domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > SecureBulletin

SecureBulletin EN

Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

897 voci in archivio · mostrate 26–50 .

Fake Adobe Reader Site Powers a New Malware-as-a-Service Platform Targeting Windows Users

lunedì 24 agosto 2026, 10:49

Researchers have uncovered a live malware-as-a-service operation hiding behind a convincing fake Adobe Acrobat Reader site, using a WebDAV trick and a disguised batch file to install information-stealing and banking-fraud malware. The platf…

This Week in Cyber: An AI Coding Assistant Helped Run a Ransomware Attack, and Azure Logins for 9 Major Firms Hit the Dark Web

lunedì 24 agosto 2026, 10:49

Two stories from this week show how enterprise security is being reshaped from both ends: a ransomware affiliate reportedly used an AI coding assistant to breach VPNs and steal credentials with minimal human input, while a dark-web seller h…

Microsoft’s New Windows Tool Quietly Resets Chrome, Firefox, and Brave to Bing

lunedì 24 agosto 2026, 10:49

A newly spotted Microsoft installer called MicrosoftSettings.exe pushes a browser extension that switches Chrome, Firefox, and Brave over to Bing search and the MSN homepage. Security researchers note the permissions it requests mirror thos…

Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

sabato 22 agosto 2026, 17:25

Security researchers at Adversa AI found a zero-click flaw in xAI’s Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader w…

Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution

sabato 22 agosto 2026, 17:25

A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected WordPress sites. A fix shippe…

Chinese Threat Group Automates Web Server Attacks at Scale Using AI Agents, Cisco Talos Warns

sabato 22 agosto 2026, 17:25

Cisco Talos has tracked a Chinese-speaking group known as UAT-10147 using AI-generated scripts and playbooks to automate reconnaissance and exploitation across roughly 170,000 URLs. The campaign hit government, education, media, technology…

New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools

sabato 22 agosto 2026, 17:25

Researchers have uncovered SilkParasite, a cyberespionage operation using spear-phishing and five previously unseen malware families to target government bodies across Central Asia. The campaign favors cloud-based command channels and steal…

Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live

venerdì 21 agosto 2026, 10:09

Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer action to take, but security teams sho…

How One Phishing Email Let Attackers Bypass MFA and Redirect a Company’s Vendor Payments

venerdì 21 agosto 2026, 10:09

An HR-themed phishing lure led a finance employee to a fake Microsoft 365 login that stole an authenticated session cookie, letting attackers bypass MFA entirely. Over the following month they used mailbox access to redirect real vendor pay…

Researchers Show How a Signed Windows Defender Driver Could Be Turned Against Security Tools

venerdì 21 agosto 2026, 10:09

Check Point researchers reverse-engineered Microsoft Defender’s BTR.sys driver and found that its undocumented transaction protocol could be reproduced to disable antivirus and EDR products from the Windows kernel using a fully legitimate…

Hijacked Rust Crates With 244 Million Downloads Turned Into Malware Delivery Pipeline

venerdì 21 agosto 2026, 10:09

A typosquatted Rust package quietly hijacked two popular crates, arrayref and append-only-vec, to run an infostealer during ordinary builds. The attack hid inside an automatically-executed build script, leaving the visible source code untou…

Feds Sound Alarm on Active Hacking Campaign Targeting Siemens S7 PLCs Nationwide

giovedì 20 agosto 2026, 10:17

NSA, CISA, the FBI, DOE and EPA have jointly warned that hackers are actively scanning for and probing Siemens S7-series PLCs across U.S. critical infrastructure. The campaign favors quiet reconnaissance and AI-assisted exploit development…

CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw

giovedì 20 agosto 2026, 10:17

CISA has added a double-free memory corruption bug in Microsoft’s Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies until August 21 to patch.

How T-Mobile’s Security Team Cut a Cable to Physically Kick Salt Typhoon Off Its Network

giovedì 20 agosto 2026, 10:17

Newly reported details describe how T-Mobile’s security team tracked Chinese state-linked hackers from Salt Typhoon to a compromised router at a third-party data center in 2024 — and cut them off by physically severing the network cable rat…

Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely

giovedì 20 agosto 2026, 10:17

Citrix has patched two new NetScaler ADC and Gateway vulnerabilities, including a 9.3-severity authentication bypass that can let remote attackers slip past login controls on SSL VPN, ICA Proxy and RDP Proxy deployments entirely.

Breach at France’s Tax Authority Exposes Financial Records of Nearly 680,000 People

mercoledì 19 agosto 2026, 08:14

France’s Directorate General of Public Finances has confirmed that attackers used compromised employee and third-party credentials to access tax records belonging to roughly 678,000 individuals and businesses. No passwords were exposed, but…

CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits

mercoledì 19 agosto 2026, 08:14

CISA, the FBI, and HHS have jointly updated their advisory on the Medusa ransomware-as-a-service operation, which has now hit more than 500 critical infrastructure organizations spanning healthcare, education, and manufacturing. The gang co…

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

mercoledì 19 agosto 2026, 08:14

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform’s webhook-testing endpoint to reach cloud metadata services and steal IAM credentials…

Fake CAPTCHA Prompts on Hacked WordPress Sites Fuel Global StopAndProtect Malware Botnet

mercoledì 19 agosto 2026, 08:14

Researchers have uncovered a sprawling campaign, dubbed StopAndProtect, that has hijacked thousands of poorly maintained WordPress sites to serve as rotating command-and-control infrastructure. Fake CAPTCHA prompts trick visitors into pasti…

Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks

martedì 18 agosto 2026, 13:10

Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has been used against government networks in Pakistan, Mongo…

Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin

martedì 18 agosto 2026, 13:10

Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been reported yet, but administrators are urged to upda…

Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control

martedì 18 agosto 2026, 13:10

A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the primary site server — no admin rights or user…

Threema Beats Back Multi-Day DDoS Siege, Rolls Out New Upstream Filtering

martedì 18 agosto 2026, 13:10

Privacy-focused messenger Threema spent nearly a day fighting off a shifting distributed denial-of-service campaign that hit both its own infrastructure and its colocation partner. No group has claimed responsibility, and the company says u…

Shell Launches Investigation After Cl0p Extortion Group Claims Theft of Nearly 90GB of Internal Data

lunedì 17 agosto 2026, 11:11

Energy giant Shell has activated its incident response process after the Cl0p extortion syndicate listed the company on its dark-web leak site, claiming to have stolen roughly 89GB of engineering documents and internal project files. Shell…

Attackers Race to Weaponize Maximum-Severity SAP Commerce Cloud Flaw Within Days of Patch

lunedì 17 agosto 2026, 11:11

A maximum-severity remote code execution flaw in SAP Commerce Cloud is already being probed by attackers just days after a fix shipped, with honeypot sensors picking up automated exploitation attempts against exposed administrative endpoint…