F5 on Wednesday announced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP. The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker ..
Categoria : Security
During her time with the U.S. Secret Service, Hazel Cerra found herself at the precipice of the rise of cybercrime. Cerra noticed how digital evidence was becoming increasingly prevalent with each investigation. “I volunteered for technical assignments and pursued opportunities to build expertise in cyber investigations and critical systems protection,” Cerra says. Taking initiative paid ..
China’s military procurement system has suspended or permanently barred more than a dozen of the country’s leading cybersecurity vendors since 2024, according to new research from threat intelligence group Natto Thoughts. The findings, based on public notices from the military procurement network cross-referenced with corporate disclosures and Chinese media reports, identify at least 21 enforcement ..
Una finta promozione, la promessa di 100 dollari e un bot Telegram: è la trappola con cui, in una campagna a tema italiano documentata dalla società italiana D3Lab, viene distribuito Albiriox, un banking trojan Android costruito per la frode on-device. Il marchio abusato è quello di UniCredit, ma conviene chiarirlo subito per non generare equivoci: ..
Nearly a dozen Unified Extensible Firmware Interface (UEFI) shim bootloaders signed by Microsoft allow attackers to bypass Secure Boot protections, ESET warns. Small, trusted pieces of software bridge a computer motherboard’s UEFI firmware and the operating system, typically a Linux distribution, enabling the machine to boot with Secure Boot enabled. By using Microsoft-signed UEFI shim ..
Modern cargo vessels are becoming floating distributed data centers. A single ship spends weeks at sea exchanging data with cloud platforms, fleet management systems, cargo-monitoring applications, and shore-based operations centers. Thousands of connected devices run at once across the vessel and its cargo. That connectivity improves visibility and control, but it also creates a security ..
Nightmare Eclipse, the disgruntled security researcher who has been dropping zero-day exploits targeting Microsoft products, released another unpatched Windows vulnerability this week, right on the July 2026 Patch Tuesday. The fresh exploit, named LegacyHive, is a local privilege escalation bug in the Windows User Profile Service that allows an attacker to load other users’ hives, ..
La comunicazione di crisi è l’insieme delle decisioni con cui un’organizzazione, mentre un incidente è in corso, sceglie cosa dire, a chi e in quale momento. È la metà meno tecnica e più sottovalutata della risposta a un attacco informatico, eppure è quella su cui, a distanza di mesi, si misura quasi sempre il danno ..
An unpatched vulnerability in Cursor on Windows can be triggered for code execution when a developer opens a repository in the application, Mindgard reports. Cursor is one of the most popular AI-assisted development environments, with more than 7 million active users. The security defect, Mindgard says, is straightforward: when opening a repository, Cursor would automatically ..
The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday urged immediate hardening of Microsoft SharePoint servers in light of recently disclosed zero-day vulnerabilities. The freshest of the exploited flaws is CVE-2026-56164, a privilege escalation issue that can be exploited remotely without authentication, and which was resolved with Microsoft’s July 2026 Patch Tuesday updates. On ..


