Security Affairs
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations|The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating|US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers|U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog|Chaos ransomware deploys browser-based msaRAT to evade network detection|Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting|Check Point patches actively exploited SmartConsole authentication bypass flaw|CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections|Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft|U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog|OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test|Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522|UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations|The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating|US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers|U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog|Chaos ransomware deploys browser-based msaRAT to evade network detection|Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting|Check Point patches actively exploited SmartConsole authentication bypass flaw|CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections|Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft|U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog|OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test|Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Security Affairs newsletter Round 121 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. ·      Expert exploited an unrestricted File Upload flaw in a PayPal Server to remotely execute code ·      Hacker BestBuy pleads guilty to hijacking more than 900k Deutsche Telekom routers ·      Security Affairs newsletter Round 120 – News […]

newsletter

A new round of the weekly SecurityAffairs newsletter arrived!

The best news of the week with Security Affairs.

·      Expert exploited an unrestricted File Upload flaw in a PayPal Server to remotely execute code
·      Hacker BestBuy pleads guilty to hijacking more than 900k Deutsche Telekom routers
·      Security Affairs newsletter Round 120 – News of the week
·      Worst known governmental leak ever affected the Swedish Transport Agency. Homeland security at risk
·      EU digital chief Andrus Ansip announced its plans to improve cyber security in EU
·      New Debian 9.1 release includes 26 security fixes for 55 packages
·      SLocker decompiled code leaked online for free, a gift for crooks and hackers
·      SLocker source code leaked online for free, a gift for crooks and hackers
·      Spring Dragon APT used more than 600 Malware samples in different attacks
·      The UK continues to grant the export of surveillance equipment to countries like Turkey
·      32M is about to become the first in the US to implant a microchip to employees volunteers
·      Experts detailed the new Operation Wilted Tulip campaign of the CopyKittens APT
·      Fruitfly macOS and OS X backdoor remained undetected for years
·      Veritaseum – Hacker Steals $8.4 Million in Ethereum, for the second time during the ICO
·      Chinese Police dismantled the behind the Fireball adware campaign that infected more than 250 Million PCs
·      CrowdStrike presented the fastest and largest cybersecurity search engine
·      New CowerSnail Windows Backdoor linked to SHELLBIND SambaCry Linux Malware
·      UniCredit bank breach – Data of 400,000 loan applicants exposed due to the hack of a partner
·      DEF CON Talk Will Expose The Latest SMB Vulnerability SMBLoris
·      Experts found critical flaws in Diebold Opteva ATM that allow to vend notes from the machine
·      Google experts blocked a new targeted malware family, the Lipizzan spyware
·      Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin
·      BLACK HAT USA – Hackers turn car washing machines in a mortal trap
·      Critical Vulnerabilities discovered in Radiation Monitoring Devices (RDMs) used at Power Plants and Airports
·      Malware experts at ESET released a free tool for ICS Malware analysis
·      Wikileaks Vault 7 – Imperial projects revealed the 3 hacking tools Achilles, SeaPea and Aeris
·      BlackHat 2017 – Positive Technologies researcher claims ApplePay vulnerable to two distinct attacks
·      Chinese researchers from Tencent hacked a Tesla model once again
·      Experts spotted Triada Trojan in firmware of low-cost Android smartphones

Hurry up, subscribe to the newsletter, next Sunday you will receive all the news directly in your inbox.I desire to inform you that Security Affairs is now open to sponsored content..I desire to inform you that Security Affairs is now open to sponsored content.
I’ll offer the opportunity to:
•    Insert banners of various sizes in all the posts on Security Affairs.
•    Publish sponsored posts written by the customers that can include any kind of commercial reference.
•    Arrange a monthly/quarterly/annual campaign (for big customers) to advertise customers’ activities and discoveries.
For more info contact me at pierluigi.paganini@securityaffairs.co
Thanks for supporting Security Affairs.

newsletter

Once again thank you!

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Newsletter)

[adrotate banner=”13″]