Home > Directory > Sicurezza > SecureBulletin
SecureBulletin EN
Cybersecurity news in English · visibilità: nel misto della home, non in primo piano.
Sito originale · Feed RSS della fonte
897 voci in archivio · mostrate 201–225 .
Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers
A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH credentials. The malicious packag…
FortiBleed: Over 73,000 Fortinet Firewalls Compromised in Industrial-Scale Cyber Espionage Campaign
An industrial-scale cyber espionage campaign dubbed “FortiBleed” has silently compromised over 73,932 unique Fortinet firewall URLs across 194 countries, targeting Fortune 500 companies, government entities, and a NATO defense contractor. D…
25-Year-Old cURL Vulnerability Patched in Record-Breaking Security Release Fixing 18 CVEs
A critical authentication bypass flaw in cURL that had existed undetected for over 25 years has been patched in curl 8.21.0, released June 24, 2026. The release simultaneously fixed 18 CVEs — the most ever addressed in a single curl version…
Microsoft Secure Boot Certificates Expire — Over a Billion PCs and Linux Systems at Risk
Microsoft’s original Secure Boot certificates have begun expiring as of June 24, 2026, affecting over a billion UEFI-capable PCs worldwide. Systems that fail to migrate to the 2023 replacement certificates will permanently lose the ability…
Operation Endgame Strikes Again: Europol Seizes StealC, Amadey and SocGholish Infrastructure — 326 Servers Down, $47M Frozen
Europol’s Operation Endgame has dismantled the infrastructure behind StealC, Amadey, and SocGholish malware, seizing 326 servers, freezing USD 47 million in crypto, and recovering 27 million stolen credentials. The action spanned six countr…
World Leaks Ransomware Dumps 630 GB of Tata Electronics Data — Confidential Apple and Tesla Files Exposed
Ransomware group World Leaks has published 630+ GB of stolen Tata Electronics data including confidential Apple iPhone manufacturing specs and Tesla engineering drawings marked as trade secrets. Tata manufactures roughly one-third of all iP…
State-Sponsored Hackers Exploit Cisco Catalyst SD-WAN Manager Zero-Day to Gain Root Access
A state-sponsored threat actor exploited zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to gain root access via a malicious CSV upload. The multi-phase intrusion also leveraged two CVSS 10.0 authentication bypass flaws and employe…
CISA Flags Actively Exploited Ubiquiti UniFi OS Vulnerabilities — Patch Deadline June 26
CISA has added three Ubiquiti UniFi OS vulnerabilities to its KEV catalog following confirmed active exploitation. Federal agencies must patch by June 26, 2026; the chained flaws enable progression from unauthorized access to full command e…
LastPass Customer Data Exposed Through Klue Supply Chain Attack — OAuth Tokens Abused to Access Salesforce CRM
LastPass disclosed a supply chain breach via vendor Klue, where stolen OAuth tokens gave attackers access to customer CRM data in Salesforce. Password vaults were not affected. IOCs have been identified.
Eight-Year-Old Samsung KNOX Flaw Exposed Hundreds of Millions of Galaxy Devices to Kernel Attacks
A critical use-after-free vulnerability in Samsung’s KNOX PROCA subsystem — undetected for 8 years — could allow kernel-level compromise on Galaxy S9 through S25 devices. Patch is available in Samsung’s January 2026 security update.
Bajaj Auto Confirms Ransomware Attack — Both Parent Company and Tech Subsidiary Affected
Bajaj Auto disclosed a ransomware attack on June 23, 2026, affecting systems at the company and its subsidiary BATL. The firm has notified CERT-In and is working to contain the incident.
DifyTap: Critical Flaws in AI Platform Dify Allow Silent Wiretapping of AI Conversations Across 1M+ Apps
Researchers at Zafran disclosed four vulnerabilities in Dify — including two critical CVSS 9+ flaws — that let attackers silently intercept AI conversations across tenants, access private files, and exploit an unauthenticated API endpoint…
Squidbleed: 29-Year-Old Squid Proxy Vulnerability Leaks Passwords and API Keys from Other Users
A critical heap overread vulnerability in Squid Proxy, dubbed Squidbleed, has gone undetected since 1997. Discovered with the help of AI, the flaw allows an attacker controlling an FTP server to leak HTTP authorization headers and API keys…
AryStinger Botnet Hijacks 4,300+ Routers to Build Global Covert Attack Proxy Network
Researchers have uncovered AryStinger, a stealthy botnet that has hijacked over 4,300 legacy Linksys and D-Link routers by exploiting decade-old vulnerabilities. Unlike DDoS botnets, AryStinger is purpose-built for covert reconnaissance and…
Prinz Eugen Ransomware Uses RemotePC RMM and PowerShell Stagers to Evade Detection
A new ransomware group is deploying the Go-based Prinz Eugen ransomware by abusing legitimate remote management software (RemotePC) and PowerShell stagers. The campaign has already hit major financial institutions and uses sophisticated ant…
Klue Supply Chain Hack Exposes Salesforce Data at Nine Cybersecurity Companies
A supply chain attack on market intelligence platform Klue has compromised Salesforce CRM data across at least nine organizations, including HackerOne, Huntress, and Recorded Future. The Icarus extortion group has claimed responsibility and…
SiderAI and MaxAI Chrome Extensions Expose 10 Million Users to Full Browser Compromise
Critical vulnerabilities dubbed Spyder and MaXSS have been discovered in the SiderAI and MaxAI Chrome extensions, which together are installed on over 10 million devices. The flaws allow malicious websites to hijack browser sessions, steal…
HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic
Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through legitimate AWS infrastru…
AutoJack: A Single Malicious Web Page Can Hijack Your AI Agent and Execute Arbitrary Code
A critical three-vulnerability exploit chain called AutoJack allows a single malicious web page to hijack Microsoft AutoGen Studio’s browsing agent and execute arbitrary code on the developer’s machine, requiring no user interaction beyond…
GentleKiller: Inside the Ransomware Framework Disabling 400+ EDR Security Products
ESET researchers have exposed GentleKiller, the in-house EDR-killing framework of the Gentlemen ransomware gang, capable of disabling over 400 security processes across 48 products using BYOVD kernel driver abuse. The rapidly evolving toolk…
CVSS 9.1: Critical Cisco ISE Vulnerabilities Enable Remote Code Execution and Unauthenticated Data Theft
Cisco has disclosed two critical vulnerabilities in its Identity Services Engine (ISE) — CVE-2026-20181 (RCE, CVSS 9.1) and CVE-2026-20190 (unauthenticated information disclosure) — affecting all ISE and ISE-PIC deployments. An authenticate…
CVE-2026-50656: Microsoft Confirms Defender ‘RoguePlanet’ Zero-Day — No Patch Available Yet
Microsoft has confirmed CVE-2026-50656, a zero-day TOCTOU race condition in Microsoft Defender dubbed ‘RoguePlanet,’ that allows low-privilege attackers to escalate to SYSTEM on fully patched Windows 10 and 11 systems. A functional public P…
usbliter8: New iPhone BootROM Vulnerability Exposes A12/A13 Apple SoCs to Full Chain-of-Trust Compromise
Security researchers have disclosed ‘usbliter8,’ a critical hardware-level BootROM vulnerability affecting Apple devices with A12, S4/S5, and A13 SoCs. The flaw allows attackers to bypass Apple’s entire Secure Boot chain — and because it re…
International Authorities Dismantle SocGholish (FakeUpdates) Malware Network — 106 Servers and 101 Domains Seized
International law enforcement agencies from the US, Netherlands, Canada, and Germany have dismantled the SocGholish malware network under Operation Endgame, seizing 106 servers and 101 domains while remediating nearly 15,000 infected websit…
Kodak Confirms Data Breach as ShinyHunters Claims 2.2 Million Customer Records Stolen
Iconic imaging company Kodak has confirmed a data breach following claims by the notorious ShinyHunters hacking group that it stole over 2.2 million customer records containing personally identifiable information and internal corporate data…