domenica 30 agosto 2026 Privacy RSS Admin
ITAGORA!
Agorà Italia - il portale · directory · notizie · ricerca
CANALI: SicurezzaLinuxAndroidGeekNewsletterAttualitàPodcastTutta la directory

Home > Directory > Sicurezza > SecureBulletin

SecureBulletin EN

Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.

Sito originale · Feed RSS della fonte

897 voci in archivio · mostrate 176–200 .

Microsoft Ships KB5095189 Cumulative Update to Patch the Windows 11 Setup Experience

lunedì 6 luglio 2026, 08:22

Microsoft’s KB5095189 update patches the Windows 11 setup experience for versions 24H2 and 25H2. It carries no CVE, but enterprises relying on Autopilot-style provisioning should confirm devices aren’t drifting onto the older baseline.

Researcher Chains a Guardrail Bypass With a Path Traversal Flaw to Access System Files in ChatGPT

sabato 4 luglio 2026, 08:01

A proof-of-concept disclosed by researcher zer0dac combined social engineering against ChatGPT’s own safety logic with a path traversal bug to retrieve restricted system files through the platform’s file download mechanism. OpenAI has since…

Ousaban Banking Trojan Resurfaces With Steganographic PDF Lures Targeting Spain and Portugal

sabato 4 luglio 2026, 08:01

Fortinet’s FortiGuard Labs has documented a fresh wave of the Ousaban banking trojan hitting Windows users in Spain and Portugal through fake corrupted PDFs and a spoofed tax portal. The campaign hides its payload inside an image file using…

New ARToken Phishing Kit Abuses Microsoft’s OAuth Device Code Flow to Hijack Microsoft 365 Accounts

sabato 4 luglio 2026, 08:01

Cisco Talos has uncovered ARToken, a phishing panel that abuses Microsoft’s device code sign-in flow to steal Microsoft 365 session tokens without a password or MFA prompt. The kit shares code and infrastructure with the EvilTokens phishing…

Researchers Chain DLL Sideloading and an RPC Flaw to Gain Root Access Inside Claude Cowork’s Sandbox

sabato 4 luglio 2026, 08:00

Security researchers at Armadin found a way to chain DLL sideloading with a flaw in an internal RPC protocol to escalate privileges and execute commands as root inside Claude Cowork’s isolated Windows sandbox. The finding shows that even he…

Google Dismantles NetNut-Linked “Popa” Residential Proxy Botnet That Hijacked 2 Million Home Devices

venerdì 3 luglio 2026, 11:31

Google, working with the FBI, Lumen Technologies, and other partners, has taken action against the NetNut residential proxy network – also tracked as “Popa” – estimated to have compromised at least 2 million home devices worldwide for use a…

AsyncRAT Trojan Hidden in 90+ Fake Software Download Sites via DLL Sideloading and ScreenConnect

venerdì 3 luglio 2026, 11:31

A stealthy campaign is hiding the AsyncRAT trojan inside fake installers for popular free software, using DLL sideloading and the legitimate ScreenConnect remote-access tool to slip past security controls on over 90 spoofed download sites.

New CitrixBleed-Class Vulnerability in Citrix NetScaler Exploited Within 24 Hours of Disclosure

venerdì 3 luglio 2026, 11:30

CVE-2026-8451, the latest entry in the CitrixBleed family of NetScaler memory-disclosure flaws, came under active exploitation less than a day after public disclosure. Decoy infrastructure operator Lupovis tracked a single threat actor prob…

DHS Confirms Hackers Breached HSIN, the Government’s Emergency Information-Sharing Platform

venerdì 3 luglio 2026, 11:30

The Department of Homeland Security has confirmed a breach of the Homeland Security Information Network (HSIN), the unclassified platform used by federal, state, local, and international partners to coordinate emergency response. The intrus…

DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk

giovedì 2 luglio 2026, 12:57

Two critical zero-click RCE vulnerabilities (CVE-2026-50548, CVE-2026-50549) in Cursor IDE, dubbed DuneSlide, allow attackers to escape the AI coding agent sandbox via prompt injection with no user interaction required. Carrying CVSS 9.8 sc…

Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year

giovedì 2 luglio 2026, 12:57

An unpatched vulnerability in Apple’s Hide My Email feature can expose users’ real email addresses behind their iCloud+ anonymization aliases, researcher Tyler Murphy and 404 Media have confirmed. Apple was notified more than a year ago wit…

Four New CVEs in Fluentd Expose Millions of Cloud and Kubernetes Logging Pipelines to RCE and Data Leaks

giovedì 2 luglio 2026, 12:57

Four new CVEs in the widely deployed Fluentd log collector — including a critical RCE vulnerability (CVE-2026-44024) exploitable via crafted log entries — put cloud and Kubernetes logging pipelines at risk of code execution, data theft, den…

81 Million Login Attempts: Massive Password Spray Campaign Bypasses MFA to Compromise Azure and Microsoft 365 Accounts

giovedì 2 luglio 2026, 12:56

A massive automated campaign made 81 million login attempts against Microsoft 365 and Azure CLI accounts between June 12 and June 26, 2026, successfully compromising 78 accounts across 64 organizations by exploiting the legacy OAuth ROPC fl…

PoC Published for CVE-2026-24294: NTLM Reflection Bypass Grants SYSTEM Access on Windows Server 2025

mercoledì 1 luglio 2026, 06:55

Synacktiv has released a working PoC for CVE-2026-24294, a new NTLM reflection bypass that grants SYSTEM-level access on Windows Server 2025 by abusing the SMB-over-custom-port feature. Microsoft patched the issue in March 2026 Patch Tuesda…

Critical wolfSSL Vulnerabilities Expose Billions of Servers and IoT Devices to Certificate Forgery and RCE

mercoledì 1 luglio 2026, 06:54

Multiple newly disclosed vulnerabilities in the wolfSSL embedded TLS library — including certificate trust bypasses, heap overflows, and post-quantum cryptography weaknesses — put billions of servers, IoT devices, and industrial systems at…

SEO-Poisoned Bing Search Delivers BumbleBee Loader and Akira Ransomware to Enterprise Network

mercoledì 1 luglio 2026, 06:53

An IT administrator searching Bing for ManageEngine OpManager was redirected to a trojanized installer, triggering a 44-hour intrusion that ended with Akira ransomware deployed network-wide and 75GB of data exfiltrated to Ukraine.

CVE-2026-8037: Critical Pre-Auth RCE in Progress Kemp LoadMaster Puts Enterprise Networks at Risk

mercoledì 1 luglio 2026, 06:53

A CVSS 9.8 pre-authentication remote code execution vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to run arbitrary commands on enterprise network edge appliances. Patched versions are now availab…

Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen

martedì 30 giugno 2026, 09:04

Researchers scanning 50,000 ClawHub skills — the official marketplace for the OpenClaw AI agent platform — found working remote control backdoors, credential stealers, and autonomous malware that installs itself by manipulating AI agent dec…

Russia’s Turla APT Deploys STOCKSTAY Backdoor Against Ukrainian Government and Military Targets

martedì 30 giugno 2026, 09:03

Russia-linked Turla (FSB Center 16) has been running a long-running espionage campaign deploying a new .NET backdoor called STOCKSTAY against Ukrainian government and military organizations since December 2022. Google Threat Intelligence Gr…

Critical Microsoft 365 RCE Flaw CVE-2025-60727 Exploitable via Malicious Excel Files — Patch Now

martedì 30 giugno 2026, 09:03

Microsoft has disclosed CVE-2025-60727, a critical out-of-bounds read remote code execution vulnerability in Microsoft 365 Apps, Excel 2016, and multiple Office versions. An attacker can achieve full system compromise by convincing a user t…

Hackers Actively Exploit CVE-2026-46817 in Oracle E-Business Suite — 456 Attacks Recorded in 24 Hours

martedì 30 giugno 2026, 09:03

Threat actors are actively exploiting CVE-2026-46817, a critical CVSS 9.8 unauthenticated remote takeover flaw in Oracle E-Business Suite, with 456 attack hits recorded in a single day across honeypot infrastructure. Organizations running O…

Palo Alto GlobalProtect VPN Authentication Bypass CVE-2026-0257 Under Active Exploitation — Patch Now

lunedì 29 giugno 2026, 13:40

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a critical authentication bypass in GlobalProtect portal and gateway components that lets unauthenticated attackers establish unauthorized VPN sessions. CISA has added i…

macOS.Gaslight: North Korea-Linked Rust Backdoor Exfiltrates Data via Telegram and Poisons AI Analysis Tools

lunedì 29 giugno 2026, 13:40

A Rust-written macOS backdoor attributed to North Korean threat actors steals browser credentials, keychain files, and terminal history, exfiltrating everything via Telegram. The malware also embeds 38 prompt injection payloads to defeat AI…

LokiBot Returns: Multi-Stage JScript Campaign Uses Process Injection to Steal Credentials

lunedì 29 giugno 2026, 13:40

LokiBot, the decade-old credential stealer, has resurfaced with a sophisticated multi-stage attack chain: a JScript email dropper, in-memory .NET injection, and process hollowing inside aspnet_compiler.exe to silently harvest passwords from…

AWS AiTM Phishing Kit Bypasses MFA to Hijack Cloud Console Sessions in Real Time

lunedì 29 giugno 2026, 13:40

A real-time adversary-in-the-middle phishing kit has been targeting AWS engineers, stealing credentials and MFA codes simultaneously to hijack cloud sessions before they expire. Standard MFA provides zero protection against this attack clas…