.14.0 del popolare pacchetto npm jscrambler è stata compromessa con un preinstall hook che eseguiva silenziosamente un infostealer Rust multipiattaforma, mirato a credenziali cloud, walle…

Il negoziatore infedele: come un consulente anti-ransomware ha tradito i suoi clienti per BlackCat

inSicurezzaDigitale.com · 13/07/2026

Angelo Martino, ex negoziatore ransomware per una società USA di incident response, è stato condannato a 70 mesi di carcere per aver passato informazioni riservate sulle trattative dei clienti alla ga…

Debian 13.6 Ships Broad Security Fixes and Secure Boot Certificate Updates

Ransomfeed Daily News · 13/07/2026

Debian has released Debian 13.6 as a point update focused on security and maintenance, alongside Debian 12.15 for the previous stable branch. Debian 13.6 bundles roughly 120 security updates and more…

Ryuk Operator Pleads Guilty as BlackCat Negotiator Gets Prison Sentence

Ransomfeed Daily News · 13/07/2026

U.S. prosecutors announced two significant ransomware case outcomes: Armenian national Karen Serobovich Vardanyan pleaded guilty to conspiracy and computer fraud for helping compromise U.S. organizati…

Keycloak fixes FGAPv2 privilege escalation and multiple access control flaws

Ransomfeed Daily News · 13/07/2026

Keycloak disclosed and patched a high-severity privilege escalation flaw, CVE-2026-9795, in its Fine-Grained Admin Permissions v2 (FGAPv2) feature after researchers reported that a delegated administr…

CISA aggiunge Langflow e Joomla al catalogo KEV: una IDOR ruba le chiavi degli agenti AI, uno zero-day PHP infetta i siti in un solo POST

inSicurezzaDigitale.com · 11/07/2026

Quattro CVE critiche entrano nel catalogo Known Exploited Vulnerabilities di CISA: un IDOR cross-tenant in Langflow usato per rubare chiavi LLM e AWS, e due zero-day di file upload non autenticato in…

Il Canada svela le sue cyber-armi: la CSE rivendica l’hackeraggio di una gang ransomware-as-a-service

inSicurezzaDigitale.com · 09/07/2026

Il rapporto annuale del Communications Security Establishment canadese rivela tre operazioni cyber offensive contro trafficanti di fentanyl, un gruppo estremista e una gang ransomware-as-a-service che…

Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

inSicurezzaDigitale.com · 09/07/2026

Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colp…

GDID: come Microsoft ha aiutato l’FBI a incastrare un presunto membro di Scattered Spider

inSicurezzaDigitale.com · 08/07/2026

Atti giudiziari desecretati rivelano come il Global Device Identifier (GDID) di Windows abbia aiutato FBI e Microsoft a identificare Peter Stokes, 19enne accusato di appartenere a Scattered Spider. Da…

Accenture Data Breach: Hackers Claim Theft of 35 GB of Source Code and Azure Credentials

SecureBulletin · 08/07/2026

A threat actor known as “888” claims to have stolen 35 GB of Accenture source code, RSA/SSH keys, and Azure access tokens, offering the data for sale in Monero. Accenture has confirmed a breach but di…

The Gentlemen Ransomware: Custom EDR/AV Killers Fuel Rapid Global Expansion

SecureBulletin · 08/07/2026

The Gentlemen ransomware group, tracked by Microsoft as Storm-2697, has claimed over 500 victims in 70+ countries using a custom EDR/AV-killing toolkit called GentleKiller and a self-propagating worm…

Rogue Agent: Critical GCP Dialogflow Flaw Let Attackers Inject Malicious Code Into AI Chatbots

SecureBulletin · 08/07/2026

Varonis Threat Labs disclosed a critical Dialogflow CX flaw, dubbed Rogue Agent, that let attackers with a single edit permission inject persistent malicious code into shared chatbot execution environ…

GitLost: How a Single GitHub Issue Can Trick AI Agents Into Leaking Private Repos

SecureBulletin · 08/07/2026

Researchers at Noma Labs disclosed GitLost, a prompt-injection flaw that let a single crafted GitHub Issue trick AI-powered Agentic Workflows into leaking private repository contents publicly, using a…

Google and FBI Disrupt NetNut Residential Proxy Network Used by Malware Operators

Ransomfeed Daily News · 07/07/2026

Google said it disrupted NetNut—also known as Popa—a large residential proxy network that investigators linked to malware delivery, command-and-control activity, and efforts by cybercriminal and espio…

Alibaba Bans Claude Code Over Alleged Hidden China-Detection Logic

Ransomfeed Daily News · 07/07/2026

Alibaba has ordered employees to stop using Anthropic’s Claude Code for work and reportedly directed them to remove other Anthropic products, classifying the software as high risk over alleged securit…

Cavern Manticore: Iranian-Linked APT Abuses SysAid RMM and DLL Sideloading to Deploy Modular C2 Framework

SecureBulletin · 07/07/2026

A newly identified Iranian-linked group, Cavern Manticore, is abusing the SysAid RMM platform and DLL sideloading via WinDirStat to deploy a modular C2 framework against Israeli organizations. Check P…

Tenda Router Backdoor (CVE-2026-11405) Lets Attackers Skip Login and Seize Full Admin Control

SecureBulletin · 07/07/2026

A hardcoded authentication backdoor in Tenda FH1201, W15E, AC10, AC5, and AC6 routers (CVE-2026-11405) lets attackers log in as admin with any username. The undocumented flaw sits in the device web se…

Januscape: 16-Year-Old Linux KVM Flaw (CVE-2026-53359) Lets Malicious VMs Corrupt Host Kernel Memory

SecureBulletin · 07/07/2026

A 16-year-old flaw in Linux KVM, tracked as CVE-2026-53359 and dubbed Januscape, lets a malicious guest VM corrupt host kernel memory via a use-after-free in the shadow MMU’s nested virtualization pat…