Pierluigi Paganini

Malware Newsletter Round 91 - Latest Threats and Insights
The latest malware newsletter reveals new threats like Infiniti Stealer and npm supply chain attacks. Developers and organizations must stay alert to evolving risks in cybersecurity.

Malicious Email Delivers CMD Malware - Privilege Escalation Alert
A malicious email has delivered a .cmd malware file that escalates privileges and bypasses antivirus systems. Users are at risk of significant system compromise. Awareness and immediate action are vital to mitigate this threat.

Iran Handala Group Breaches Israeli Defence Contractor PSK Wind
Iranian hackers have breached PSK Wind Technologies, an Israeli defense contractor. Sensitive military data has been stolen, posing serious risks to national security. Organizations must strengthen their defenses against such cyber threats.

Google Dawn Flaw - CISA Adds CVE-2026-5281 to Catalog
CISA has flagged a critical vulnerability in Google Dawn, urging users to update their browsers immediately. This flaw allows remote code execution, putting many at risk. Stay safe by updating now.

Free VPNs Leak User Data - Privacy Risks Explained
A recent study reveals that many free VPNs on Android leak user data while claiming to protect privacy. Users are exposed to tracking and dangerous permissions. Choosing reputable VPN services is crucial for safeguarding digital privacy.

Telegram Zero-Day - Alleged Flaw Allows Device Takeover
A critical vulnerability in Telegram could allow hackers to take over devices without user interaction. Telegram denies the existence of this flaw, raising concerns for millions of users. With no patch available, the risk remains high. Stay alert and protect your device until a solution is found.
Threat Intel - Pro-Iranian Nasir Security Targets Energy Firms
Nasir Security, a group linked to Iran, is targeting energy companies in the Gulf. This poses a significant risk to critical infrastructure and regional stability. Companies must enhance their cybersecurity measures to mitigate these threats.
Malware - Iran-linked Actors Use Telegram for Attacks
Iran-linked actors are using Telegram to deploy malware against dissidents and journalists. This poses a serious risk of surveillance and data theft. The FBI is raising awareness to help protect potential victims.
Privacy Breach - French Carrier Tracked via Strava Activity
A French aircraft carrier was tracked through a sailor's Strava activity, revealing a serious operational security flaw. This incident highlights the risks of fitness apps for military personnel.
Threat Intel - Russia Establishes Vienna as Spy Hub for NATO
Russia has turned Vienna into its largest spy hub, monitoring NATO communications. With around 500 diplomats, many may be covert spies. This poses significant security risks for Western nations.
Payload Ransomware - Breaches Royal Bahrain Hospital Data
Payload Ransomware claims to have breached Royal Bahrain Hospital, stealing 110 GB of sensitive data. Patients and the healthcare sector are at risk as the group threatens to leak this data if the ransom isn't paid. Urgent action is needed to protect sensitive information.
Securing Unstructured Data in an AI-Driven World
File servers are fading as modern workflows shift to collaboration tools and AI. This change raises concerns about data security. Organizations need to rethink how they protect unstructured data across diverse platforms.
Secure Package Managers: ENISA's Essential Guide for Developers
ENISA has launched its first Technical Advisory on Secure Package Managers. This guide helps developers safely use third-party packages. With rising security threats, following these best practices is essential for protecting your projects. Don't risk your software's integrity!