Osaka Metropolitan University cancels classes after suspected ransomware attack
L’evoluzione del ransomware: come l’AI potenzia le negoziazioni
L'uso strategico dell'intelligenza artificiale trasforma le estorsioni e le negoziazioni dei moderni gruppi ransomware.
How to secure RMM software: 8 controls MSPs should test
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation.
Arabic Streaming Websites ClickFix Campaign
بسم الله الرحمن الرحيم
The Hidden Risks of Affiliate Brand Bidding
Learn how affiliate brand bidding can become advertising abuse, affect branded search, and create unnecessary costs for brands.
ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
Today I learned: Python's .start Files as a Persistence Mechanism
Introduction Python 3.15 (the final release is currently scheduled for October 9, 2026) introduces a new interpreter-startup mechanism worth adding to the DFIR checklist: .start files.
A .start file placed in a Python site-packages directory contains one or more references in the form package.module:callable. During normal interpreter initialization, Python resolves those references, imports the corresponding modules, and invokes the callables before control reaches the first line of user-supplied Python code. The application itself does not need to import the module and does not need to know that the .start file exists. From a security perspective, that makes .start files an interesting execution primitive. An attacker who can write to an applicable site-packages directory can arrange for code to execute whenever an affected Python interpreter starts. Depending on where the file is placed, this may affect a single virtual environment, a user’s Python installations, or a system-wide interpreter.
EXCLUSIVE: Accenture contractor removed from FBI following damaging data breach, sources say
The Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a damaging data breach that exposed sensitive personal details of thousands of bureau employees, two sources familiar with the matter told Reuters.
Accenture contractor removed from FBI following damaging data breach, sources say
Shares in British clothing company ASOS dive after hackers apparently send push notification
Shares in British clothing company ASOS dive after hackers apparently send push notification
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage.
IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime
Explore how IronChain ransomware works, why its latest build matters, and how its drivers, persistence, and encryption logic increase recovery risk.
Cybertech Europe 2026: AI e resilienza ridisegnano la cyber security europea
Cybertech Europe 2026 porta a Roma il confronto su AI, resilienza, Zero Trust e infrastrutture critiche: le priorità per CISO e imprese
Torna la “truffa della ballerina”: falsi concorsi su WhatsApp per sottrarre gli account
Dipendenza cognitiva dall’AI: quando deleghiamo alla macchina anche il dubbio
Affidare all’AI sintesi e analisi complesse riduce il carico cognitivo, ma può indebolire la capacità di verificare ciò che il modello ha escluso o semplificato. Per i CISO, il rischio non è quindi delegare alla macchina, ma farlo senza preservare il dubbio, il controllo delle fonti e la responsabilità della decisione
From Detonation to Detection: The Sandbox Now Writes the Rules
Understanding what a malware sample does and being able to detect it are two different jobs, and the second one needs a skill many teams are short of. The Group-IB Malware Detonation Platform now produces indicators, Sigma rules, and hunting queries from the behavior it observes.
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails.
Super Intelligence: The Rise of Super-Intelligent Threats
A Sekoia perspective on what the White House's latest move means for cyber defense.
Servizi di ascolto e GDPR: dalla DPIA alla gestione del rischio, come costruire l’accountability
Nei servizi rivolti a persone vulnerabili, la DPIA non è un adempimento formale: serve a decidere prima cosa accadrà quando qualcosa andrà storto. Data breach, fornitori, formazione e rischio residuo diventano così elementi di un’accountability che deve proteggere non soltanto i dati, ma le persone
Engineer sentenced for locking over 3,000 devices on employer network
A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack.
8.8 Million People Affected in Major Denmark Data Breach
The Denmark data breach exposed names, addresses and CPR numbers of 8.8 million registered people through abused legitimate access.
Wikimedia Finds Unauthorized OpenAI Agent Activity Across Its Platforms
OpenAI rogue AI agents made unauthorized wiki edits, probed Etherpad and generated millions of automated requests across Wikimedia projects.
The Hidden Risks of Affiliate Brand Bidding
Learn how affiliate brand bidding can become advertising abuse, affect branded search, and create unnecessary costs for brands.
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union.
Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool
Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE).
Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement
Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement
Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data
US, Australia warn of latest Citrix vulnerability after NetScaler advisory
IQVIA fined $7.8 million for failing to properly anonymize health data
Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization.
University of Illinois Chicago affected by ransomware attack on medical school