Found 33868 bookmarks
Newest
Websites with an undefined trust level: avoiding the trap
Websites with an undefined trust level: avoiding the trap
We explain what suspicious websites are and how to distinguish a safe site from a fraudulent one. A new category in Kaspersky solutions: we’re sharing global statistics on untrusted site detection.
·securelist.com·
Websites with an undefined trust level: avoiding the trap
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
Kaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot. We attribute this activity to OceanLotus APT.
·securelist.com·
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
Exploits and vulnerabilities in Q1 2026
Exploits and vulnerabilities in Q1 2026
This report provides statistical data on published vulnerabilities and exploits we researched during Q1 2026. It also includes summary data on the use of C2 frameworks in APT attacks.
·securelist.com·
Exploits and vulnerabilities in Q1 2026
CVE-2025-68670: discovering an RCE vulnerability in xrdp
CVE-2025-68670: discovering an RCE vulnerability in xrdp
During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.
·securelist.com·
CVE-2025-68670: discovering an RCE vulnerability in xrdp
State of ransomware in 2026
State of ransomware in 2026
Kaspersky researchers are sharing insights into the main ransomware trends for 2026: EDR killers on the rise, switching from data encryption to data leaks, and more.
·securelist.com·
State of ransomware in 2026
Kimsuky targets organizations with PebbleDash-based tools
Kimsuky targets organizations with PebbleDash-based tools
Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.
·securelist.com·
Kimsuky targets organizations with PebbleDash-based tools
The Browser Under Siege: Q1 2026 Phishing Report
The Browser Under Siege: Q1 2026 Phishing Report
Across Q1 2026, PIXM detected and analyzed over 75 distinct phishing campaigns. What stands out is not the volume — it is how rapidly the campaigns matured across the quarter. January's attacks relied on credential harvesting forms and consumer brand impersonation. By March, the same threat surface featured 100+ phishing pages hosted on Microsoft's own Azure infrastructure, comprehensive MFA bypass against authenticator apps and FIDO tokens, and fully functional proxy-based site clones.
·pixmsecurity.com·
The Browser Under Siege: Q1 2026 Phishing Report
Cybersecurity “intro”
Cybersecurity “intro”
Come ho raccontato qualche giorno fa su altri canali ho iniziato a lavorare su una serie di video + articoli tecnici dedicati esclusivamente a chi vuole iniziare a lavorare nel contesto cybersecuri…
·roccosicilia.com·
Cybersecurity “intro”
Info per i supporter
Info per i supporter
Cari supporter – ovvero coloro che oltre a leggere i miei post e vedere i video hanno anche deciso di sostenere il mio progetto di divulgazione – ho un aggiornamento strutturale da farv…
·roccosicilia.com·
Info per i supporter
Info Sec Unplugged: update sul progetto podcast.
Info Sec Unplugged: update sul progetto podcast.
Il progetto podcast ha effettivamente preso una buona piega: assieme ad Andrea stiamo registrando con la media delle due puntate al mese e da quando ne ho parlato l’ultima volta ci sono quatt…
·roccosicilia.com·
Info Sec Unplugged: update sul progetto podcast.
MISP how-to: integrazione di feeds
MISP how-to: integrazione di feeds
Premessa Questo post riprende una serie di contenuti che avevo in roadmap sul tema MISP e vorrei farlo discutendo alcuni use case su cui sto lavorando. Come alcuni sanno tempo fa ho iniziato a lavo…
·roccosicilia.com·
MISP how-to: integrazione di feeds
Cina, Stati Uniti e la sfida degli abissi
Cina, Stati Uniti e la sfida degli abissi
La mappatura dei fondali oceanici sta diventando un elemento sempre più importante della competizione tra le due superpotenze, per motivi militari, economici e scientifici.
·guerredirete.it·
Cina, Stati Uniti e la sfida degli abissi
Polymarket e i pericoli dei mercati predittivi
Polymarket e i pericoli dei mercati predittivi
Scommesse su guerre e tragedie, rischi di insider trading e minacce: perché la nuova frontiera della speculazione selvaggia deve preoccuparci
·guerredirete.it·
Polymarket e i pericoli dei mercati predittivi
Fuga da Big Tech
Fuga da Big Tech
È possibile sottrarsi alle grandi piattaforme e ricreare un ambiente online libero, collettivo e governato dagli stessi utenti? Come scrive Kenobit in “Assalto alle piattaforme”, le alternative esistono, ma la strada per conquistare la libertà digitale è ancora molto lunga.
·guerredirete.it·
Fuga da Big Tech
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
A 24-year-old British national and senior member of the cybercrime group "Scattered Spider" has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer…
·krebsonsecurity.com·
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
Anti-DDoS Firm Heaped Attacks on Brazilian ISPs
Anti-DDoS Firm Heaped Attacks on Brazilian ISPs
A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm's chief…
·krebsonsecurity.com·
Anti-DDoS Firm Heaped Attacks on Brazilian ISPs
Canvas Breach Disrupts Schools & Colleges Nationwide
Canvas Breach Disrupts Schools & Colleges Nationwide
An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service's login page with a ransom demand that…
·krebsonsecurity.com·
Canvas Breach Disrupts Schools & Colleges Nationwide
Patch Tuesday, May 2026 Edition
Patch Tuesday, May 2026 Edition
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the…
·krebsonsecurity.com·
Patch Tuesday, May 2026 Edition
Aggiornamento Statuto Associativo Berghem-in-the-Middle
Aggiornamento Statuto Associativo Berghem-in-the-Middle
Ciao a tutti! 👋 Grazie al via libera dei soci nell’ultima assemblea, abbiamo ufficialmente depositato il nuovo statuto associativo, in …
·hacklabg.net·
Aggiornamento Statuto Associativo Berghem-in-the-Middle
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.
·group-ib.com·
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns