惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
MyScale Blog
MyScale Blog
有赞技术团队
有赞技术团队
V
Visual Studio Blog
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
Vercel News
Vercel News
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Y
Y Combinator Blog
Blog — PlanetScale
Blog — PlanetScale
D
DataBreaches.Net
美团技术团队
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
A
About on SuperTechFans
云风的 BLOG
云风的 BLOG
The Cloudflare Blog
宝玉的分享
宝玉的分享
V
V2EX
Microsoft Azure Blog
Microsoft Azure Blog

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
Security Affairs newsletter Round 576 by Pierluigi Pagani...
Pierluigi Pa · 2026-05-10 · via Security Affairs

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Coordinated Takedown of Scam Centers Leads to at Least 276 Arrests; Alleged Managers and Recruiters Charged in San Diego  

Vimeo data breach exposes personal information of 119,000 people

Member of Prolific Russian Ransomware Group Sentenced to Prison  

Romanian National Appears in Federal Court Following Extradition from Romania on Bank Fraud Charges Stemming From “Vishing” Scheme  

AI Firm Braintrust Prompts API Key Rotation After Data Breach

Malware

CloudZ RAT potentially steals OTP messages using Pheno plugin  

xlabs_v1 DDoS-for-Hire IoT Botnet Exposed:  One Operator Error. An Entire Operation Revealed   

Darktrace Malware Analysis: Jenkins Honeypot Reveals Emerging Botnet Targeting Online Games  

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook  

Fake call logs, real payments: How CallPhantom tricks Android users

Hacking

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)  

Meet Bluekit: The AI-Powered All-in-One Phishing Kit  

South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)

Information about the Copy Fail vulnerability, which allows attackers to gain root access on virtually any modern Linux distribution    

The TSIG That Wasn’t: Finding an Authentication Bypass Across CoreDNS Transports  

Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack  

TrustFall: coding agent security flaw enables one-click RCE in Claude, Cursor, Gemini CLI and GitHub Copilot  

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

Dirty Frag: Universal Linux LPE 

ClaudeBleed: A Flaw In Claude’s Browser Extension Allows Any Extension to Hijack It 

Load-Bearing Assumptions — the rxrpc case (CVE-2026-43500) and the constraint that was never there  

Intelligence and Information Warfare

Army turns to ‘hackathons’ to better connect dozens of weapons, systems 

A rigged game: ScarCruft compromises gaming platform in a supply-chain attack  

Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution  

Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants  

Welcome to the GRU University, Where Moscow Turns Students into Spies and Hackers  

Cybersecurity

Preparing for a ‘vulnerability patch wave’      

Email threat landscape: Q1 2026 trends and insights  

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise  

India orders infosec red alert in case Mythos sparks crime spree

Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware

Google Chrome ‘silently’ downloads 4GB AI model to your device without permission, report claims — researcher says practice may violate EU law, waste thousands of kilowatts of energy  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment