News da fonti internazionali (BleepingComputer, DARK Reading, The Hacker News)
- WhatsApp phishing attack uses fake business docs to hack PCsby Bill Toulas on 22 Giugno 2026 at 10:42 pm
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]
- JaredFromSubway MEV bot hacked in $15 million crypto theftby Bill Toulas on 22 Giugno 2026 at 9:52 pm
The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. [...]
- FFmpeg fixes PixelSmash flaw in widely used video decoderby Bill Toulas on 22 Giugno 2026 at 9:05 pm
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]
- FortiBleed campaign used custom FortiGate sniffer to steal credentialsby Lawrence Abrams on 22 Giugno 2026 at 8:01 pm
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]
- ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attackby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 6:00 pm
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis
- Microsoft says Windows 11 26H2 is coming soon, details upgrade processby Lawrence Abrams on 22 Giugno 2026 at 5:41 pm
Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. [...]
- Microsoft fixes AutoGen Studio flaw that enabled code executionby Bill Toulas on 22 Giugno 2026 at 5:28 pm
A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage. [...]
- Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenantsby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 4:13 pm
Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers' applications without requiring authentication. The vulnerabilities have been collectively codenamed DifyTap by Zafran Security.
- Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaignby Elizabeth Montalbano on 22 Giugno 2026 at 4:10 pm
Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker.
- 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requestsby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 2:29 pm
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is still live in Squid's default configuration. Researchers at Calif.io disclosed it in June and named it Squidbleed (
- A Glimpse into the “Search Your Target” Market for Stolen Credentialsby Sponsored by Flare on 22 Giugno 2026 at 2:05 pm
Attackers no longer need to sift through massive credential dumps. They can pay others to do it for them. Flare explores how an emerging underground market searches stolen credential databases for specific companies, domains, and accounts. [...]
- New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealerby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 1:20 pm
Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware. Evidence indicates that the threat actor is likely Russian-speaking and financially motivated, owing to the
- Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countriesby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 12:45 pm
Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and the major device-maker app stores are in from the start. On that date, certified Android phones in Brazil, Indonesia, Singapore, and Thailand will block normal installs of apps whose developers have not registered an identity with Google, whether the app
- Stop Your Legacy Infrastructure from Hijacking Your AI Agentsby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 11:58 am
Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents. AI adoption is moving faster than security programs can account for. Roughly 71% of organizations are piloting AI agents across their
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and Moreby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 10:55 am
It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devicesby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 9:11 am
Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers this way. The warrant let CSIS alter,
- AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Networkby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 6:57 am
A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is still rising. The distinction matters. AryStinger exists for the stage of an attack that comes before the break-in. Infected
- INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacificby info@thehackernews.com (The Hacker News) on 22 Giugno 2026 at 6:06 am
A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity. According to INTERPOL's 2025/2026 Asia and South Pacific Cyberthreat Assessment Report, phishing has emerged as the most widespread and
- AryStinger botnet infected thousands of D-Link routers worldwideby Bill Toulas on 21 Giugno 2026 at 2:14 pm
A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. [...]
- New Prinz Eugen ransomware prioritizes recent files for encryptionby Bill Toulas on 20 Giugno 2026 at 3:23 pm
A new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. [...]
- Microsoft links Mastra AI supply chain attack to North Korean hackersby Lawrence Abrams on 20 Giugno 2026 at 2:09 pm
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]
- Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keysby info@thehackernews.com (The Hacker News) on 20 Giugno 2026 at 9:56 am
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens
- Klue OAuth breach victim list grows as Icarus hackers claim attackby Lawrence Abrams on 19 Giugno 2026 at 10:31 pm
Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. [...]
- Hackers exploit info disclosure bug in Gravity SMTP WordPress pluginby Bill Toulas on 19 Giugno 2026 at 8:25 pm
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chainby info@thehackernews.com (The Hacker News) on 19 Giugno 2026 at 6:37 pm
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use. This is not a remote attack. It requires
- The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processesby info@thehackernews.com (The Hacker News) on 19 Giugno 2026 at 6:33 pm
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller. "They also incorporate third-party or
- Texas govt data breach exposes over 3 million driver’s licensesby Bill Toulas on 19 Giugno 2026 at 4:12 pm
The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. [...]
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Executionby info@thehackernews.com (The Hacker News) on 19 Giugno 2026 at 3:30 pm
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the same machine and spawn a process on the host. No credentials, no sign-in screen, and no further user interaction once
- Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sitesby info@thehackernews.com (The Hacker News) on 19 Giugno 2026 at 3:07 pm
Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercriminals of access to infected computer systems," Maikel Rollman of the Netherlands National High Tech Crime Unit said. "This prevents
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devicesby info@thehackernews.com (The Hacker News) on 19 Giugno 2026 at 2:00 pm
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign, believed to be the work of Russian-speaking threat actors, has been codenamed FortiBleed. The number of compromised devices stands at
















