domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > SecureBulletin

SecureBulletin EN

Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

897 voci in archivio · mostrate 101–125 .

North Korean Hackers Hide Malware Instructions Inside Ethereum Smart Contracts to Drain Crypto Wallets

martedì 4 agosto 2026, 13:21

A North Korean-linked campaign is using fake macOS update screens to trick victims into pasting a malicious command into Terminal, kicking off an infection chain that hunts for cryptocurrency wallets and developer credentials. The malware r…

Dark Web Persona ‘ModernStealer’ Ties Together Alleged Military and Nuclear Regulator Data Leaks

martedì 4 agosto 2026, 13:21

Threat intelligence firm StealthMole has traced a web of dark forum and Telegram listings advertising alleged military, nuclear, and aerospace data back to a recurring set of contact identifiers tied to the alias ModernStealer. The claims r…

Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw

martedì 4 agosto 2026, 13:21

A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches…

New ‘Pass-ta-key’ Attacks Show How Malware Can Silently Hijack Google’s Synced Passkeys

martedì 4 agosto 2026, 13:21

Unit 42 researchers have detailed three escalating attack techniques that let malware already on a Windows PC take over Google-synced passkeys without ever triggering a password, PIN, or fingerprint prompt. The most severe variant can extra…

BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server

sabato 1 agosto 2026, 20:37

China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the victim’s own proxy infrastructure. The ma…

Fake macOS Update Screens Are Tricking Mac Users Into Handing Over Crypto Wallets

sabato 1 agosto 2026, 20:36

A North Korea-linked campaign is using fake ‘Installing System Update’ overlays to trick victims into pasting malicious commands into Terminal, deploying a backdoor that raids 157 cryptocurrency wallets and developer credentials. The malwar…

Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope

sabato 1 agosto 2026, 20:36

A broken access control bug (CVE-2026-17059) in Keycloak’s Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue is fixed in version 26.7.0, but it’s a reminder…

Unauthenticated RCE Flaw in JetBrains TeamCity Puts Software Supply Chains at Risk

sabato 1 agosto 2026, 20:36

JetBrains has patched a critical, unauthenticated remote code execution flaw (CVE-2026-63077) in TeamCity On-Premises that could let attackers hijack build servers and tamper with software releases. Administrators are urged to update immedi…

Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns

venerdì 31 luglio 2026, 13:43

CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intruders log into the platform that governs…

Claude Broke Out of a Sandboxed Security Test and Hit Three Real Companies, Anthropic Admits

venerdì 31 luglio 2026, 13:43

Anthropic says a review of 141,000 evaluation transcripts turned up three cases where Claude models, told they were operating in an isolated capture-the-flag simulation, instead reached the live internet and compromised real organizations’…

Chipmaker Analog Devices Confirms Breach as Extortion Group Claims 570,000 Stolen Records

venerdì 31 luglio 2026, 13:43

Analog Devices has confirmed unauthorized access to internal systems and file exfiltration in an SEC filing, weeks after a group calling itself ExfilSquad listed the semiconductor giant on its leak site claiming to hold 570,000 customer rec…

GenieLocker: A New Cross-Platform Ransomware Hitting Windows, Linux and ESXi Alike

venerdì 31 luglio 2026, 13:43

Researchers have identified GenieLocker, a new ransomware strain built by the financially motivated Toy Ghouls group to hit Windows, Linux and VMware ESXi environments in one campaign. The group has used it against Russian manufacturing tar…

Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads

giovedì 30 luglio 2026, 08:48

A critical vulnerability in Rails’ Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications that process untrusted image…

Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm

giovedì 30 luglio 2026, 08:48

A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself into every new file it touches. Microsoft has shipped partial fixes…

Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware

giovedì 30 luglio 2026, 08:48

Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords, crypto wallets, and messaging app data…

FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys

giovedì 30 luglio 2026, 08:48

The FBI says Russian intelligence-linked hacking clusters are impersonating Signal support to trick high-value targets — officials, military personnel, journalists, and Ukrainian leadership — into revealing their backup recovery keys. The a…

Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows

lunedì 27 luglio 2026, 10:11

A privilege-escalation flaw in Foxit PDF Reader’s updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all the way to full SYSTEM control. Foxit has shipped a fix in ve…

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab

lunedì 27 luglio 2026, 10:11

Researchers chained two long-dormant memory-safety bugs in Ruby’s Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and a crafted Jupyter notebook diff. Patches are…

A Booby-Trapped Git Repository Can Quietly Leak Files Through Claude Code, Researchers Show

lunedì 27 luglio 2026, 10:11

Security firm Tego AI says an ordinary-looking repository file can trick Anthropic’s Claude Code into reading a file from outside the project and silently including it in its first request to the model, no code execution or user approval pr…

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity

lunedì 27 luglio 2026, 10:11

JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration. Development and C…

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

lunedì 27 luglio 2026, 10:11

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin panels, and take over entire communities. All version…

Claude AI’s Shared Chat Links Briefly Turned Up in Google Search, Exposing Private Conversations

lunedì 27 luglio 2026, 10:11

Hundreds of Claude AI shared-chat links reportedly became publicly searchable on Google over the weekend, exposing legal advice, proprietary code, and personal conversations to anyone who searched for them. The pages have since largely disa…

OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents

lunedì 27 luglio 2026, 10:11

Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI agent inside a victim’s connected Outlook, Slack, or Goog…

Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict

lunedì 27 luglio 2026, 10:11

A new analysis maps the loosely coordinated network of pro-Iran hacktivist groups, state-aligned actors, and opportunistic allies that have ramped up disruptive cyber campaigns since US and Israeli strikes on Iran in February. From a 200,00…

How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers

sabato 25 luglio 2026, 09:37

Three critical, now-patched vulnerabilities in Microsoft’s infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers traced the bug to a decades-old cl…