Tag : Cybercrime

image_pdfimage_print

The Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison in the US. Maksim Silnikau, 40, built the ransomware operation and recruited other individuals through cybercrime forums, according to documents presented in court. Silnikau provided Ransom Cartel conspirators with stolen credentials and other information on compromised computers, as ..

Leggi tutto

Una vulnerabilità critica nella piattaforma AI di ServiceNow consente a un attaccante non autenticato di eseguire codice da remoto e prendere il controllo dell’istanza. Identificata come CVE-2026-6875 , è passata dalla pubblicazione del proof of concept tecnico ai primi payload osservati in rete in circa 72 ore, e la finestra di esposizione per chi gestisce ..

Leggi tutto

Una vulnerabilità critica nel cuore di WordPress consente a un attaccante anonimo di eseguire codice da remoto su un’installazione standard, senza credenziali, senza plugin e senza interazione della vittima. La falla, battezzata wp2shell dai ricercatori di Searchlight Cyber (divisione Assetnote) che l’hanno scoperta, colpisce il core della piattaforma che, secondo la stessa società, sostiene oltre ..

Leggi tutto

Il team GReAT di Kaspersky ha documentato nel report di Securelist OkoBot, un framework malevolo composto da oltre venti moduli che colpisce gli utenti di criptovaluta su Windows. La catena di attacco è stata ridisegnata a fine aprile 2025; la telemetria sulle vittime copre il periodo aprile 2025-giugno 2026 e GReAT ne ha identificato gli ..

Leggi tutto

A recently discovered advanced persistent threat (APT) actor has been targeting government and electric power organizations in multiple countries, Kaspersky reports. Dubbed Armored Likho, the APT engages both in financially motivated attacks against individuals and in cyber-espionage operations against organizations in Russia, Brazil, and Kazakhstan. The threat actor’s arsenal includes modular remote access trojans (RATs) ..

Leggi tutto

Threat actors are using prompt injection attacks embedded in malicious websites and manipulated search results to trick AI agents into making payments or trusting fraudulent cryptocurrency platforms. Zscaler says it identified two campaigns relying on indirect prompt injection, including a payment scam hiding behind API documentation, and a typosquatting operation promoting a crypto platform that ..

Leggi tutto

SecurityWeek’s cybersecurity news weekly roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of ..

Leggi tutto