domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > SecureBulletin

SecureBulletin EN

Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

897 voci in archivio · mostrate 151–175 .

Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control

domenica 19 luglio 2026, 06:50

Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local user escalate to full SYSTEM access with no…

Inside NadMesh: The Shodan-Powered Botnet Hunting Exposed AI Servers

domenica 19 luglio 2026, 06:50

Researchers at XLab have identified NadMesh, a Go-based botnet that uses Shodan to hunt down exposed AI and MCP infrastructure before hijacking it with more than 20 exploitation techniques. The malware behaves less like a typical worm and m…

EY Notifies Clients After Breach of IT Support Platform Exposes Tax Documents

sabato 18 luglio 2026, 10:17

Ernst & Young is notifying clients that attackers accessed a third-party IT support ticketing platform for roughly two weeks this spring, downloading documents containing sensitive tax and investment data before the intrusion was detected…

Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems

sabato 18 luglio 2026, 10:17

Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary suffered a ransomware attack that forced a temporary halt of US production, while Canadian operations continued unaffected. The company says product safety was not comp…

Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts

sabato 18 luglio 2026, 10:17

A newly disclosed Windows zero-day called LegacyHive abuses the User Profile Service to let a low-privileged user tamper with an administrator’s registry hive, opening a path to persistence and code execution under admin rights. The bug aff…

CISA Confirms Active Exploitation of Critical SharePoint Deserialization Flaw

sabato 18 luglio 2026, 10:16

CISA has added CVE-2026-58644, a critical unauthenticated remote code execution flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog after confirming real-world attacks. Federal agencies must remediate under BOD 26-0…

SonicWall SMA1000 Zero-Days Under Active Attack: Perfect-10 Flaw Chained for Root Access

venerdì 17 luglio 2026, 14:15

Attackers were exploiting a maximum-severity SonicWall SMA1000 flaw before the vendor’s advisory even landed, chaining it with a privilege-escalation bug to seize root and pivot into corporate Active Directory environments. Both CVEs are no…

Critical 7-Zip Flaw Lets Booby-Trapped Archives Hijack Your System

venerdì 17 luglio 2026, 14:15

A newly patched 7-Zip vulnerability lets attackers achieve remote code execution simply by getting a victim to open a maliciously crafted compressed file. With 7-Zip installed on millions of machines worldwide, the flaw is a ready-made vect…

CISA Sounds Alarm as Attackers Exploit Critical FortiSandbox Command Injection Flaws

venerdì 17 luglio 2026, 14:15

CISA has confirmed active exploitation of two OS command injection vulnerabilities in Fortinet’s FortiSandbox product line, adding both to its Known Exploited Vulnerabilities catalog and giving federal agencies just days to respond. The fla…

Scattered Spider Duo Sentenced Over £29 Million Transport for London Cyberattack

venerdì 17 luglio 2026, 14:15

Two young members of the Scattered Spider hacking collective have been jailed for over five years each after a 2024 breach knocked out 148 Transport for London systems and forced 27,000 staff to reset passwords in person. Prosecutors called…

Accenture Data Breach: Hackers Claim Theft of 35 GB of Source Code and Azure Credentials

mercoledì 8 luglio 2026, 10:59

A threat actor known as “888” claims to have stolen 35 GB of Accenture source code, RSA/SSH keys, and Azure access tokens, offering the data for sale in Monero. Accenture has confirmed a breach but disputes the claimed scope.

The Gentlemen Ransomware: Custom EDR/AV Killers Fuel Rapid Global Expansion

mercoledì 8 luglio 2026, 10:59

The Gentlemen ransomware group, tracked by Microsoft as Storm-2697, has claimed over 500 victims in 70+ countries using a custom EDR/AV-killing toolkit called GentleKiller and a self-propagating worm encryptor. A May 2026 leak of the group’…

GitLost: How a Single GitHub Issue Can Trick AI Agents Into Leaking Private Repos

mercoledì 8 luglio 2026, 10:59

Researchers at Noma Labs disclosed GitLost, a prompt-injection flaw that let a single crafted GitHub Issue trick AI-powered Agentic Workflows into leaking private repository contents publicly, using a simple linguistic trick to bypass safet…

Rogue Agent: Critical GCP Dialogflow Flaw Let Attackers Inject Malicious Code Into AI Chatbots

mercoledì 8 luglio 2026, 10:59

Varonis Threat Labs disclosed a critical Dialogflow CX flaw, dubbed Rogue Agent, that let attackers with a single edit permission inject persistent malicious code into shared chatbot execution environments, exfiltrate conversations, and lau…

Cavern Manticore: Iranian-Linked APT Abuses SysAid RMM and DLL Sideloading to Deploy Modular C2 Framework

martedì 7 luglio 2026, 11:00

A newly identified Iranian-linked group, Cavern Manticore, is abusing the SysAid RMM platform and DLL sideloading via WinDirStat to deploy a modular C2 framework against Israeli organizations. Check Point ties the campaign to known Iranian…

Januscape: 16-Year-Old Linux KVM Flaw (CVE-2026-53359) Lets Malicious VMs Corrupt Host Kernel Memory

martedì 7 luglio 2026, 11:00

A 16-year-old flaw in Linux KVM, tracked as CVE-2026-53359 and dubbed Januscape, lets a malicious guest VM corrupt host kernel memory via a use-after-free in the shadow MMU’s nested virtualization path. A public PoC currently causes reliabl…

Tenda Router Backdoor (CVE-2026-11405) Lets Attackers Skip Login and Seize Full Admin Control

martedì 7 luglio 2026, 11:00

A hardcoded authentication backdoor in Tenda FH1201, W15E, AC10, AC5, and AC6 routers (CVE-2026-11405) lets attackers log in as admin with any username. The undocumented flaw sits in the device web server and cannot be detected through the…

Critical BeyondTrust Flaws (CVSS 9.2) in Remote Support and PRA Let Attackers Bypass Access Controls

martedì 7 luglio 2026, 11:00

BeyondTrust disclosed critical flaws (advisory BT26-03, CVSS 9.2) in Remote Support and Privileged Remote Access that let limited-privilege users bypass access controls. Cloud customers were auto-patched in April 2026, but self-hosted deplo…

New “Bad Epoll” Linux Zero-Day Lets Local Users Root Servers and Android Devices

lunedì 6 luglio 2026, 08:22

A newly disclosed Linux kernel flaw dubbed “Bad Epoll” (CVE-2026-46242) lets a local, unprivileged user escalate to root on Linux servers, desktops, and Android devices via a use-after-free in the epoll subsystem. There is no workaround; on…

PamStealer: New macOS Infostealer Disguises Itself as the Maccy Clipboard Manager

lunedì 6 luglio 2026, 08:22

PamStealer is a newly discovered macOS infostealer that impersonates the Maccy clipboard manager, using a two-stage AppleScript-to-Rust infection chain to steal Keychain data, browser credentials, and clipboard contents while evading detect…

Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk

lunedì 6 luglio 2026, 08:22

runZero has disclosed seven new CVEs in FatFs, the FAT/exFAT filesystem driver used across ESP-IDF, STM32Cube, Zephyr, MicroPython, and countless other embedded platforms. The bugs range from CVSS Medium to High and can lead to memory corru…

New T3MP3ST Framework Turns AI Coding Agents Into Autonomous 0-Day Hunters

lunedì 6 luglio 2026, 08:22

T3MP3ST, a new open-source framework, turns AI coding agents like Claude Code and Codex into autonomous red-teaming operators, claiming strong results on benchmark suites and a set of real 2026 CVEs.

Apache ActiveMQ Patches Three Vulnerabilities Enabling DoS, Data Leakage, and Privilege Escalation

lunedì 6 luglio 2026, 08:22

Apache ActiveMQ users should urgently patch three newly disclosed vulnerabilities — CVE-2026-53917, CVE-2026-54475, and CVE-2026-49877 — that can crash brokers, break temporary-destination isolation, and let low-privilege Web Console users…

Flipper Zero Maker Overhauls Firmware Contribution Rules After Community Backlash

lunedì 6 luglio 2026, 08:22

Flipper Devices has rolled out new firmware contribution rules, including GitHub Discussions-based feature voting and mandatory integration testing, after community backlash over a perceived firmware development slowdown.

Cybersecurity Week in Review: AI Model Redeployment, a Linux Root Zero-Day, and Hundreds of Chrome Patches

lunedì 6 luglio 2026, 08:22

This week: Anthropic’s Claude Mythos 5 returns to critical infrastructure use, a near-100%-reliable Linux root zero-day emerges, Chrome patches 382 bugs, and Scattered Spider notches another extradition.