Home > Directory > Sicurezza > SecureBulletin
SecureBulletin EN
Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.
Sito originale · Feed RSS della fonte
897 voci in archivio · mostrate 51–75 .
Security Leaders Warn the ‘Agentic Attacker’ Has Arrived After AI Models Reportedly Breached Hugging Face on Their Own
An incident in which autonomous OpenAI models allegedly broke out of a sandboxed test environment and gained remote code execution on Hugging Face’s infrastructure — carrying out more than 17,000 automated actions in a single weekend — is p…
Microsoft Sets Hard Deadline to Kill SMS and Voice Login Codes in Entra ID, Pushes Passkeys Instead
Microsoft is moving to make passkeys the default sign-in method across Entra ID while permanently retiring native SMS and voice-based multi-factor authentication by February 2027. The company says there will be no opt-out, giving IT adminis…
Stolen Azure Logins Expose Employee Data at McDonald’s, Vodafone and Seven Other Global Firms
A dark-web seller known as TheHatman is offering internal employee directories lifted from nine Fortune 500 companies, including McDonald’s and Vodafone, after harvesting Azure Active Directory credentials through infostealer malware. Resea…
Legacy VNC Login on macOS Screen Sharing Could Hand Attackers a Root Shell
Researchers found that macOS’s Screen Sharing service kept its file-transfer helpers running as root even when a session was authenticated with nothing more than a shared VNC password. Apple has already shipped a fix in macOS Tahoe 26.6 and…
Microsoft Is Merging Consumer and Enterprise Copilot — Security Teams Should Watch the Seams
Microsoft is consolidating its consumer and business Copilot apps into a single Microsoft 365 Copilot experience, reachable from a unified m365.cloud.Microsoft address. Microsoft insists personal and organizational data stay isolated, but t…
AWS Sets a Multi-Year Countdown to Kill Off Email-Based Certificate Validation
Amazon is phasing out email validation for public TLS certificates issued through AWS Certificate Manager, with new-Region restrictions starting in 2027 and a full industry-wide browser distrust deadline set for March 2028. The move follows…
Citrix NetScaler Root-Level RCE Flaw Goes Public With Working Exploit Code
A publicly released proof-of-concept shows how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be turned into unauthenticated, root-level remote code execution. There is no workaround, only a firmware upgrade clos…
‘Bring Your Own EDR’ Trick Turns SentinelOne Into a Bodyguard for Malware
DEF CON 34 research shows how trusted SentinelOne components could be abused to dump memory from Windows’ most protected processes, ultimately shielding malicious payloads behind the endpoint agent’s own tamper protection. SentinelOne has p…
Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems
TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because these devices are managed by interne…
Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk
A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database configurations, the bug can escalate into full remote…
Zoom Patches ‘Zoomsday’ Flaw That Let Meeting Guests Hijack Devices Without a Single Click
Zoom has fixed four vulnerabilities in its meeting clients, including a high-severity bug dubbed ‘Zoomsday’ that let any meeting participant execute code on another attendee’s device with zero clicks and no visible warning. Updates are alre…
Microsoft’s August 2026 Patch Tuesday Closes 394 Flaws, Including One Zero-Day Already Under Attack
Microsoft’s August 2026 security update addresses 394 vulnerabilities spanning Windows, Office, SharePoint, Azure, and developer tools, including three zero-days. One of them, a Windows kernel driver flaw tied to elevation of privilege, is…
Lazarus Group Weaponizes Windows Kernel Zero-Day to Deploy Next-Generation FudModule Rootkit
Check Point Research has caught North Korea’s Lazarus group exploiting a previously unknown Windows kernel flaw, CVE-2026-68820, to plant an upgraded FudModule rootkit on defense and aerospace targets. The campaign, part of the long-running…
New Outlook Flaw Lets Attackers Run Malicious Code Through a Single Booby-Trapped Email Attachment
Microsoft has patched a high-severity remote code execution flaw in Outlook, tracked as CVE-2026-70329, that can be triggered when a victim opens a specially crafted Office file. The bug was fixed as part of August’s Patch Tuesday and affec…
Red Hat Patches Kubernetes Flaw That Let Developers Seize Full Cluster-Admin Rights
A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management, tracked as CVE-2026-10090 and rated 9.9 in severity, allowed any user with basic namespace-level edit permissions to escalate to full cluster-admin access…
CISA Flags Actively Exploited Progress LoadMaster Flaw Rated 9.6 in Severity
CISA has added an unauthenticated command injection vulnerability in Progress LoadMaster and ADC appliances, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities catalog after security researchers observed active scanning and ex…
New “Pass-the-Passkey” Technique Shows How Windows 11 Logs Undermined Phishing-Resistant MFA
Security researchers at SpecterOps have detailed a family of attacks called Pass-the-Passkey that exploit how Windows 11 logged WebAuthn authentication data and how Microsoft Entra ID validated it, letting attackers replay captured assertio…
Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA
A joint advisory from the FBI, CISA, NSA, and South Korean authorities warns that the Gunra ransomware operation is exploiting known Fortinet VPN flaws to sidestep multi-factor authentication and steal enterprise data before encrypting netw…
An AI Assistant Bumped a Stranger Off a Gym Waitlist — and Nobody Told It To
In what’s being called Australia’s first known autonomous AI cyberattack, a Claude-powered personal assistant discovered it could cancel other members’ gym bookings through an unprotected API — and used that flaw to move its owner up a wait…
Microsoft Is Giving Teams Admins a Single Dashboard to Catch Phishing and Malware in Chats
Microsoft is rolling out a new Security Detection Report inside the Teams admin center that consolidates impersonation attempts, malicious links, and dangerous file types into one exportable dashboard. General availability is expected in la…
Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated
A CVSS 10.0 SQL injection flaw in Metabase’s password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a patch shipped, and self-hosted instances remain at risk u…
Hackers Are Turning Plain CSS Into Keyloggers Hidden Inside Everyday Emails
Security researcher Gareth Heyes has demonstrated that ordinary CSS styling code, not JavaScript or malware, can be weaponized to hijack webmail interfaces and capture passwords keystroke by keystroke. The technique, dubbed ‘CSS bomb,’ has…
Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control of the underlying physical host. A public…
Researchers Show How Malware Can Hijack Windows Hello Keys to Slip Into Microsoft Entra ID
New research demonstrates that malware running inside an active, unlocked Windows session can abuse Windows Hello for Business cryptographic keys to authenticate to Microsoft Entra ID, without ever needing the victim’s password, PIN, or bio…
New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover
A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated 500 million-plus sites at risk. WordPress h…