News da fonti internazionali (BleepingComputer, DARK Reading, The Hacker News)
- Name That Toon Conteston 26 Giugno 2026 at 11:00 am
- Reducing security operations complexity with Wazuh Cloudby Sponsored by Wazuh on 8 Giugno 2026 at 2:01 pm
Security teams are increasingly overwhelmed by alert fatigue, infrastructure maintenance, and complex hybrid environments. This article explores how Wazuh Cloud helps simplify SIEM/XDR operations through managed infrastructure, automated scaling, and AI-driven security analysis. [...]
- AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overloadby info@thehackernews.com (The Hacker News) on 8 Giugno 2026 at 1:19 pm
Phishing has always been a numbers game. AI has turned it into a volume machine. Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for Tier 1 to review, another link to inspect, and another alert that cannot be dismissed at a glance. As the queue grows, a credential theft attempt or malware delivery can easily
- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and Moreby info@thehackernews.com (The Hacker News) on 8 Giugno 2026 at 1:18 pm
Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked. A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes showed up again. And while everyone chased the loud stuff, quieter attackers sat in inboxes for months, reading mail and
- Check Point links VPN zero-day attacks to Qilin ransomware gangby Sergiu Gatlan on 8 Giugno 2026 at 1:05 pm
Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...]
- The Hardest Forkby info@thehackernews.com (The Hacker News) on 8 Giugno 2026 at 11:53 am
Mythos is real. I know a big chunk of the industry thinks it's a marketing stunt, and I get why. I get it. But I've seen the findings, and they're bad. These aren't "whoops, this line right here is wrong, and that's RCE." They're novel combinations of a few dozen issues out of thousands of things every SAST scanner already finds, chained together into something much worse. It's real creativity,
- Oxford University discloses data breach after careers platform hackby Sergiu Gatlan on 8 Giugno 2026 at 11:14 am
The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. [...]
- VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliancesby info@thehackernews.com (The Hacker News) on 8 Giugno 2026 at 10:27 am
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems. The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking groups known as Clay Typhoon (Microsoft),
- UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaignby info@thehackernews.com (The Hacker News) on 8 Giugno 2026 at 7:39 am
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as
- VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacksby info@thehackernews.com (The Hacker News) on 8 Giugno 2026 at 6:08 am
Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackle software supply chain threats. "When automatic updates are enabled, new versions are auto-updated two hours after they are published, adding an extra layer of protection
- Over 20,000 Instagram accounts stolen in Meta AI support hackby Sergiu Gatlan on 8 Giugno 2026 at 6:00 am
Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]
- Hands on with Intelligent Terminal, an AI-powered Windows Terminalby Mayank Parmar on 7 Giugno 2026 at 11:20 pm
Microsoft has created an open-source fork of Windows Terminal called "Intelligent Terminal," and it allows you to use AI directly inside Terminal without interfering with the regular session. [...]
- C0XMO botnet spreads via DD-WRT router flaw, kills rival malwareby Bill Toulas on 7 Giugno 2026 at 2:17 pm
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]
- Silent Ransom Group targets law firms with fake IT support callsby Lawrence Abrams on 7 Giugno 2026 at 2:09 pm
The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. [...]
- Critical Everest Forms Pro flaw exploited to take over WordPress sitesby Bill Toulas on 6 Giugno 2026 at 2:09 pm
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]
- New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltrationby info@thehackernews.com (The Hacker News) on 6 Giugno 2026 at 1:36 pm
OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that handle sensitive data and require stricter protection guarantees. Lockdown Mode is available to logged-in users across Free, Go, Plus, and Pro, and
- Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AIby info@thehackernews.com (The Hacker News) on 6 Giugno 2026 at 8:29 am
A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic for a data business Bright Data markets heavily to the AI industry. The company, the successor to Luminati, operates what it calls the largest residential proxy network in the world,
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalogby info@thehackernews.com (The Hacker News) on 6 Giugno 2026 at 8:14 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-28318 (CVSS score: 7.5), is a denial-of-service (DoS) bug that causes the service to crash
- AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugsby info@thehackernews.com (The Hacker News) on 6 Giugno 2026 at 7:28 am
Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent. The same week, Google shipped Chrome 149 with patches for 429 security bugs, the most ever in a single release. Only the FFmpeg bugs were found by AI.
- Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attackby info@thehackernews.com (The Hacker News) on 6 Giugno 2026 at 6:58 am
Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, per OpenSourceMalware. The development has GitHub to disable access to those repositories. "Access to this
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Availableby info@thehackernews.com (The Hacker News) on 6 Giugno 2026 at 4:19 am
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types - On-Prem Deployment Cisco SD-WAN Cloud-Pro Cisco SD-WAN Cloud (Cisco Managed) Cisco SD-WAN for Government (FedRAMP) "A
- Suspicious Polyfill login prompts pop up on Toshiba, Muji websitesby Bill Toulas on 5 Giugno 2026 at 9:54 pm
Tech giant Toshiba and mega-retailer Muji warned visitors that suspicious sign-in screens popping up on their websites could collect credentials. [...]
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversby Sergiu Gatlan on 5 Giugno 2026 at 7:15 pm
CISA warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. [...]
- Exposed Fuel Tank Gauges Under Attack in the USby Nate Nelson on 5 Giugno 2026 at 7:04 pm
Threat actors are taking advantage of Internet-exposed tank gauges by breaching gas stations, opening the door to disruption.
- Chinese APT deploys new malware to keep access to hacked networksby Bill Toulas on 5 Giugno 2026 at 6:09 pm
A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD. [...]
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacksby info@thehackernews.com (The Hacker News) on 5 Giugno 2026 at 6:05 pm
Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively. According to JFrog, the information stealer "scrapes every secret it can find on a developer's machine, hides behind an eBPF kernel rootkit, and
- Dark web Nemesis Market vendor gets 26 years for selling drugsby Sergiu Gatlan on 5 Giugno 2026 at 5:50 pm
A California man was sentenced to more than 26 years in federal prison for trafficking fentanyl and methamphetamine through Nemesis Market, one of the world's largest dark web marketplaces. [...]
- Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Appsby info@thehackernews.com (The Hacker News) on 5 Giugno 2026 at 2:53 pm
Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campaigns in early 2025, with each attack wave making use of distinct websites mimicking utilities, war-related updates, and a government news source: govlens[.]net, which
- Over 900 US gas station tank gauge systems exposed to attacksby Sergiu Gatlan on 5 Giugno 2026 at 2:50 pm
Over 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been found exposed online and are vulnerable to ongoing attacks. [...]
- Adaptive, Agentic AI Worms Loom as Next Enterprise Threatby Robert Lemos on 5 Giugno 2026 at 2:40 pm
AI worms, or "viruses with wings and brains," adapt to new environments, seek out vulnerabilities, and will likely strike within a year, researchers say.
.png?width=1280&auto=webp&quality=80&disable=upscale)















