lunedì 31 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > SecureBulletin

SecureBulletin EN

Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

903 voci in archivio · mostrate 276–300 .

Threat Actors Use AI Agents and Cursor IDE to Automate Active Directory Attacks and Beat EDR

giovedì 4 giugno 2026, 09:02

Sophos has uncovered a Russian-speaking threat actor using AI-assisted tools, Cobalt Strike, and a purpose-built automated lab to develop EDR bypass malware targeting Active Directory environments — with Claude Opus and MCP coordinating the…

Five OpenClaw Zero-Days Let Attackers Silently Hijack AI Agent Access on Slack, Teams, and Discord

giovedì 4 giugno 2026, 09:02

Researcher Philip Garabandic disclosed five zero-day vulnerabilities in OpenClaw allowing identity spoofing to hijack trusted AI agent access across Slack, Discord, Microsoft Teams, Matrix, and Zalo. The same root cause persisted across all…

CVE-2025-48595: Android 0-Day Actively Exploited — Patch Your Devices Now

giovedì 4 giugno 2026, 09:02

Google has confirmed active exploitation of CVE-2025-48595, a zero-click Android Framework privilege escalation flaw affecting Android 14-16. Devices without the June 2026 patch remain at risk of complete compromise.

WordPress Sites Turned Into Spy Networks: Malware Hides C2 Commands in Steam Profile Comments Using Unicode Steganography

mercoledì 3 giugno 2026, 07:57

A sophisticated malware campaign has compromised approximately 1,900 WordPress sites using Steam Community profile pages as a covert C2 channel. The malware employs Unicode steganography to hide commands in profile comment text and installs…

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog as Active Exploitation Confirmed — Patch by June 4

mercoledì 3 giugno 2026, 07:56

CISA has added CVE-2024-21182, a critical unauthenticated Oracle WebLogic Server vulnerability, to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild exploitation. Federal agencies must patch by June 4, 2026.

FSB Claims Foreign Spyware Found on Russian Officials’ Phones in Targeted Espionage Campaign

mercoledì 3 giugno 2026, 07:56

Russia’s FSB announced the disruption of a foreign intelligence campaign implanting advanced spyware on senior officials’ mobile phones, enabling silent surveillance, communication interception, and data exfiltration consistent with nation-…

1-Click GitHub Token Theft: VSCode Webview Flaw Exposes OAuth Tokens for All Private Repositories

mercoledì 3 giugno 2026, 07:53

A critical VSCode webview vulnerability lets attackers steal GitHub OAuth tokens with a single click, granting full access to all private repositories. Researcher Ammar Askar published a complete five-stage proof-of-concept exploit chain on…

Critical Supply Chain Attack: 31 Red Hat Cloud Services npm Packages Backdoored to Steal Cloud and Dev Credentials

martedì 2 giugno 2026, 11:52

A sophisticated supply chain attack dubbed “Miasma: The Spreading Blight” has backdoored over 30 official @redhat-cloud-services npm packages, deploying credential-stealing malware that targets AWS, Azure, GCP secrets, GitHub tokens, and de…

SmartApeSG Campaign Exploits ClickFix Fake Verification Pages to Deliver NetSupport RAT

martedì 2 giugno 2026, 11:52

The SmartApeSG campaign is using ClickFix scripts disguised as fake browser verification pages to deploy a two-stage infection chain, culminating in a persistent NetSupport Manager RAT installation on Windows hosts.

Attackers Exploit Docker and Kubernetes Misconfigurations to Escape Containers and Seize Host Control

martedì 2 giugno 2026, 11:52

Security researchers have documented a wave of attacks exploiting Docker and Kubernetes misconfigurations to break out of containers and take full control of host systems, including supply chain attacks targeting CI/CD pipelines.

OverlayPhantom Android Banking Trojan Targets 180+ Apps Across 10 Countries

martedì 2 giugno 2026, 11:52

A dangerous new Android banking trojan called OverlayPhantom has been targeting users in ten countries, abusing Android’s Accessibility Service to steal banking and cryptocurrency credentials from over 180 financial apps.

Hackers Are Calling You on Microsoft Teams Pretending to Be IT Support — How to Detect and Stop the Attack

lunedì 1 giugno 2026, 08:36

Threat actors are systematically abusing Microsoft Teams’ external collaboration features to impersonate IT helpdesk staff, convincing employees to grant remote access and install malware. Black Basta ransomware affiliates pioneered the tec…

Massive Supply Chain Attack: Poisoned VS Code Extension and “Megalodon” Campaign Steal Credentials from Millions of Developers

lunedì 1 giugno 2026, 08:35

Two coordinated supply chain attacks poisoned the Nx Console VS Code extension (2.2M installs) and backdoored 5,561 GitHub repositories simultaneously, stealing cloud credentials and 3,800 internal GitHub source code repositories. CISA assi…

Meta AI Flaw Lets Attackers Hijack Instagram Accounts Without Verification — Premium Handles Worth $1M+ Stolen

lunedì 1 giugno 2026, 08:31

A critical flaw in Meta’s AI account recovery tool allowed attackers to trick the chatbot into sending password reset codes with no identity verification, enabling theft of premium Instagram accounts worth over $1 million. Accounts with 2FA…

CVE-2026-41089: Windows Netlogon 0-Click RCE Now Actively Exploited — Patch Domain Controllers Immediately

lunedì 1 giugno 2026, 08:31

Microsoft’s May 2026 Patch Tuesday addressed CVE-2026-41089, a critical Windows Netlogon 0-click RCE — now actively exploited in the wild. Domain controllers running unpatched Windows Server face complete compromise with no user interaction…

Malicious NuGet Package Impersonates Sicoob Banking SDK to Steal mTLS Certificates and Financial Credentials

domenica 31 maggio 2026, 12:53

A malicious NuGet package named “Sicoob.Sdk” impersonated the official Sicoob banking SDK and silently exfiltrated PFX certificates, private keys, and banking credentials from 484 downloads using Sentry telemetry infrastructure to evade det…

Google Chrome’s Device-Bound Session Credentials Go GA — Cryptographically Kills Cookie-Theft Attacks

domenica 31 maggio 2026, 12:52

Google has moved Device Bound Session Credentials (DBSC) to general availability in Chrome on Windows, cryptographically binding session cookies to the originating device via TPM. Enabled by default for all Google Workspace and personal acc…

GitLab Patches High-Severity Duo AI Identity Flaw and Multiple Authorization, DoS Vulnerabilities

domenica 31 maggio 2026, 12:52

GitLab has released emergency security patches (versions 19.0.1, 18.11.4, 18.10.7) fixing a CVSS 8.2 Duo AI identity flaw (CVE-2026-4868) that could enable lateral movement, alongside a Wiki denial-of-service bug, GraphQL project enumeratio…

Microsoft Releases Emergency KB5089573 for Windows 11 to Permanently Fix Patch Tuesday Install Failures

domenica 31 maggio 2026, 12:52

Microsoft has released KB5089573, a critical out-of-band update for Windows 11, permanently fixing the EFI System Partition space issue that caused widespread 0x800f0922 installation failures following May 2026 Patch Tuesday. The update als…

JINX-0164: Crypto-Targeting APT Uses LinkedIn Job Lures and Fake Meeting Apps to Deploy macOS Malware and Poison npm Supply Chain

sabato 30 maggio 2026, 11:00

Threat actor JINX-0164 is targeting cryptocurrency developers via fake LinkedIn profiles, luring them into downloading custom macOS malware (AUDIOFIX and MINIRAT) that steals credentials, cloud tokens, and crypto wallet data — then escalate…

‘The Gentlemen’ Ransomware: Self-Propagating Go Encryptor Uses SYSTEM Scheduled Tasks to Lock Entire Networks

sabato 30 maggio 2026, 10:59

A new Go-based ransomware called The Gentlemen (tracked as Storm-2697 by Microsoft) spreads automatically across networks using eight simultaneous propagation methods, escalates to SYSTEM privileges via scheduled tasks, and operates as a Ra…

GREYVIBE: Russian-Aligned Hackers Use ChatGPT and Google Gemini to Build Cyberweapons Targeting Ukraine

sabato 30 maggio 2026, 10:59

A newly tracked threat actor called GREYVIBE is using generative AI tools including ChatGPT and Google Gemini to develop malware, generate phishing lures, and attack Ukrainian government, military, and civilian targets. WithSecure researche…

CVE-2026-0257: Palo Alto PAN-OS Authentication Bypass Actively Exploited — Patch Immediately

sabato 30 maggio 2026, 10:59

A critical authentication bypass in Palo Alto Networks PAN-OS (CVE-2026-0257) is being actively exploited in two distinct waves, with attackers forging GlobalProtect VPN session cookies to gain unauthorized network access. CISA has added it…

Malicious npm Package forge-jsxy Pushes 22 Versions in 22 Days to Steal Crypto Wallets and Deploy Persistent Backdoor

venerdì 29 maggio 2026, 10:17

The npm package forge-jsxy quietly stole cryptocurrency wallet keys, browser credentials, and developer data across Windows, macOS, and Linux — publishing 22 malicious versions in 22 days, and leaving behind a backdoor that survives uninsta…

Grandoreiro Banking Trojan Returns: Targeting Portuguese Banks and Latin American Companies With Dual Campaigns

venerdì 29 maggio 2026, 10:15

The long-running Grandoreiro banking trojan has resurfaced with two active campaigns — one using DLL Side-Loading via cloud infrastructure and another via obfuscated VBS scripts — targeting over 20 Portuguese banks and companies across Spai…