Home > Directory > Sicurezza > SecureBulletin
SecureBulletin EN
Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.
Sito originale · Feed RSS della fonte
897 voci in archivio · mostrate 76–100 .
Levi Strauss Confirms Data Breach After Employees Fall for Social Engineering Scam
Levi Strauss & Co. has disclosed that attackers tricked three employees into handing over access to company-issued computers, letting intruders reach and exfiltrate internal files. The denim maker says the intrusion was contained quickly an…
18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers
A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root — and in tested cases, escape containers entire…
ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials
A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines and CI pipelines along the way. Re…
Patchwork Espionage Group Uses Fake PDFs and Romance-Themed Chat Apps to Spy on PCs and Phones
The long-running Patchwork espionage group, also tracked as Dropping Elephant, is running parallel campaigns against Windows machines and Android phones — one built around a PDF-disguised shortcut file, the other around trojanized chat apps…
Swiss Government IT Agency Confirms SharePoint Breach, About 200 Accounts Compromised
Switzerland’s Federal Office for Information Technology and Telecommunication says attackers likely exploited recently disclosed Microsoft SharePoint flaws to steal credentials for roughly 200 user and technical accounts. No evidence of dat…
Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents
Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor’s surrounding ‘harness’ handles tool permissions rather tha…
New Vanta Stealer Malware Raids Browsers, Crypto Wallets and Gaming Accounts in a Single Sweep
A newly documented information stealer called Vanta Stealer goes well beyond saved browser passwords, harvesting cookies, payment data, Discord tokens, gaming accounts and cryptocurrency wallet files in one automated run. Analysts at Point…
Thousands of Exposed Rockwell PLCs Leave US Water Utilities Open After Multi-State Attack Wave
A wave of attacks against U.S. water and wastewater utilities has renewed scrutiny of how many industrial controllers sit exposed to the open internet. Forescout researchers count over 4,400 internet-facing Rockwell Automation PLCs, while t…
SilverFox Malware Deploys New Kernel Drivers to Blind Antivirus Before Installing ValleyRAT
Researchers at CATO Networks have caught the SilverFox threat group hiding behind trusted PDF software while quietly loading vulnerable, signed kernel drivers to knock out endpoint protection. The campaign, which struck a Japanese manufactu…
Greatness Phishing Service Lets Attackers Slide Past MFA Into Microsoft 365 Inboxes
A phishing-as-a-service platform called Greatness is stealing live authentication tokens rather than passwords, letting attackers walk past multi-factor authentication and into Microsoft 365 mailboxes. A recent campaign hid behind spoofed v…
Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN
Cisco has patched five vulnerabilities in Catalyst SD-WAN Software, three of them scoring 9.9 out of 10 on the CVSS scale. There is no evidence of active exploitation yet, but every deployment mode is affected and there are no workarounds…
Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers
Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repository details and CI/CD identifiers str…
How Attackers Spent July Turning Microsoft, Zoom, and Government Sites Against Their Own Users
Threat intelligence from ANY.RUN shows attackers spent July 2026 weaponizing the everyday trust built into Microsoft logins, Zoom event pages, and government portals across the US, Europe, and Brazil. The campaigns combined OAuth token thef…
How a Rogue Prompt Could Turn Microsoft Copilot Into a $250,000 Wire Fraud Accomplice
A proof-of-concept from Barracuda researchers shows how attackers could weaponize Microsoft Copilot itself to escalate a single compromised inbox into full CEO account takeover and a quarter-million-dollar wire fraud, using little more than…
One Click, Total Takeover: The RCE Bug That Hid Inside Cursor, VS Code, and Google Antigravity
Security researchers at AISLE uncovered a one-click remote code execution flaw shared by Cursor, Microsoft VS Code, and Google Antigravity, all three built on the same underlying codebase. A single click on a booby-trapped Git commit link c…
Six Ways to Break Flowise: New RCE Chain Puts AI Workflow Servers at Risk
Security researchers at Elttam disclosed six separate remote code execution flaws in the Flowise AI workflow platform, spanning CSV processing, sandboxed JavaScript, and database configuration. Several of the bugs were found to bypass earli…
DarkSword Exploit Kit Quietly Expands to 180 Sites, Turning iPhones Into Data-Theft Targets
A leaked iOS exploit chain known as DarkSword has grown into a sprawling, fast-changing network of malicious infrastructure, with researchers at Censys tracking 27 hosts and 180 web properties designed to silently harvest keychain data, iCl…
Arch Linux Freezes AUR Package Adoptions After Attackers Exploit Abandoned Projects
Arch Linux has temporarily disabled the ability to adopt orphaned AUR packages after security teams spotted a wave of hostile takeovers followed by malicious code injected through routine-looking commits. The move follows a larger supply-ch…
How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline
Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses for attacker-controlled ones. The…
ShinyHunters Strikes Again: Brinks Home Confirms Breach Tied to Salesforce Systems
Brinks Home has confirmed attackers broke into systems connected to its Salesforce environment after the ShinyHunters extortion crew claimed to have stolen nearly five million records. The company says core alarm monitoring services were un…
865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records
A breach at Russian VPN provider SplitVPN, formerly NotVPN, has exposed the records of roughly 865,000 users despite the service’s long-standing ‘no logs’ promise. The leaked database reportedly includes emails, IP addresses, partial paymen…
FBI and Allied Governments Warn Companies Are Unknowingly Hiring North Korean Operatives
A joint advisory from the U.S. State Department, FBI, and partner nations including Japan, the UK, Germany, Canada, and South Korea warns that North Korean IT workers are using stolen identities and forged documents to land remote jobs, fun…
The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking
A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver can also redirect network traffic and block rival…
SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login
SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform are urged to patch immediately, as a successful bypass…
SonicWall VPN Gateways Hit by Zero-Click Root Takeover Chain Tied to INC Ransomware
Attackers are chaining two SonicWall SMA 1000 series flaws to gain root access to VPN gateways without a password or any user interaction. Researchers at Resecurity tie the campaign to INC Ransomware, which began exploiting the bugs weeks b…