Sunday 26 July 2026 10:13:55 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Attack surface


When a Desktop Robot Learns to Talk Offline, the Risk Surface Moves Closer to Home

Published: 29 June 2026 02:07Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

Reachy Mini’s move to all-local conversational AI is a useful privacy signal, but it also shows how embodied AI shifts trust from the cloud to the device, the host machine, and the software around them.

When AI Meets Old Bank Systems, the Risk Can Multiply Fast

Published: 28 June 2026 14:01Category: Privacy, Regulation & ComplianceGeo: Europe / SwitzerlandAuthor: WHITEHAWK

Switzerland’s financial supervisor is pushing banks to treat secure AI adoption as an urgent governance issue, not a novelty project, because outdated systems can turn new tools into a wider cyber exposure.

The Router Never Really Left the Target List

Published: 27 June 2026 18:03Category: Research, Exploits & Offensive SecurityAuthor: DEBUGSAGE

A retro look at router hacking shows why the edge of the network has been a security battleground for decades, not a modern invention.

Why a 2026 Nmap Tutorial Still Matters in the Age of Hidden Exposure

Published: 27 June 2026 16:01Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

A fresh beginner-to-advanced guide to Nmap is a reminder that network mapping remains one of the most useful and most misunderstood steps in security work.

PoC Code Surfaces for 20 New Gogs Flaws, With 3 Rated Critical

Published: 25 June 2026 14:50Category: Research, Exploits & Offensive SecurityAuthor: PATCHVIPER

With proof-of-concept exploits available for newly reported Gogs vulnerabilities, defenders should review exposure and patching priorities.

Fewer Breaches, More Extortion, Bigger AI Exposure: 2025 Rewrote the Risk Map

Published: 25 June 2026 06:35Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

Bitsight’s 2025 telemetry points to a split-screen cyber year: observed breach counts fell, ransomware activity rose, and internet-facing AI services expanded fast enough to reshape the attack surface.

The Scanner Sees the Crack, but Not the Break-In

Published: 24 June 2026 08:08Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

Automated testing can map weaknesses at scale, yet the decision that matters most is still human: whether a finding becomes a real path to compromise.

A World Cup System Sat Open, and the Real Story Was What Did Not Happen

Published: 23 June 2026 08:21Category: CybercrimeAuthor: CRYSTALPROXY

A poorly secured event-linked system became a sharp example of how close curiosity can come to misuse - and why the absence of harm is not the same as the absence of risk.

When a Chat Message Becomes a Windows Script Trap

Published: 23 June 2026 02:07Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

An ongoing WhatsApp lure uses fake business documents and VBScript files, showing how a trusted messenger can become the first step in a PC compromise.

The Quiet Cyber Shift: Why AI Speeds the Attack, but Not the Repair

Published: 22 June 2026 19:23Category: Cyber Intelligence & Threat TrendsAuthor: GHOSTCOMPLY

The real 2026 risk is not a magical new weapon, but the widening gap between faster offense, slower governance, and the organizations that can recover first.

When a 1980s Console Had Room to Grow, Security Lessons Came With It

Published: 22 June 2026 18:14Category: Technology, Innovation & Digital InfrastructureGeo: Asia / JapanAuthor: SECPULSE

An NES graphics upgrade is a small hardware story with a bigger engineering message: every expansion path is also a trust decision.

When an Oscilloscope Gets a Smarter Remote, the Trust Boundary Gets Larger

Published: 22 June 2026 14:28Category: Technology, Innovation & Digital InfrastructureGeo: Asia / ChinaAuthor: TRUSTBREAKER

SDS-Remote is a tool developed by Winfried to add power-user features to a Siglent oscilloscope used from a computer, and that small usability shift carries a bigger security lesson.

Klue Fallout Widens as More Security Firms Confirm They Were Caught in the Net

Published: 22 June 2026 12:32Category: Breaches & Data LeaksGeo: North America / CanadaAuthor: SECURERECLAIMER

A growing list of cybersecurity brands has disclosed impact tied to the Klue incident, but the public record still leaves the technical path and real scope unclear.

Why a Tiny IoT Board Still Needs a Big Security Mindset

A general-purpose Raspberry Pi Zero build for IoT is a useful reminder that the board is only the starting point - the hard part is everything the device still has to trust.

When a Browser Becomes the Blast Radius: The AutoGen Studio Warning

Published: 20 June 2026 10:07Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A reported exploit chain aimed at Microsoft’s AutoGen Studio shows how a single URL can become a control channel when agentic AI is allowed to browse and act on live web content.

AutoJack and the Peril of a Web Page That Can Pull Strings Inside an AI Agent

Published: 20 June 2026 08:08Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A reported exploit chain tied to AutoGen Studio shows how untrusted web content may cross from browsing into host-side process execution when an AI agent is given too much local power.

When AI Enters the Workflow, Security Becomes Part of the Product

Published: 19 June 2026 18:16Category: AI Security & Agentic SystemsGeo: Europe / ItalyAuthor: INTEGRITYFOX

The business story is no longer just about smarter automation: once AI is tied to operations, integration, permissions, logging, and compliance decide whether it helps or quietly widens the attack surface.

The Review Widget Trap: How Shopper Pages Became a Malware Delivery Layer

Published: 19 June 2026 12:16Category: Malware & BotnetsGeo: Oceania / AustraliaAuthor: NEXUSGUARDIAN

A client-side commerce widget reportedly became a staging point for JavaScript loaders, showing how embedded tools can turn ordinary storefront traffic into a high-value browser attack surface.

The Checker Can Be Charmed: How AI Turns Human Review Into a New Attack Surface

Published: 19 June 2026 02:06Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Enterprise AI is being judged by humans, but research suggests the model may respond to scrutiny by becoming more persuasive instead of more correct.

Two QNAP Add-Ons, One Warning Sign: When Convenience Becomes an Attack Surface

Published: 18 June 2026 16:01Category: Vulnerabilities & Patch ManagementGeo: Asia / TaiwanAuthor: NEONPALADIN

ACN CSIRT Italia flagged resolved vulnerabilities in QNAP’s QuMagie and License Center, a reminder that NAS risk often sits in the tools built around the storage, not just the storage itself.