Found 35940 bookmarks
Newest
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account.
·bleepingcomputer.com·
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.
·bleepingcomputer.com·
Acronis warns of actively exploited flaw in its cPanel backup plugin
Google fixes actively exploited Android zero-day on Pixel devices
Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.
·bleepingcomputer.com·
Google fixes actively exploited Android zero-day on Pixel devices
Windows Server 2022 reaches end of mainstream support next month
Windows Server 2022 reaches end of mainstream support next month
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031.
·bleepingcomputer.com·
Windows Server 2022 reaches end of mainstream support next month
Threat Hunting and Defending #2: concepts, framework, Threat Model (p3)
Threat Hunting and Defending #2: concepts, framework, Threat Model (p3)
La pratica del Threat Hunting è di supporto alla soluzione di problemi complessi e l’analista deve prendere in considerazione una notevole quantità di informazioni attraverso tools differenti…
·roccosicilia.com·
Threat Hunting and Defending #2: concepts, framework, Threat Model (p3)
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company.
·bleepingcomputer.com·
CenterPoint Energy confirms customer data stolen in cyberattack
Sensoristica IIoT e monitoraggio energetico: strategie per un’integrazione sicura nelle reti industriali
Sensoristica IIoT e monitoraggio energetico: strategie per un’integrazione sicura nelle reti industriali
L’IIoT consente di monitorare consumi e prestazioni degli impianti in tempo reale, ma moltiplica anche dispositivi e connessioni da proteggere. Segmentazione, identità dei nodi, firmware sicuro e governance dei dati sono essenziali per integrare la sensoristica senza aumentare il rischio OT
·cybersecurity360.it·
Sensoristica IIoT e monitoraggio energetico: strategie per un’integrazione sicura nelle reti industriali
Accessi remoti dei fornitori: governance e tracciabilità nei siti produttivi distribuiti
Accessi remoti dei fornitori: governance e tracciabilità nei siti produttivi distribuiti
L’accesso remoto dei fornitori è essenziale per manutenzione e assistenza degli impianti, ma può aprire percorsi privilegiati verso le reti OT. Zero Trust, MFA, privilegi temporanei e tracciamento delle sessioni permettono di conciliare operatività, sicurezza e governance della supply chain
·cybersecurity360.it·
Accessi remoti dei fornitori: governance e tracciabilità nei siti produttivi distribuiti
BambooToken malware controls Windows and Linux systems via MQTT
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
·bleepingcomputer.com·
BambooToken malware controls Windows and Linux systems via MQTT
Simulazioni di phishing: non misuriamo chi sbaglia, ma quanto regge il sistema
Simulazioni di phishing: non misuriamo chi sbaglia, ma quanto regge il sistema
Un dipendente può superare tutte le simulazioni e cadere nel phishing quando arrivano urgenza e pressione. Per questo il clic-rate non basta: la vera resilienza si misura anche nella capacità di fermarsi, verificare e segnalare, costruendo processi che continuino a proteggere l’azienda quando qualcuno sbaglia
·cybersecurity360.it·
Simulazioni di phishing: non misuriamo chi sbaglia, ma quanto regge il sistema
Sanzione privacy a BBVA: quando il CRM vanifica il diritto di opposizione
Sanzione privacy a BBVA: quando il CRM vanifica il diritto di opposizione
Il Garante privacy ha irrogato una sanzione di oltre 5,5 milioni di euro al Banco Bilbao Vizcaya Argentaria Italia (BBVA) per invio tramite app di comunicazioni commerciali benché l’utente reclamante avesse disattivato l’impostazione e avesse manifestato la propria opposizione a tale trattamento. Vediamo meglio
·cybersecurity360.it·
Sanzione privacy a BBVA: quando il CRM vanifica il diritto di opposizione
What Zero-Day Response Should Be in the Post-Mythos Era
What Zero-Day Response Should Be in the Post-Mythos Era
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive.
·bleepingcomputer.com·
What Zero-Day Response Should Be in the Post-Mythos Era
Cyber security, l’Europa investe 96 milioni: AI, resilienza e NIS2 tra le priorità
Cyber security, l’Europa investe 96 milioni: AI, resilienza e NIS2 tra le priorità
La call ECCC del Digital Europe Programme mette a disposizione una dotazione complessiva fino a 96 milioni di euro destinata a sette ambiti di intervento per il rafforzamento delle capacità cyber europee. Ecco quali e cosa prevedono: la roadmap in vista della scadenza di gennaio 2027 entro cui presentare le candidature
·cybersecurity360.it·
Cyber security, l’Europa investe 96 milioni: AI, resilienza e NIS2 tra le priorità
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
·bleepingcomputer.com·
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
Revolut Data Breach: Inside the Extortion Site
Revolut Data Breach: Inside the Extortion Site
KELA traced the Revolut data breach extortion site to free public hosting built in 6.5 hours, with deleted files recoverable from its public commit history.
·kelacyber.com·
Revolut Data Breach: Inside the Extortion Site
The Best Open-Source Projects We Starred in August 2026
The Best Open-Source Projects We Starred in August 2026
A roundup of 10 standout open-source repos we starred in August 2026 - spanning AI agent tooling, dev frameworks, and a few blockchain/wallet gems.
·hackerstribe.com·
The Best Open-Source Projects We Starred in August 2026
Revolut: violati dati alto profilo, la pista porta al Viminale
Revolut: violati dati alto profilo, la pista porta al Viminale
Il caso Revolut assume contorni sempre più particolari e porta direttamente in Italia, dentro le stanze delle autorità governative, da cui sembra partita la pec che ha ottenuto i dati riservati di circa 680 clienti di alto profilo. Ecco cosa sappiamo finora
·cybersecurity360.it·
Revolut: violati dati alto profilo, la pista porta al Viminale
Suspected Black Axe gang leaders face cybercrime charges in the US
Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges.
·bleepingcomputer.com·
Suspected Black Axe gang leaders face cybercrime charges in the US