Francesco Cipollone🔥Appsec and ☁️ Cloudsec 🐒
@FrankSEC42
Followers
6K
Following
26K
Media
3K
Statuses
19K
Appsec and cloudsec crazy, CEO & founder and @sec_phoenix and @nsc42ltd board of @csaukchapter London host of @podcast_cyber
London, England
Joined September 2018
Check out this great conversation: Chris romeo live no
0
0
6
Microsoft Teams phishing attack alerts coming to everyone next month - @serghei
https://t.co/3ZKnt22EBv
https://t.co/3ZKnt22EBv
bleepingcomputer.com
Microsoft reminded Microsoft 365 admins that its new brand impersonation protection feature for Teams Chat will be available for all customers by mid-February 2025.
0
86
221
🛑 Urgent: Apple has released a software update to patch a zero-day vulnerability (CVE-2025-24085) actively exploited in the wild, affecting iPhones, iPads, Macs, Apple TVs, and more. 👉 Read:
thehackernews.com
Apple addresses a zero-day flaw (CVE-2025-24085) and fixes 9 vulnerabilities in iOS 18.3, macOS Sequoia 15.3, and more.
1
192
385
HPE investigates breach as hacker claims to steal source code - @serghei
https://t.co/ZFGQtX7JzD
https://t.co/ZFGQtX7JzD
bleepingcomputer.com
Hewlett Packard Enterprise (HPE) is investigating claims of a new breach after a threat actor said they stole documents from the company's developer environments.
2
55
124
🚨 Warning to Developers: Malicious Solana-related npm and PyPI packages are designed to steal #Solana private keys, drain wallets, and even delete your files. Learn more:
thehackernews.com
Malicious npm and PyPI packages exfiltrate Solana keys, steal Discord tokens, and wipe project files.
4
60
121
🛡️ The U.S. Treasury just sanctioned 2 individuals and 4 entities tied to North Korea’s illicit IT worker network—a major blow to funding its WMD and missile programs. 👉 Read More:
thehackernews.com
North Korean IT workers funnel millions to Kim's WMD programs via wage theft, insider threats, and extortion.
1
25
56
Microsoft starts force upgrading Windows 11 22H2, 23H3 devices - @serghei
https://t.co/N55OfJ41ae
https://t.co/N55OfJ41ae
bleepingcomputer.com
Microsoft has started the forced rollout of Windows 11 24H2 to eligible, non-managed systems running the Home and Pro editions of Windows 11 22H2 and 23H2.
7
35
83
We are looking for some interns to join our team here at Microsoft. If you are currently studying cyber security, computer science, mathematics or anything similar and based in Ireland or Cheltenham then we would love to hear from you -
2
42
59
GDPR complaints filed against TikTok, Temu for sending user data to China - @billtoulas
https://t.co/XzG5crpYja
https://t.co/XzG5crpYja
bleepingcomputer.com
Non-profit privacy advocacy group "None of Your Business" (noyb) has filed six complaints against TikTok, AliExpress, SHEIN, Temu, WeChat, and Xiaomi, for unlawfully transferring European user's data...
7
55
155
🔒 A new flaw (CVE-2024-7344) in UEFI systems has been discovered, letting attackers run unsigned code during system boot—even with Secure Boot enabled. Read more ➡️
thehackernews.com
UEFI vulnerability CVE-2024-7344 allows unsigned code execution in Secure Boot systems. Microsoft revokes binaries; vendors issue patches.
0
109
194
Hackers leak configs and VPN credentials for 15,000 FortiGate devices - @LawrenceAbrams
https://t.co/Fr3S3GMDeb
https://t.co/Fr3S3GMDeb
bleepingcomputer.com
A new hacking group has leaked the configuration files, IP addresses, and VPN credentials for over 15,000 FortiGate devices for free on the dark web, exposing a great deal of sensitive technical...
10
208
483
https://t.co/sxKsk2uIAg malware attacks add rogue admins to 5,000+ WordPress sites - @billtoulas
https://t.co/8vbDfGAGRq
https://t.co/8vbDfGAGRq
bleepingcomputer.com
A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data.
0
35
75
Today Microsoft fixed 6 kernel address leaks that I reported CVE-2025-21316 CVE-2025-21317 CVE-2025-21318 CVE-2025-21319 CVE-2025-21320 CVE-2025-21321
47
113
2K
Hackers use FastHTTP in new high-speed Microsoft 365 password attacks - @billtoulas
https://t.co/0uRSTgSavu
https://t.co/0uRSTgSavu
bleepingcomputer.com
Threat actors are utilizing the FastHTTP Go library to launch high-speed brute-force password attacks targeting Microsoft 365 accounts globally.
1
34
99
🚨 Six critical security flaws disclosed in Rsync could allow attackers to execute arbitrary code on clients. Any server with a public mirror could be exploited, putting SSH keys and other critical files at risk. Read the full advisory:
thehackernews.com
Patches for six Rsync flaws, including critical CVE-2024-12084 (CVSS 9.8), released in v3.4.0. Update now.
0
46
124
Millions of Accounts At Risk due to a deficiency in Google’s “Sign in with Google” OAuth authentication flow: https://t.co/jXTLbyUfYd
trufflesecurity.com
Millions of Americans can have their data stolen right now because of a deficiency in Google’s “Sign in with Google” authentication flow. If you’ve worked for a startup in the past - especially one...
0
2
4
🔴 Critical Alert: Microsoft has just released a massive patch for 161 vulnerabilities across its software, including 3 zero-day flaws that have been actively exploited. ⤷ CVE-2025-21333 ⤷ CVE-2025-21334 ⤷ CVE-2025-21335 Patch now:
thehackernews.com
Microsoft’s January 2025 update addresses 161 vulnerabilities, including 3 zero-days and 5 critical flaws.
4
214
442
GitHub projects targeted with malicious commits to frame researcher - @Ax_Sharma
https://t.co/AwMKeo0UI4
https://t.co/AwMKeo0UI4
bleepingcomputer.com
GitHub projects have been targeted with malicious commits and pull requests, in an attempt to inject backdoors into these projects. Most recently, the GitHub repository of Exo Labs, an AI and machine...
5
49
99
Palo Alto Networks warns of critical RCE zero-day exploited in attacks - @billtoulas
https://t.co/shAlYsdJTl
https://t.co/shAlYsdJTl
bleepingcomputer.com
Palo Alto Networks is warning that a critical zero-day vulnerability on Next-Generation Firewalls (NGFW) management interfaces, currently tracked as 'PAN-SA-2024-0015,' is actively being exploited in...
0
49
79
#WordPress Over 4mln WordPress websites were impacted by a critical 'Really Simple Security' plugin authentication bypass vulnerability CVE-2024-10924 (CVSS score 9.8) exposing websites to takeover and providing full administrative access: 👇 https://t.co/EX9Wdwveir
1
9
36