Home > Directory > Sicurezza > Ransomfeed Daily News
Ransomfeed Daily News EN
Daily cybersecurity news · visibilità: nel misto della home, non in primo piano.
Sito originale · Feed RSS della fonte
30 voci in archivio · mostrate 1–25 .
Spaggiari Hacked, xpl0itrs Claims 6.1 TB From 3,000+ Italian Schools. Is ClasseViva Safe? - Pasquale Pillitteri
Spaggiari Hacked, xpl0itrs Claims 6.1 TB From 3,000+ Italian Schools. Is ClasseViva Safe? Pasquale Pillitteri. Fonte: https://news.google.com/rss/articles/CBMijwFBVV95cUxOWVcwdnF1UUFsV1dYUnhKWVZDSlBpU3hkc3pSdTZqcWVnN0VnTUtnX01UQzh0Qm1JajF4S…
Japan outlines measures to protect infrastructure from cyberattacks - The Japan Times
Japan outlines measures to protect infrastructure from cyberattacks The Japan Times. Fonte: https://news.google.com/rss/articles/CBMiqgFBVV95cUxQbEJEQ29kb2JycjZJdUNqTUFDTy1zbmdRM0VxSnozeGNDTllnMFRjd0lqZGdjWkhTUjdjM2tEdmtQT1dRQU5Pc3hZaWpQaEd…
Mustang Panda Deploys SolidPDFCreator Stage-1 Backdoor Against India Targets
Researchers identified a Windows DLL backdoor dubbed SolidPDFCreator and attributed it to the China-linked threat group Mustang Panda, describing the malware as a stage-1 backdoor used in a campaign targeting entities in India. The sample w…
OAuth Client ID Spoofing Enables Stealthy Microsoft Entra Account Enumeration
Proofpoint reported that attackers are increasingly abusing OAuth client ID spoofing against Microsoft Entra ID to enumerate accounts and validate credentials without registering a legitimate OAuth application. The activity relies on Resour…
Ghostcommit Uses PNG-Hidden Prompts to Make AI Coding Agents Leak Secrets
Researchers disclosed Ghostcommit, a proof-of-concept software supply-chain attack that hides prompt-injection instructions inside a PNG image referenced by an AGENTS.md file, allowing malicious pull requests to appear benign during review…
Allies Attribute Turla Espionage and Router Intrusions to Russia’s FSB Centre 16
The UK, France, the EU, and partner cyber agencies publicly attributed a broad cyber-espionage campaign to FSB Centre 16, linking the Russian intelligence unit to both the long-running Turla intrusion set and active exploitation of internet…
CERT Polska Discloses Four Vulnerabilities in GNU gawk
CERT Polska disclosed four vulnerabilities in GNU gawk, tracked as CVE-2026-40467, CVE-2026-40468, CVE-2026-40469, and CVE-2026-40553. The issues were highlighted in a CERT Polska advisory and later amplified by security reporting, identify…
Debian 13.6 Ships Broad Security Fixes and Secure Boot Certificate Updates
Debian has released Debian 13.6 as a point update focused on security and maintenance, alongside Debian 12.15 for the previous stable branch. Debian 13.6 bundles roughly 120 security updates and more than 120 bug fixes, with patches affecti…
Ryuk Operator Pleads Guilty as BlackCat Negotiator Gets Prison Sentence
U.S. prosecutors announced two significant ransomware case outcomes: Armenian national Karen Serobovich Vardanyan pleaded guilty to conspiracy and computer fraud for helping compromise U.S. organizations and deploy Ryuk ransomware, while Fl…
Keycloak fixes FGAPv2 privilege escalation and multiple access control flaws
Keycloak disclosed and patched a high-severity privilege escalation flaw, CVE-2026-9795, in its Fine-Grained Admin Permissions v2 (FGAPv2) feature after researchers reported that a delegated administrator could bypass missing authorization…
Google and FBI Disrupt NetNut Residential Proxy Network Used by Malware Operators
Google said it disrupted NetNut—also known as Popa—a large residential proxy network that investigators linked to malware delivery, command-and-control activity, and efforts by cybercriminal and espionage actors to mask their origin IP addr…
Alibaba Bans Claude Code Over Alleged Hidden China-Detection Logic
Alibaba has ordered employees to stop using Anthropic’s Claude Code for work and reportedly directed them to remove other Anthropic products, classifying the software as high risk over alleged security vulnerabilities and backdoor concerns…
Multiple Open Source Projects Disclose High-Impact RCE, Injection, and Traversal Flaws
Several open source projects disclosed serious vulnerabilities affecting developer and infrastructure tooling, including remote code execution, SQL injection, server-side request forgery, prompt-driven query injection, and path traversal. C…
Adobe ColdFusion RDS File-Write Flaw Faces Active Exploitation
Adobe ColdFusion is facing active exploitation of CVE-2026-48282, a maximum-severity flaw tied to RDS arbitrary file write that can be abused without privileges on unpatched servers. The Canadian Centre for Cyber Security warned that open-s…
France to End Certification of Non-Quantum-Safe Encryption Products
France's cybersecurity agency, ANSSI, said it will stop certifying security products that lack post-quantum or quantum-resistant encryption beginning in 2027. Because ANSSI certification is required for products used by French government ag…
Teen Arrested for Bandai Channel Attack That Canceled 46,000 Subscriptions
Japanese police arrested a 15-year-old high school student from Saitama Prefecture for allegedly carrying out a sustained cyberattack against Bandai Channel, the anime streaming service operated by Bandai Namco Filmworks. Investigators said…
OpenSSH 10.4 fixes multiple flaws and adds optional post-quantum signatures
OpenSSH has released version 10.4 with eight security fixes affecting both client and server components, including sftp, scp, sshd, ssh, ssh-agent, and cryptographic verification logic. The update addresses path traversal-style and file red…
Microsoft Edge Patches Multiple High-Severity RCE and Security Bypass Flaws
Microsoft Edge (Chromium-based) has received fixes for multiple high-severity vulnerabilities, including remote code execution flaws CVE-2026-58289, CVE-2026-58293, CVE-2026-58285, CVE-2026-58288, CVE-2026-57974, CVE-2026-58284, CVE-2026-58…
Malicious npm Rollup Polyfills Linked to Lazarus Target Developer Environments
Researchers identified a malicious npm supply-chain campaign that impersonated Rollup polyfill tooling to compromise developer workstations and CI/build systems. The primary packages, rollup-packages-polyfill-core and rollup-runtime-polyfil…
Medtronic Data Breach Exposed Personal and Health Information in ShinyHunters Attack
Medtronic disclosed that unauthorized actors accessed certain corporate IT systems between April 13 and April 19, exposing personal and health-related information tied to 3,834,294 individuals. The company said the incident was detected aft…
Linux Kernel Flaws Expose Systems to Local Root Escalation
Researchers disclosed two separate Linux kernel privilege-escalation flaws that can give local attackers root access across a wide range of systems, including servers, desktops, and Android devices. One bug, CVE-2026-46242 or Bad Epoll, is…
PolinRider Supply Chain Campaign Hijacks Developer Packages and Uses Blockchain Dead Drops
Researchers reported a broad software supply chain campaign targeting developers and cryptocurrency users through hijacked packages, browser extensions, and compromised maintainer accounts across ecosystems including npm, Go, Chrome, and Pa…
PamStealer macOS Infostealer Uses Fake Maccy Apps and PAM Password Validation
Researchers have identified PamStealer, a previously unseen macOS malware family distributed through fake websites impersonating the legitimate Maccy clipboard manager. The infection begins with a trojanized disk image and a compiled AppleS…
Pegasus Infected European Parliament Spyware Investigator’s iPhone
Citizen Lab found that the iPhone of former European Parliament member Stelios Kouloglou was infected twice with NSO Group’s Pegasus spyware, in October 2022 and March 2023, while he served on the Parliament’s PEGA Committee investigating s…
Anthropic Publishes Claude Fable 5 Cyber Safeguards and Jailbreak Severity Framework
Anthropic said it has globally re-deployed Claude Fable 5 with updated cybersecurity controls and released new technical details on how the model handles cyber-related prompts. The company said the system uses safety classifiers to sort req…