Skip to the content
logo main
  • News
  • How To
  • Members Area
  • About me
  • English
    • Italiano
    • Français
    • Deutsch
    • English
logo main
Microsoft 365, Entra ID, and OAuth abuse remain a top initial-access channel
19/07/2026
News
by Giuseppe

Microsoft 365, Entra ID, and OAuth abuse remain a top initial-access channel

Identity abuse is one of the clearest operational threats in the feed, especially around Microsoft 365 and Entra ID. Attackers are using fake passkey enrollment, device-code flow a

Read more
Roundcube, ColdFusion, SharePoint and other enterprise web stacks are under active exploitation
19/07/2026
News
by Giuseppe

Roundcube, ColdFusion, SharePoint and other enterprise web stacks are under active exploitation

A major cluster of articles shows attackers moving quickly on high-value web application flaws, with CISA repeatedly adding exploited issues to its KEV catalog. Roundcube mail serv

Read more
Microsoft’s July patch tsunami and the race to compress exploitation windows
19/07/2026
News
by Giuseppe

Microsoft’s July patch tsunami and the race to compress exploitation windows

Microsoft’s July 2026 Patch Tuesday was one of the biggest security releases in company history, with coverage across hundreds of vulnerabilities and multiple already exploited i

Read more
Swiss banking and public-sector cyber agenda: NCSC, nLPD, and notification obligations keep gaining weight
19/07/2026
News
by Giuseppe

Swiss banking and public-sector cyber agenda: NCSC, nLPD, and notification obligations keep gaining weight

Across the feed, the strongest Swiss-relevant signal is not a single breach but the steady hardening of governance expectations around cyber risk, privacy, and incident handling. T

Read more
Ransomware and extortion operations continue to target organizations worldwide
18/07/2026
News
by Giuseppe

Ransomware and extortion operations continue to target organizations worldwide

Ransomware leak sites and reporting showed continued activity from groups such as Qilin, DragonForce, Akira, Play, Incransom, and others against companies, schools, hospitals, and

Read more
Credential theft, phishing, and fake downloads remain the main path to compromise
18/07/2026
News
by Giuseppe

Credential theft, phishing, and fake downloads remain the main path to compromise

Attackers continued to rely on phishing, fake installers, and stolen credentials as their most reliable access methods. Reports covered trojanized Webex, Zoom, and MobaXterm instal

Read more
CrowdStrike, Microsoft, and others are using AI to reframe vulnerability discovery and remediation
18/07/2026
News
by Giuseppe

CrowdStrike, Microsoft, and others are using AI to reframe vulnerability discovery and remediation

A series of vendor posts and interviews emphasized that frontier AI models are now finding vulnerabilities faster than traditional review and fuzzing in some contexts. Chainguard d

Read more
Passwordless identity and MFA changes are reshaping enterprise access management
18/07/2026
News
by Giuseppe

Passwordless identity and MFA changes are reshaping enterprise access management

Vendors are steadily shifting away from SMS and older second factors toward passkeys and hardware-backed authentication. Microsoft announced passkeys as the default sign-in experie

Read more
Security teams are racing to manage AI, MCP, and coding-agent risk in software development
18/07/2026
News
by Giuseppe

Security teams are racing to manage AI, MCP, and coding-agent risk in software development

A growing body of discussion centered on how AI coding agents, MCP servers, and agent histories create new software-security exposures. Researchers and practitioners warned that AI

Read more
Firmware and driver flaws continue to expose kernel and physical-memory abuse paths
18/07/2026
News
by Giuseppe

Firmware and driver flaws continue to expose kernel and physical-memory abuse paths

Several low-level vulnerabilities showed how drivers and firmware can grant attackers dangerous kernel capabilities. CERT published a Pegatron tdeio64.sys issue that allowed arbitr

Read more

Posts pagination

1 … 5 6 7 … 9
  • GitHub
  • LinkedIn
RSS Feeds
  • Articles FeedURL Copied!

Categories

  • API (1)
  • Artificial Intelligence (2)
  • CyberSec (4)
  • Development (2)
  • Hacking (1)
  • How To (9)
  • Malware Detection (1)
  • Members Only Content (2)
  • Mikrotik (2)
  • Mobile (2)
  • NetworkMonitoring (2)
  • NetworkSecurity (3)
  • News (79)
  • Privacy (2)
  • Programming (1)
  • Python (1)
  • RouterOS (1)
  • Security Tools (5)
  • Self-Hosting (2)
  • SMS (1)
  • Threat Hunting (1)
  • ThreatDetection (1)

Recent Posts

  • Brazilian banking trojan expanding into Portugal
    by Giuseppe
    24/07/2026
  • Iranian attacks against Siemens and Schneider industrial systems
    by Giuseppe
    24/07/2026
  • Check Point SmartConsole: authentication bypass actively exploited
    by Giuseppe
    24/07/2026
  • Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
    by Giuseppe
    24/07/2026
  • HollowGraph uses Microsoft 365 calendars as a covert C2 channel
    by Giuseppe
    23/07/2026

© 2026 SEC-TTL — All rights reserved

SEC-TTL is a cybersecurity news aggregator — sources are always credited and linked. Report / takedown · Copyright policy

  • News
  • How To
  • Members Area
  • About me
  • English
    • Italiano
    • Français
    • Deutsch
    • English