An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.
Android malware combo takes out loans and relays victims' credit cards
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
Hundreds of fake Chrome VPN extensions route traffic through a proxy
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider.
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.
Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire.
FBI: Hackers target online accounts to steal nude photos
The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos.
Hackers leverage new Microsoft SharePoint exploit in attacks
Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday.
TL;DR: Flipper OS is an additional layer on top of a standard Debian-based Linux system. It lets you switch between multiple preconfigured system profiles for different tasks, so you can experiment freely without worrying about breaking your setup or turning it into a mess.
Why build Flipper OS, yet another operating system, when there are already so many? Why not simply take a standard Debian-based system, as Raspberry Pi does, and customize it?
The problem is that conventional Linux
Signal adds new security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates.
Penetration test e AI: non serve un’AI più potente, ma un pentester più strategico
La competenza distintiva di un tester offensivo cambia ai tempi dell'intelligenza artificiale. Ecco come effettuare penetration test efficaci nell'era dell'AI
Mythos e Chronos, la corsa contro il tempo di Anthropic e le domande senza risposta
Un modello troppo capace per essere rilasciato al pubblico. Questo è Mythos, del quale si sa quel poco che basta per alimentare dubbi, legati anche alla corsa contro il tempo di Anthropic per sbarcare in borsa. Anche unendo i punti, i quesiti rimangono irrisolti
Patch Tuesday agosto 2026: un driver Windows, il gruppo Lazarus e 400 vulnerabilità sullo sfondo
Il Patch Tuesday di agosto 2026 interviene per correggere 421 vulnerabilità tra cui una zero-day nel driver WinSock già sfruttata da Lazarus e quattro RCE unauthenticated con CVSS 9.8. E conferma che con l’adozione l'AI-driven discovery il triage per contesto batte il triage per punteggio
6G, infrastruttura di sorveglianza pervasiva: rischi cyber, minaccia cinese e Golden power
Integrated Sensing and Communication (ISAC), consenso informato e resilienza delle reti mobili di sesta generazione: un'analisi tecnico-scientifica del 6G come infrastruttura di sorveglianza pervasiva
NIS2, ACN chiarisce come funzionerà la vigilanza: ora bisogna dimostrare la compliance
Le nuove FAQ di ACN chiariscono come funzioneranno monitoraggio e vigilanza NIS2. Per le imprese non basterà avere procedure e documenti: serviranno evidenze capaci di dimostrare l'effettiva applicazione delle misure e una governance che colleghi rischi, decisioni, responsabilità e controlli
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
A new NFC relay malware designated as WindRelay, paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out.
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity.
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.