Security Affairs

Security Affairs Read, think, share … Security is everyone’s responsibility

  • The European Commission confirmed a cyberattack affecting part of its cloud systems
    by Pierluigi Paganini on March 27, 2026 at 9:43 pm

    The European Commission confirmed a cyberattack affecting part of its cloud systems, now contained, with no impact on internal networks. On March 24, the European Commission detected a cyberattack affecting the cloud infrastructure hosting its Europa.eu websites. The incident was quickly contained, with mitigation measures applied and no disruption to website availability. Early findings suggest

  • New AITM phishing wave hijacks TikTok Business accounts
    by Pierluigi Paganini on March 27, 2026 at 3:23 pm

    A new AITM phishing campaign targets TikTok Business accounts to hijack them for malvertising, continuing tactics seen in earlier Google-themed scams. Push Security researchers uncovered a new wave of AITM phishing pages targeting TikTok for Business accounts, aiming to hijack them for malvertising. The campaign includes TikTok and Google-themed fake pages, showing links to previous

  • CISA and BSI warn orgs of critical PTC Windchill and FlexPLM flaw
    by Pierluigi Paganini on March 27, 2026 at 2:58 pm

    CISA warns of a critical flaw in PTC Windchill and FlexPLM (CVE-2026-4681), with no patch yet and potential for imminent exploitation. CISA issued an advisory about a critical vulnerability, tracked as CVE-2026-4681 (CVSS score of 10.0), in PTC’s Windchill and FlexPLM software. At this time, no patches are available, and no active attacks have been

  • U.S. CISA adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalog
    by Pierluigi Paganini on March 27, 2026 at 10:14 am

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Aquasecurity Trivy flaw, tracked as CVE-2026-33634 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. On March 19, 2026, attackers used compromised credentials to release a malicious

  • China-linked Red Menshen APT deploys stealthy BPFDoor implants in telecom networks
    by Pierluigi Paganini on March 27, 2026 at 6:16 am

    China-linked Red Menshen APT group used stealthy BPFDoor implants in telecom networks to spy on government targets. Rapid7 Labs uncovered a China-linked threat group known as Red Menshen has been running a long-term espionage campaign by infiltrating telecom networks, mainly in the Middle East and Asia. Active since at least 2021, the group uses highly

  • U.S. CISA adds a Langflow flaw to its Known Exploited Vulnerabilities catalog
    by Pierluigi Paganini on March 26, 2026 at 9:05 pm

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Langflow to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Langflow flaw, tracked as CVE-2026-33017 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. Langflow is a popular tool used for building agentic AI workflows.  CVE-2026-33017 is a

  • Coruna exploit reveals evolution of Triangulation iOS exploitation framework
    by Pierluigi Paganini on March 26, 2026 at 7:12 pm

    Kaspersky found Coruna iOS exploits reuse updated code from the 2023 Operation Triangulation attacks, suggesting a possible link. Kaspersky researchers discovered that the Coruna iOS exploit kit uses an updated version of the same kernel exploit seen in the 2023 Operation Triangulation campaign. While early evidence didn’t clearly link the two, the code similarities now

  • Researchers uncover WebRTC skimmer bypassing traditional defenses
    by Pierluigi Paganini on March 26, 2026 at 11:30 am

    Researchers found a new skimmer using WebRTC to steal and send payment data, bypassing traditional security controls. Sansec researchers discovered a new payment skimmer that uses WebRTC data channels instead of typical web requests to load malicious code and exfiltrate stolen payment data. “What sets this attack apart is the skimmer itself. Instead of the usual

  • Russian authorities arrest alleged LeakBase admin behind stolen data marketplace
    by Pierluigi Paganini on March 26, 2026 at 8:47 am

    Russian authorities arrested the alleged LeakBase admin for running a marketplace selling stolen data since 2021. Russian law enforcement has arrested the suspected administrator of LeakBase, a cybercrime forum used to trade stolen personal data. The suspect, from Taganrog, is accused of running the platform since 2021. During a search of his home, authorities seized

  • Russian national convicted for running botnet used in attacks on U.S. firms
    by Pierluigi Paganini on March 25, 2026 at 9:27 pm

    A Russian hacker got 2 years in prison, $100K fine, and $1.6M judgment for running a botnet used in ransomware attacks on U.S. firms. Russian national Ilya Angelov (40) was sentenced to 24 months in prison for operating a botnet used to carry out ransomware attacks on dozens of U.S. companies. He was also fined

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.