lunedì 31 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > SecureBulletin

SecureBulletin EN

Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

903 voci in archivio · mostrate 251–275 .

UNC3753 (Luna Moth) Escalates Campaign Against US Law Firms: Vishing, RMM Tools, and Now Physical Intrusion

mercoledì 10 giugno 2026, 10:28

Google Cloud Mandiant has documented a sustained UNC3753 (Luna Moth) campaign targeting US law firms from January–May 2026. The group uses vishing calls and RMM tools to exfiltrate gigabytes of legal data within hours, and has now escalated…

SAP June 2026 Patch Day: Four Critical Flaws Including CVSS 9.9 SAML Bypass in NetWeaver ABAP

mercoledì 10 giugno 2026, 10:27

SAP’s June 2026 Security Patch Day addressed 15 security notes including four critical vulnerabilities. The most severe — CVE-2026-44748 (CVSS 9.9) — is an XML Signature Wrapping flaw in SAP NetWeaver ABAP’s SAML authentication spanning ver…

Meet Pink: The New Extortion Group Using Vishing and Microsoft 365 Tools to Drain Enterprise Cloud Storage

mercoledì 10 giugno 2026, 10:27

A new extortion group called Pink (CL-CRI-1147) has emerged, targeting enterprise organizations through voice phishing to steal Microsoft 365 credentials and cloud files. With ties to the Com network and tactical similarities to Scattered S…

Google Chrome 149 Patches 429 Vulnerabilities Including 22 Critical — Update Immediately

mercoledì 10 giugno 2026, 10:26

Google has released Chrome 149.0.7827.53 with 429 security fixes, including 22 rated critical. The patch covers use-after-free and memory corruption bugs across ANGLE, GPU, Network, Password Manager, and Chrome for iOS — one of the largest…

CVE-2026-50751: Check Point VPN 0-Day Actively Exploited to Deploy Qilin Ransomware

martedì 9 giugno 2026, 14:03

A critical CVSS 9.3 authentication bypass in Check Point Remote Access VPN (CVE-2026-50751) is being actively exploited in the wild, with confirmed post-compromise activity linked to the Qilin ransomware gang. Exploitation has been ongoing…

CVE-2026-23111: Linux Kernel nftables Use-After-Free Enables Root Privilege Escalation — Public Exploit Available

martedì 9 giugno 2026, 14:03

A use-after-free vulnerability in the Linux kernel nftables subsystem (CVE-2026-23111) allows unprivileged local attackers to escalate privileges to root on Debian and Ubuntu LTS systems. A public exploit with over 99% reliability has been…

WhatsApp Disrupts Fresh NSO Group Pegasus Campaign, Seeks Court Contempt Order

martedì 9 giugno 2026, 14:02

Meta’s WhatsApp has disrupted a new NSO Group-linked Pegasus spyware campaign targeting users in Jordan and Lebanon, and is now petitioning a U.S. federal court to hold NSO in contempt for violating a permanent injunction issued after a lan…

China-Linked OP-512 Uses Cryptographically Unique Web Shells in Patient IIS Server Espionage Campaign

martedì 9 giugno 2026, 14:02

ReliaQuest has uncovered OP-512, a new China-linked threat cluster targeting IIS servers with a custom web shell framework that generates cryptographically unique signatures per deployment, evading traditional detection. The group accessed…

Instagram Logic Bug Exposed Unredacted Emails and Phone Numbers for Any Account — Including Mark Zuckerberg’s

lunedì 8 giugno 2026, 18:14

A critical logic flaw in Instagram’s web-based password reset flow exposed fully unredacted email addresses and phone numbers for any account by username, including high-profile accounts. Meta patched the issue with an emergency hotfix on J…

EDRChoker: New Red Team Tool Silences Cloud-Connected EDR Agents by Choking Network With Windows QoS

lunedì 8 giugno 2026, 18:14

A new open-source tool called EDRChoker throttles EDR agent network connections to 8 bps using Windows native Policy-Based QoS, effectively blinding cloud-connected endpoint security tools without generating WFP firewall alerts or packet-bl…

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens — No Patch Coming

lunedì 8 giugno 2026, 18:14

Researchers at Mitiga Labs demonstrated a five-step npm supply chain attack that rewrites ~/.claude.json to redirect Claude Code MCP traffic through attacker-controlled infrastructure, silently capturing OAuth tokens for Jira, Confluence, a…

Microsoft Warns: Claude Code GitHub Action Exploitable via Prompt Injection to Leak CI/CD Secrets

lunedì 8 giugno 2026, 18:13

Microsoft Threat Intelligence disclosed a prompt injection flaw in the Claude Code GitHub Action that allowed attackers to access /proc/self/environ and steal API keys from CI/CD runners. Anthropic patched the issue in version 2.1.128, rele…

OpenAI Launches ChatGPT Lockdown Mode to Block Prompt Injection Data Exfiltration

lunedì 8 giugno 2026, 18:13

OpenAI has released ChatGPT Lockdown Mode, a new security feature that disables outbound network capabilities to cut off data exfiltration pathways exploited in prompt injection attacks. Available to personal, Business, and Enterprise users…

Critical HuggingFace Transformers Flaw CVE-2026-4372 Enables Silent RCE — 232 Million Installs at Risk

lunedì 8 giugno 2026, 18:13

A critical RCE vulnerability in HuggingFace Transformers (CVE-2026-4372) allows attackers to silently execute code by loading a malicious AI model, bypassing the trust_remote_code=False security control. Over 232 million installations were…

CISA Warns: SolarWinds Serv-U CVE-2026-28318 Actively Exploited — Zero-Auth DoS Attack Hits File Transfer Platform

lunedì 8 giugno 2026, 18:13

CISA has added CVE-2026-28318, a zero-authentication denial-of-service flaw in SolarWinds Serv-U, to its Known Exploited Vulnerabilities catalog. Attackers can crash the service remotely with a single crafted HTTP request. Federal agencies…

CISA Adds Actively Exploited Linux Kernel CVE-2022-0492 to KEV Catalog — Patch Now

lunedì 8 giugno 2026, 09:53

CISA has added CVE-2022-0492, a Linux kernel improper authentication flaw, to its Known Exploited Vulnerabilities catalog. The vulnerability enables privilege escalation and container escape attacks and is being actively exploited in the wi…

CISA Warns: Hackers Are Targeting U.S. Fuel Tank Monitoring Systems Across Critical Infrastructure

lunedì 8 giugno 2026, 09:53

CISA, the FBI, NSA, and five other federal agencies have issued a joint advisory confirming active cyberattacks against Automatic Tank Gauge (ATG) systems used in US energy, chemical, transportation, and food sectors. Attackers are exploiti…

CVE-2026-9614 (CVSS 8.8): Ivanti Neurons for ITSM Flaw Allows Authenticated Attackers to Gain Full Admin Access

lunedì 8 giugno 2026, 09:52

Ivanti has disclosed a high-severity privilege escalation vulnerability in its Neurons for ITSM platform, tracked as CVE-2026-9614 with a CVSS score of 8.8. An authenticated attacker with low-level credentials can exploit the flaw remotely…

JS.MonoGlyphRAT: Stealthy New Malware Hidden in Fake Purchase Orders Targets US Enterprises

lunedì 8 giugno 2026, 09:52

A previously unknown remote access trojan called JS.MonoGlyphRAT is spreading through US businesses disguised as routine purchase orders and business quotes. It evades all major antivirus tools by using an unusual obfuscation technique base…

HTTP/2 Bomb: Single-Attacker Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

lunedì 8 giugno 2026, 09:51

A newly disclosed exploit called the ‘HTTP/2 Bomb’ can exhaust tens of gigabytes of server memory in seconds using just a home internet connection. Five of the world’s most widely deployed web servers are affected, including nginx, Apache h…

Iran-Linked Black Shadow Group Obliterates IT, Backups and Recovery Systems Across US and Middle East

venerdì 5 giugno 2026, 13:29

Operating under the cover name Ababil of Minab, Iran-linked APT group Black Shadow launched a wave of destructive attacks against US transit agencies, Israeli firms, and Middle East organizations, wiping virtual machines, SQL databases, and…

Google Gemini Voice Assistant Hijacked via WhatsApp, Slack and SMS: Researchers Bypass All Google Defenses

venerdì 5 giugno 2026, 13:29

SafeBreach researchers demonstrate how attackers can silently hijack Google Gemini through malicious payloads in WhatsApp, Slack, SMS, and other messaging app notifications, bypassing all of Google patched defenses using a novel Fake Contex…

TA4922: Chinese Cybercrime Group Deploys Atlas RAT, ValleyRAT and AI-Assisted Malware in Global Phishing Blitz

venerdì 5 giugno 2026, 13:29

Proofpoint exposes TA4922, a Chinese-speaking cybercrime group conducting more unique campaigns than any other tracked actor in 2026, deploying Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT through HR and tax-themed phishing lure…

The Gentlemen Ransomware Group: Fortinet Exploits, AI Operations, and Custom C2 Make Them 2026’s Most Dangerous Crew

venerdì 5 giugno 2026, 13:28

Russian-speaking ransomware group The Gentlemen ranks second in 2026 activity, exploiting Fortinet vulnerabilities, deploying the custom G-BOT C2 framework, using AI for negotiations, and linking operationally to Black Basta through shared…

CVE-2026-8206 (CVSS 9.8): Kirki WordPress Plugin Flaw Lets Attackers Steal Admin Accounts on 500,000+ Sites

giovedì 4 giugno 2026, 09:03

A critical unauthenticated privilege escalation flaw (CVE-2026-8206, CVSS 9.8) in the Kirki WordPress plugin allows attackers to redirect password reset emails and take over administrator accounts. Over 150,000 sites remain unpatched — upda…