lunedì 31 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > SecureBulletin

SecureBulletin EN

Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

903 voci in archivio · mostrate 301–325 .

Hackers Use Fake ChatGPT and Claude Installers to Deploy DinDoor Backdoor

venerdì 29 maggio 2026, 10:14

Cybercriminals are distributing trojanized AI application installers on GitHub and SourceForge, luring victims with fake ChatGPT and Claude desktop apps to silently deploy the DinDoor backdoor, steal cryptocurrency wallets, and establish pe…

NightSpire Ransomware Exploits RDP and Remote Admin Tools to Hit 64 Organizations in 33 Countries

giovedì 28 maggio 2026, 08:40

NightSpire ransomware has hit at least 64 organizations across 33 countries by exploiting Remote Desktop Protocol access and installing legitimate remote administration tools like AnyDesk and Chrome Remote Desktop for stealthy persistence…

Seedworm (MuddyWater) APT Abuses Signed Security Binaries in Global Espionage Campaign Across 9 Countries

giovedì 28 maggio 2026, 08:40

Iran-linked Seedworm (MuddyWater) APT has been caught running a broad espionage campaign against at least 9 organizations across 9 countries in early 2026. The group hijacked legitimate, digitally signed binaries from Fortemedia and Sentine…

Tycoon 2FA Phishing Kit Bypasses MFA at Scale — 62% of Microsoft 365 Phishing Attempts Linked to Single Threat Actor

giovedì 28 maggio 2026, 08:39

The Tycoon 2FA phishing-as-a-service kit, operated by threat actor Storm-1747, is bypassing multi-factor authentication on Microsoft 365 and Google Workspace accounts at massive scale. At its peak it accounted for 62% of phishing attempts b…

BadHost (CVE-2026-48710): Critical Authentication Bypass Threatens Thousands of AI Agent Applications

giovedì 28 maggio 2026, 08:38

A newly disclosed critical vulnerability dubbed ‘BadHost’ (CVE-2026-48710) enables attackers to bypass authentication in FastAPI and Starlette-based AI applications through manipulated HTTP Host headers. Thousands of LLM inference servers…

Fox Tempest: Microsoft DCU Dismantles Malware-Signing-as-a-Service That Forged Trusted Certificates for Ransomware Groups

mercoledì 27 maggio 2026, 07:42

Microsoft’s Digital Crimes Unit has disrupted Fox Tempest, a criminal malware-signing-as-a-service operation that abused Microsoft’s Artifact Signing infrastructure to issue fraudulent code-signing certificates. Over 1,000 certificates have…

Grafana GitHub Breach: TanStack npm Supply Chain Attack Leads to Source Code Theft and Ransom Demand

mercoledì 27 maggio 2026, 07:41

Grafana Labs has confirmed a ransomware-linked breach of its GitHub environment traced to the TanStack npm supply chain compromise. Attackers exfiltrated internal source code repositories and issued a ransom demand on May 16, 2026. Grafana…

Void Botnet Routes Commands Through Ethereum Smart Contracts to Evade Law Enforcement Takedowns

mercoledì 27 maggio 2026, 07:40

A new Rust-based botnet sold on cybercrime forums uses Ethereum smart contracts as its command-and-control channel, making traditional infrastructure takedowns impossible. The Void Botnet supports fourteen payload types including in-memory…

TeamPCP Poisons Microsoft’s Official Python DurableTask SDK — Multi-Cloud Credential Worm Hits PyPI

mercoledì 27 maggio 2026, 07:39

The TeamPCP threat group has compromised three consecutive versions of Microsoft’s official Python DurableTask SDK on PyPI, injecting a worm-like payload that steals multi-cloud credentials from AWS, Azure, GCP, and Kubernetes environments…

Russian Hacker Builds Persistent Gemini Jailbreak to Power Influence Campaign, Credential Theft, and Crypto Wallet Draining

martedì 26 maggio 2026, 09:55

A Russian-speaking threat actor tracked as “bandcampro” has been exposed using a persistently jailbroken Google Gemini CLI to power a five-year operation combining AI-generated political disinformation, WordPress credential theft via AI-ass…

Cloud Atlas APT Patches termsrv.dll to Enable Silent Dual RDP Sessions — Targets Government and Diplomatic Organizations

martedì 26 maggio 2026, 09:54

The Cloud Atlas APT group has adopted a stealthy new technique: modifying Windows termsrv.dll to enable multiple simultaneous RDP sessions, allowing attackers to maintain covert access while legitimate users remain logged in. The campaign t…

Critical 7-Zip Flaw CVE-2026-48095 (CVSS 8.8) Enables Arbitrary Code Execution via NTFS Vtable Hijack

martedì 26 maggio 2026, 09:53

A critical heap buffer overflow in 7-Zip 26.00 (CVE-2026-48095, CVSS 8.8) lets attackers execute arbitrary code through an NTFS vtable hijack. The attack works regardless of file extension and requires no interaction beyond opening a crafte…

Payload Ransomware Deploys ChaCha20 + Curve25519 ECDH to Lock Files — 50+ Victims Across Five Countries

martedì 26 maggio 2026, 09:53

A new ransomware operation called Payload has emerged using military-grade ChaCha20 encryption paired with Curve25519 ECDH key exchange, making file recovery without the operator key impossible. Active since February 2026, the group has alr…

Megalodon Campaign Backdoors 5,500+ GitHub Repositories in Six-Hour CI/CD Blitz

lunedì 25 maggio 2026, 12:22

The automated “Megalodon” attack campaign pushed malicious CI/CD backdoors into 5,561 GitHub repositories within 6 hours on May 18, 2026, harvesting cloud credentials and OIDC tokens. The Tiledesk npm package was among the downstream victim…

Supply Chain Attack Backdoors 233 Laravel-Lang Package Versions Across 700 GitHub Repositories

lunedì 25 maggio 2026, 12:22

Attackers exploited GitHub’s tagging system to inject credential-stealing PHP backdoors into 233 versions of Laravel-Lang packages, silently targeting developer cloud keys, SSH credentials, and CI/CD secrets across 700 repositories. Immedia…

Hackers Exploit End-of-Life F5 BIG-IP as Enterprise Entry Point, Pivoting to Active Directory via Confluence RCE

lunedì 25 maggio 2026, 12:22

Microsoft Defender researchers document a multi-stage intrusion where threat actors exploited an end-of-life F5 BIG-IP appliance to gain SSH access, then pivoted through an unpatched Confluence server to reach Active Directory — a textbook…

CVE-2026-9256 “nginx-poolslip”: Critical NGINX Flaw Enables Unauthenticated DoS and Code Execution

lunedì 25 maggio 2026, 12:22

A critical heap buffer overflow in the NGINX rewrite module (CVE-2026-9256, “nginx-poolslip”) allows unauthenticated remote attackers to crash NGINX workers or execute code. Proof-of-concept activity is already circulating — patch to versio…

art-template npm Package Backdoored to Deliver iOS Browser Exploit Kit via Supply Chain Attack

domenica 24 maggio 2026, 18:13

Attackers hijacked the widely-used art-template npm library by taking over its maintenance, then injected a sophisticated iOS browser exploit kit that silently targeted Safari users on vulnerable devices through any web application that inc…

2026 FIFA World Cup Phishing Fraud Triples in Scope: 222 Fake Domains, Four Criminal Clusters

domenica 24 maggio 2026, 18:13

A massive phishing operation targeting 2026 FIFA World Cup fans has grown nearly three times larger than initially reported, now spanning 222 fraudulent domains across 203 unique IP addresses and operated by at least four independent crimin…

CISA Flags Actively Exploited Langflow Flaw CVE-2025-34291 — AI Workflow Deployments at Risk

domenica 24 maggio 2026, 18:13

CISA has added CVE-2025-34291, a critical CORS misconfiguration in the Langflow AI workflow platform, to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Organizations using Langflow face the risk of full account…

AI Discovers 10,000+ Zero-Days: Anthropic’s Claude Mythos Preview Transforms Cybersecurity Defense

domenica 24 maggio 2026, 18:12

Anthropic’s Claude Mythos Preview AI model has autonomously discovered over 10,000 critical zero-day vulnerabilities across major software systems as part of Project Glasswing, revealing both the extraordinary potential of AI in cybersecuri…

Ukrainian Intelligence Report: Russian APT Groups Intensify Cyber Operations — 5,927 Incidents, 37% Rise in 2025

sabato 23 maggio 2026, 06:50

A new intelligence report from Ukraine’s National Security and Defense Council reveals Russian state-sponsored threat groups dramatically escalated cyber operations in 2025, with CERT-UA recording 5,927 incidents — a 37.4% increase year-ove…

Ubiquiti Issues Emergency Patches for Five Critical UniFi OS Vulnerabilities, Three Rated Maximum CVSS 10.0

sabato 23 maggio 2026, 06:50

Ubiquiti Networks has released urgent firmware updates addressing five critical vulnerabilities in its UniFi OS platform, including three flaws rated CVSS 10.0 — the maximum severity score. The unauthenticated remote code execution and path…

CISA Adds Two Actively Exploited Microsoft Defender Zero-Days to KEV Catalog — Patch by June 3

sabato 23 maggio 2026, 06:50

CISA has added two critical Microsoft Defender vulnerabilities — CVE-2026-45498 and CVE-2026-41091 — to its Known Exploited Vulnerabilities catalog following evidence of active exploitation in the wild. Federal agencies face a June 3, 2026…

LiteSpeed cPanel Plugin Zero-Day (CVE-2026-48172) Actively Exploited to Gain Server Root Access

sabato 23 maggio 2026, 06:49

LiteSpeed has disclosed and patched a critical zero-day privilege escalation flaw (CVE-2026-48172) in its cPanel user-end plugin that is already being actively exploited in the wild to gain root access on Linux hosting servers. Administrato…