Roundcube 1.7.2 closes high-impact XSS and SSRF issues, a reminder that webmail platforms sit where untrusted email content and server-side network access can become the same attack surface.
A former European Parliament member involved in spyware oversight was reported to have had a mobile device repeatedly hacked, turning a case about surveillance abuse into a warning about the security of high-risk political work.
Researchers reported Pegasus on the phone of a former European Parliament spyware investigator, a reminder that mobile surveillance can cut straight through oversight circles.
A reported exploit chain aimed at Microsoft’s AutoGen Studio shows how a single URL can become a control channel when agentic AI is allowed to browse and act on live web content.
A reported Outlook zero-click flaw tied to APT28 underscores a hard truth: mail rendering and legacy NTLM authentication can intersect in ways that expose credential material without a deliberate click.
Agentic systems can turn trusted content, tools, and memory into an attack path, making human oversight easier to outrun than many teams expect.
A critical Windows Netlogon flaw tied to CVE-2026-41089 puts domain controllers in the highest-risk tier, where a network-reachable bug can become an identity problem, not just a server patch.
A reported zero-click case on iPhone pushes mobile identity security into the spotlight, where account abuse can look normal until the messages start moving money.
A reported zero-click chain linking WhatsApp for iOS and Apple’s ImageIO framework highlights how legacy iPhones can turn a chat app into a stealthy fraud surface.
Un percorso zero-click da una vulnerabilità di decodifica Dolby al controllo a livello kernel mostra come la sicurezza mobile possa crollare nel punto di giunzione tra parsing multimediale e driver del vendor.
Una catena di exploit segnalata mostra come un punto d’appoggio multimediale zero-click possa essere combinato con una vulnerabilità di un driver specifica del dispositivo per far salire la posta in gioco dal rischio di parsing all’impatto a livello kernel.
La correzione di Microsoft per CVE-2026-40361 ha rimesso sul tavolo una domanda familiare: quanto rischio può vivere nel percorso di anteprima della posta prima che qualcuno faccia clic su qualcosa?
Un proof-of-concept in circolazione per CVE-2026-0073 ha attirato l’attenzione sul percorso di debug wireless di Android, dove un errore nel controllo dell’affidabilità potrebbe contare molto più di quanto dovrebbe una semplice funzione di comodità.
A stealthy Unicode trick has left thousands of helpdesk servers wide open to attackers-no clicks, no logins required.
Un subdolo trucco Unicode ha lasciato migliaia di server helpdesk spalancati agli attaccanti-nessun clic, nessun login richiesto.