A Ukrainian-Russian dual national who spent years overseeing one of the most operationally sophisticated money laundering rings in recent cybercrime…
Tag: EN
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 118
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
Engineer Jailed Over Insider Cyber Extortion Plot Against Industrial Firm
The former infrastructure engineer was sentenced to 32 months in federal prison for sabotage of his employer’s computer network and for demanding a ransom…
AgentCorruption Exposes Security Risks in Amazon Bedrock AgentCore
A single prompt could have led to the exposure of conversations, source code, stored memories and cloud credentials across multiple AI agents in the same…
Nippon Columbia malware incident exposes 8.6 million karaoke fan records
Daiichi Kosho, a major Japanese entertainment system maker, disclosed that a malware infection at its contractor, Nippon Columbia, exposed more than 8.7…
Stolen Passwords Expose 1,787 US Water Providers to Hackers
A new cybersecurity study has found that stolen passwords are exposing more than 1,700 American water and wastewater providers to potential hacking.…
Bitdefender finds preinstalled Android malware you can’t uninstall, seen in 150 countries
Bitdefender finds Midnight Mimosa, preinstalled Android malware on cheap MediaTek phones that fakes ad clicks, drops apps and builds a proxy botnet.…
Claude Exploited SQL Injection Flaws to Execute Commands on Real Servers
Anthropic has revealed that Claude models exploited software flaws, ran commands on real servers, submitted live forms, and bypassed web limits during…
The Luna Moth Files Weren’t Hacked. Here’s How They Leaked.
When asked about the “Luna Moth Files” that had mysteriously appeared online, Silent Ransom Group called them “fake” and insisted they hadn’t had any leak…
Security Affairs newsletter Round 599 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email…
“123456” password used in massive Danish CPR data breach
Ritzau has more on the Denmark Central Person Register (CPR) breach that affected more than 5 million living Danes and 3 million deceased: At least three…
Anthropic Restricts Internet Access for Internal AI Tests After Claude Models Target Real Websites
Anthropic has restricted live internet access across its internal artificial intelligence evaluations after finding cases in which Claude models performed…
AI systems are fully capable of carrying out nightmare attacks against infrastructure and nobody’s ready
Meanwhile, AI agents move robotic arms, ‘make OT device operator screens lie’
Two days to TechCrunch Disrupt: What’s next for AI and software development
First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code…
Why “secure by design” is the new standard for open source
Open source software faces significant regulatory shifts, making “secure by design” development practices increasingly important. The Cyber Resilience Act…
U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to its Known Exploited…
Below the Waterline Stage 2 – Regulating Red Teams
Regulated red teaming explained: CBEST, TIBER-EU, DORA and more with practical guidance on safe delivery, approvals, evidence and reporting.
Week in review: FortiBleed is still active, Patch Tuesday forecast
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Three questions a hospital CISO should ask a healthcare…
Google Domains CCTLD Registry Hijacks – Chrome Responds
HOC Shorts Cybercriminals compromised the infrastructure of three Country-Code Top-Level Domain (ccTLD) registry—.gh (Ghana), .sl (Sierra Leone), and…
Ransomware Actors Exploiting Palo Alto GlobalProtect Flaw for Stealthy VPN Access
Ransomware groups are actively exploiting CVE-2026-0257, an authentication bypass affecting Palo Alto Networks PAN-OS GlobalProtect and Prisma Access.…
