Martedi 22 Settembre 2026 06:09:03 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContatti
ItalianoEnglish

#zero-click


Roundcube’s Patch Day Exposes a Familiar Trap: Mail Content Can Attack Both the Browser and the Backend

Published: 10 July 2026 08:43Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

Roundcube 1.7.2 closes high-impact XSS and SSRF issues, a reminder that webmail platforms sit where untrusted email content and server-side network access can become the same attack surface.

The Watchdog Was Watched: Pegasus Lands on a Spyware Investigator

Published: 03 July 2026 14:15Category: Cyber Warfare & Nation-State OperationsGeo: Europe / GreeceAuthor: AGONY

A former European Parliament member involved in spyware oversight was reported to have had a mobile device repeatedly hacked, turning a case about surveillance abuse into a warning about the security of high-risk political work.

When the Spyware Watchers Become the Watched

Published: 03 July 2026 08:19Category: Cyber Warfare & Nation-State OperationsGeo: Europe / GreeceAuthor: AGONY

Researchers reported Pegasus on the phone of a former European Parliament spyware investigator, a reminder that mobile surveillance can cut straight through oversight circles.

When a Browser Becomes the Blast Radius: The AutoGen Studio Warning

Published: 20 June 2026 10:07Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A reported exploit chain aimed at Microsoft’s AutoGen Studio shows how a single URL can become a control channel when agentic AI is allowed to browse and act on live web content.

Inbox as Tripwire: The Outlook Path That Can Turn Hidden Mail Into Credential Leakage

Published: 12 June 2026 14:36Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

A reported Outlook zero-click flaw tied to APT28 underscores a hard truth: mail rendering and legacy NTLM authentication can intersect in ways that expose credential material without a deliberate click.

When the Agent Clicks for You: The Quiet Risk Behind Zero-Click AI Compromise

Published: 05 June 2026 10:08Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Agentic systems can turn trusted content, tools, and memory into an attack path, making human oversight easier to outrun than many teams expect.

When Netlogon Breaks, the Domain Feels It First

Published: 01 June 2026 10:29Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A critical Windows Netlogon flaw tied to CVE-2026-41089 puts domain controllers in the highest-risk tier, where a network-reachable bug can become an identity problem, not just a server patch.

When a Chat App Speaks for You: The Silent WhatsApp Takeover Risk on iOS 16

Published: 27 May 2026 13:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A reported zero-click case on iPhone pushes mobile identity security into the spotlight, where account abuse can look normal until the messages start moving money.

When a Single Image Can Become a Payment Scam on Older iPhones

Published: 26 May 2026 16:37Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A reported zero-click chain linking WhatsApp for iOS and Apple’s ImageIO framework highlights how legacy iPhones can turn a chat app into a stealthy fraud surface.

Quando un bug multimediale raggiunge il kernel: la catena del Pixel 10 che conta

Pubblicato: 15 Maggio 2026 19:45Categoria: Ricerca, Exploit e Sicurezza OffensivaArea: Nord America / USAAutore: PATCHVIPER

Un percorso zero-click da una vulnerabilità di decodifica Dolby al controllo a livello kernel mostra come la sicurezza mobile possa crollare nel punto di giunzione tra parsing multimediale e driver del vendor.

Pixel 10 e il percorso silenzioso dall’audio dei messaggi alla potenza del kernel

Pubblicato: 15 Maggio 2026 19:00Categoria: Ricerca, Exploit e Sicurezza OffensivaArea: Nord America / USAAutore: DEBUGSAGE

Una catena di exploit segnalata mostra come un punto d’appoggio multimediale zero-click possa essere combinato con una vulnerabilità di un driver specifica del dispositivo per far salire la posta in gioco dal rischio di parsing all’impatto a livello kernel.

Il lato nascosto di Outlook: una patch critica riaccende la minaccia della posta zero-click

Pubblicato: 13 Maggio 2026 16:23Categoria: Vulnerabilità e gestione delle patchArea: North America / USAAutore: SECURESPECTER

La correzione di Microsoft per CVE-2026-40361 ha rimesso sul tavolo una domanda familiare: quanto rischio può vivere nel percorso di anteprima della posta prima che qualcuno faccia clic su qualcosa?

La scorciatoia di debug di Android è appena diventata l’anello più debole

Pubblicato: 11 Maggio 2026 13:53Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: SECURESPECTER

Un proof-of-concept in circolazione per CVE-2026-0073 ha attirato l’attenzione sul percorso di debug wireless di Android, dove un errore nel controllo dell’affidabilità potrebbe contare molto più di quanto dovrebbe una semplice funzione di comodità.

Invisible Threat: FreeScout Servers Laid Bare by Zero-Click Exploit

Published: 04 March 2026 11:32Category: Vulnerabilities & Patch ManagementAuthor: KERNELWATCHER

A stealthy Unicode trick has left thousands of helpdesk servers wide open to attackers-no clicks, no logins required.

Minaccia invisibile: server FreeScout messi a nudo da un exploit zero-click

Pubblicato: 04 Marzo 2026 11:32Categoria: Vulnerabilities & Patch ManagementAutore: KERNELWATCHER

Un subdolo trucco Unicode ha lasciato migliaia di server helpdesk spalancati agli attaccanti-nessun clic, nessun login richiesto.