Security Affairs Read, think, share ⌠Security is everyone’s responsibility
- Unusual toolset used in recent Fog Ransomware attackby Pierluigi Paganini on June 14, 2025 at 6:38 am
Fog ransomware operators used in a May 2025 attack unusual pentesting and monitoring tools, Symantec researchers warn. In May 2025, attackers hit an Asian financial firm with Fog ransomware, using rare tools like Syteca monitoring software and pentesting tools GC2, Adaptix, and Stowaway. Symantec researchers pointed out that the use of these tools is unusual
- A cyberattack on United Natural Foods caused bread shortages and bare shelvesby Pierluigi Paganini on June 13, 2025 at 10:32 pm
Cyberattack on United Natural Foods Inc. (UNFI) disrupts deliveries, causing Whole Foods shortages nationwide after systems were taken offline on June 5. United Natural Foods, Inc. (UNFI) is a Providence, Rhode Islandâbased natural and organic food company. The largest publicly traded wholesale distributor of health and specialty food in the United States and Canada, it is Whole Foods Marketâs main supplier, with their traffic making up over
- Paraguay Suffered Data Breach: 7.4 Million Citizen Records Leaked on Dark Webby Pierluigi Paganini on June 13, 2025 at 5:35 pm
Resecurity researchers found 7.4 million records containing personally identifiable information (PII) of Paraguay citizens on the dark web. Resecurity has identified 7.4 million records containing personally identifiable information (PII) of Paraguayan citizens leaked on the dark web today. Last week, cybercriminals have offered information about all citizens of Paraguay for sale, demanding $7.4 million in
- Apple confirmed that Messages app flaw was actively exploited in the wildby Pierluigi Paganini on June 13, 2025 at 10:15 am
Apple confirmed that a security flaw in its Messages app was actively exploited in the wild to target journalists with Paragonâs Graphite spyware. Apple confirmed that a now-patched vulnerability, tracked as CVE-2025-43200, in its Messages app was actively exploited in the wild to target journalists with Paragonâs Graphite spyware. The IT giant addressed the flaw
- Trend Micro fixes critical bugs in Apex Central and TMEE PolicyServerby Pierluigi Paganini on June 13, 2025 at 7:06 am
Trend Micro fixed multiple vulnerabilities that impact its Apex Central and Endpoint Encryption (TMEE) PolicyServer products. Trend Micro address remote code execution and authentication bypass vulnerabilities impacting its Endpoint Encryption (TMEE) PolicyServer and Apex Central solutions. Trend Micro Endpoint Encryption PolicyServer is a centralized management server used in Trend Microâs Endpoint Encryption solution. It acts
- Paragon Graphite Spyware used a zero-day exploit to hack at least two journalistsâ iPhonesby Pierluigi Paganini on June 12, 2025 at 7:58 pm
Security researchers at Citizen Lab revealed that Paragonâs Graphite spyware can hack fully updated iPhones via zero-click attacks. Citizen Lab has confirmed that Paragonâs Graphite spyware was used to hack fully updated iPhones, targeting at least two journalists in Europe. The group found forensic evidence showing the phones had communicated with the same spyware server.
- SinoTrack GPS device flaws allow remote vehicle control and location trackingby Pierluigi Paganini on June 12, 2025 at 11:45 am
Two vulnerabilities in SinoTrack GPS devices can allow remote vehicle control and location tracking by attackers, US CISA warns. U.S. CISA warns of two vulnerabilities in SinoTrack GPS devices that remote attackers can exploit to access a vehicleâs device profile without permission. The researchers warn that potential exploitation could allow attackers to track its location
- U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalogby Pierluigi Paganini on June 12, 2025 at 9:17 am
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added ASUS RT-AX55 devices, Craft CMS, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This week, Akamai researchers warned that
- Exposed eyes: 40,000 security cameras vulnerable to remote hackingby Pierluigi Paganini on June 12, 2025 at 7:37 am
Over 40,000 internet-exposed security cameras worldwide are vulnerable to remote hacking, posing serious privacy and security risks. Bitsight warns that over 40,000 security cameras worldwide are exposed to remote hacking due to unsecured HTTP or RTSP (Real-Time Streaming Protocol) access. These cameras stream live feeds openly via IP addresses, making them easy targets for spying,
- Operation Secure: INTERPOL dismantles 20,000+ malicious IPs in major cybercrime crackdownby Pierluigi Paganini on June 11, 2025 at 9:32 pm
INTERPOL announced that a joint operation code-named Operation Secure took down 20,000+ malicious IPs/domains tied to 69 info-stealers. Between January and April 2025, INTERPOL led Operation Secure, a global effort that took down over 20,000 malicious IPs and domains linked to information-stealing malware. With support from 26 countries and partners like Group-IB, Kaspersky, and Trend