sabato 29 agosto 2026 Privacy RSS Admin
ITAGORA!
Il portale italiano · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > Ransomfeed Daily News

Ransomfeed Daily News EN

Daily cybersecurity news · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

30 voci in archivio · mostrate 1–25 .

Spaggiari Hacked, xpl0itrs Claims 6.1 TB From 3,000+ Italian Schools. Is ClasseViva Safe? - Pasquale Pillitteri

domenica 23 agosto 2026, 10:41

Spaggiari Hacked, xpl0itrs Claims 6.1 TB From 3,000+ Italian Schools. Is ClasseViva Safe? Pasquale Pillitteri. Fonte: https://news.google.com/rss/articles/CBMijwFBVV95cUxOWVcwdnF1UUFsV1dYUnhKWVZDSlBpU3hkc3pSdTZqcWVnN0VnTUtnX01UQzh0Qm1JajF4S…

Japan outlines measures to protect infrastructure from cyberattacks - The Japan Times

domenica 23 agosto 2026, 10:13

Japan outlines measures to protect infrastructure from cyberattacks The Japan Times. Fonte: https://news.google.com/rss/articles/CBMiqgFBVV95cUxQbEJEQ29kb2JycjZJdUNqTUFDTy1zbmdRM0VxSnozeGNDTllnMFRjd0lqZGdjWkhTUjdjM2tEdmtQT1dRQU5Pc3hZaWpQaEd…

Mustang Panda Deploys SolidPDFCreator Stage-1 Backdoor Against India Targets

lunedì 13 luglio 2026, 15:09

Researchers identified a Windows DLL backdoor dubbed SolidPDFCreator and attributed it to the China-linked threat group Mustang Panda, describing the malware as a stage-1 backdoor used in a campaign targeting entities in India. The sample w…

OAuth Client ID Spoofing Enables Stealthy Microsoft Entra Account Enumeration

lunedì 13 luglio 2026, 15:08

Proofpoint reported that attackers are increasingly abusing OAuth client ID spoofing against Microsoft Entra ID to enumerate accounts and validate credentials without registering a legitimate OAuth application. The activity relies on Resour…

Ghostcommit Uses PNG-Hidden Prompts to Make AI Coding Agents Leak Secrets

lunedì 13 luglio 2026, 15:08

Researchers disclosed Ghostcommit, a proof-of-concept software supply-chain attack that hides prompt-injection instructions inside a PNG image referenced by an AGENTS.md file, allowing malicious pull requests to appear benign during review…

Allies Attribute Turla Espionage and Router Intrusions to Russia’s FSB Centre 16

lunedì 13 luglio 2026, 15:05

The UK, France, the EU, and partner cyber agencies publicly attributed a broad cyber-espionage campaign to FSB Centre 16, linking the Russian intelligence unit to both the long-running Turla intrusion set and active exploitation of internet…

CERT Polska Discloses Four Vulnerabilities in GNU gawk

lunedì 13 luglio 2026, 14:05

CERT Polska disclosed four vulnerabilities in GNU gawk, tracked as CVE-2026-40467, CVE-2026-40468, CVE-2026-40469, and CVE-2026-40553. The issues were highlighted in a CERT Polska advisory and later amplified by security reporting, identify…

Debian 13.6 Ships Broad Security Fixes and Secure Boot Certificate Updates

lunedì 13 luglio 2026, 02:06

Debian has released Debian 13.6 as a point update focused on security and maintenance, alongside Debian 12.15 for the previous stable branch. Debian 13.6 bundles roughly 120 security updates and more than 120 bug fixes, with patches affecti…

Ryuk Operator Pleads Guilty as BlackCat Negotiator Gets Prison Sentence

lunedì 13 luglio 2026, 01:06

U.S. prosecutors announced two significant ransomware case outcomes: Armenian national Karen Serobovich Vardanyan pleaded guilty to conspiracy and computer fraud for helping compromise U.S. organizations and deploy Ryuk ransomware, while Fl…

Keycloak fixes FGAPv2 privilege escalation and multiple access control flaws

lunedì 13 luglio 2026, 00:53

Keycloak disclosed and patched a high-severity privilege escalation flaw, CVE-2026-9795, in its Fine-Grained Admin Permissions v2 (FGAPv2) feature after researchers reported that a delegated administrator could bypass missing authorization…

Google and FBI Disrupt NetNut Residential Proxy Network Used by Malware Operators

martedì 7 luglio 2026, 14:10

Google said it disrupted NetNut—also known as Popa—a large residential proxy network that investigators linked to malware delivery, command-and-control activity, and efforts by cybercriminal and espionage actors to mask their origin IP addr…

Alibaba Bans Claude Code Over Alleged Hidden China-Detection Logic

martedì 7 luglio 2026, 14:09

Alibaba has ordered employees to stop using Anthropic’s Claude Code for work and reportedly directed them to remove other Anthropic products, classifying the software as high risk over alleged security vulnerabilities and backdoor concerns…

Multiple Open Source Projects Disclose High-Impact RCE, Injection, and Traversal Flaws

martedì 7 luglio 2026, 07:21

Several open source projects disclosed serious vulnerabilities affecting developer and infrastructure tooling, including remote code execution, SQL injection, server-side request forgery, prompt-driven query injection, and path traversal. C…

Adobe ColdFusion RDS File-Write Flaw Faces Active Exploitation

martedì 7 luglio 2026, 04:04

Adobe ColdFusion is facing active exploitation of CVE-2026-48282, a maximum-severity flaw tied to RDS arbitrary file write that can be abused without privileges on unpatched servers. The Canadian Centre for Cyber Security warned that open-s…

France to End Certification of Non-Quantum-Safe Encryption Products

martedì 7 luglio 2026, 02:06

France's cybersecurity agency, ANSSI, said it will stop certifying security products that lack post-quantum or quantum-resistant encryption beginning in 2027. Because ANSSI certification is required for products used by French government ag…

Teen Arrested for Bandai Channel Attack That Canceled 46,000 Subscriptions

martedì 7 luglio 2026, 01:07

Japanese police arrested a 15-year-old high school student from Saitama Prefecture for allegedly carrying out a sustained cyberattack against Bandai Channel, the anime streaming service operated by Bandai Namco Filmworks. Investigators said…

OpenSSH 10.4 fixes multiple flaws and adds optional post-quantum signatures

martedì 7 luglio 2026, 00:06

OpenSSH has released version 10.4 with eight security fixes affecting both client and server components, including sftp, scp, sshd, ssh, ssh-agent, and cryptographic verification logic. The update addresses path traversal-style and file red…

Microsoft Edge Patches Multiple High-Severity RCE and Security Bypass Flaws

lunedì 6 luglio 2026, 06:04

Microsoft Edge (Chromium-based) has received fixes for multiple high-severity vulnerabilities, including remote code execution flaws CVE-2026-58289, CVE-2026-58293, CVE-2026-58285, CVE-2026-58288, CVE-2026-57974, CVE-2026-58284, CVE-2026-58…

Malicious npm Rollup Polyfills Linked to Lazarus Target Developer Environments

lunedì 6 luglio 2026, 04:05

Researchers identified a malicious npm supply-chain campaign that impersonated Rollup polyfill tooling to compromise developer workstations and CI/build systems. The primary packages, rollup-packages-polyfill-core and rollup-runtime-polyfil…

Medtronic Data Breach Exposed Personal and Health Information in ShinyHunters Attack

domenica 5 luglio 2026, 23:04

Medtronic disclosed that unauthorized actors accessed certain corporate IT systems between April 13 and April 19, exposing personal and health-related information tied to 3,834,294 individuals. The company said the incident was detected aft…

Linux Kernel Flaws Expose Systems to Local Root Escalation

domenica 5 luglio 2026, 19:07

Researchers disclosed two separate Linux kernel privilege-escalation flaws that can give local attackers root access across a wide range of systems, including servers, desktops, and Android devices. One bug, CVE-2026-46242 or Bad Epoll, is…

PolinRider Supply Chain Campaign Hijacks Developer Packages and Uses Blockchain Dead Drops

domenica 5 luglio 2026, 19:06

Researchers reported a broad software supply chain campaign targeting developers and cryptocurrency users through hijacked packages, browser extensions, and compromised maintainer accounts across ecosystems including npm, Go, Chrome, and Pa…

PamStealer macOS Infostealer Uses Fake Maccy Apps and PAM Password Validation

venerdì 3 luglio 2026, 11:12

Researchers have identified PamStealer, a previously unseen macOS malware family distributed through fake websites impersonating the legitimate Maccy clipboard manager. The infection begins with a trojanized disk image and a compiled AppleS…

Pegasus Infected European Parliament Spyware Investigator’s iPhone

venerdì 3 luglio 2026, 10:05

Citizen Lab found that the iPhone of former European Parliament member Stelios Kouloglou was infected twice with NSO Group’s Pegasus spyware, in October 2022 and March 2023, while he served on the Parliament’s PEGA Committee investigating s…

Anthropic Publishes Claude Fable 5 Cyber Safeguards and Jailbreak Severity Framework

venerdì 3 luglio 2026, 08:05

Anthropic said it has globally re-deployed Claude Fable 5 with updated cybersecurity controls and released new technical details on how the model handles cyber-related prompts. The company said the system uses safety classifiers to sort req…