http://localhost:1313/posts/__tweet/
Living Inside the Shell: zsh Modules on macOS
The .zshrc.zwc You Forgot to Check
Placeholder domain used in dev docs now serves ClickFix attacks
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
UK regulator to investigate Pornhub parent company for alleged age verification failings
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
No evidence of successful foreign meddling in 2024 election, spy agencies found
No evidence of successful foreign meddling in 2024 election, spy agencies found
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
Attacco all’FBI, ShinyHunters rivendica il colpo: cosa sappiamo davvero
ShinyHunters sostiene di essere riuscito a violare l'infrastruttura dell'FBI e di aver sottratto una grande quantità di informazioni relative ad agenti, dipendenti ed ex dipendenti, oltre a persone che avrebbero presentato domanda per lavorare nell'agenzia. Il Bureau non ha ancora confermato ufficialmente, ecco cosa risulta verificato
InfraTrust report warns network management systems under attack
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them.
Claude Opus 5.5 spinge l’AI nella cyber: più capacità, più controlli
Claude Opus 5.5 avvicina le capacità cyber dei modelli più avanzati a una platea molto più ampia e per questo Anthropic ha introdotto nuovi safeguard, routing delle richieste sensibili, sandbox e accessi verificati: per le aziende cambia il modo di governare gli agenti AI
FBI investigating alleged ShinyHunters breach of its jobs site
In corso un phishing a tema “bollo auto” ai danni di ACI
How One Kubernetes YAML Can Hand Over a GCP Organization
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation.
Norton 360 Advanced: anti-truffa Pro con IA per 10 dispositivi
Norton 360 Advanced offre il servizio anti-truffa Pro con IA per proteggere fino a 10 dispositivi: ecco come funziona e quali sono i costi.
Latvia arrests suspected hacker for electronics repair company breach
Burnham announces plan for new UK center to fight disinformation
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
Microsoft: September Windows updates break Always On VPN connections
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems.
Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies
Explore phishing risk across 5 key US industries and learn how faster detection and threat visibility help mitigate attacks.
Garante privacy, 120 giorni per contestare: resta il nodo dei tempi delle sanzioni
Il Garante privacy ha 120 giorni per notificare la contestazione, non per concludere il procedimento sanzionatorio. La Cassazione chiarisce la distinzione, ma lascia emergere un problema irrisolto: manca un termine finale certo. Una lacuna che incide sulla difesa delle imprese e che l’Autorità potrebbe colmare con il proprio regolamento
EU Turns the Tables on Big Tech Over Children’s Safety
EU KIDS Act proposes new age limits, parental controls and safety requirements for children using social media and online platforms in the EU.
Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE
CVE-2026-65660 is a SharePoint RCE flaw rated 8.8 that Microsoft first called a 6.5 spoofing bug.
Shiny Hunters Claim FBI Breach, Offer Sample of Alleged Stolen Data
The FBI is investigating after Shiny Hunters claimed it stole thousands of agents' personal data via FBIjobs.go.
Harness’ Rahul Sood: AppSec in the Agentic Era Is About More Than Code. It’s About Authority
The Cyber Express talks to Harness' Rahul Sood about AI-speed development, faster remediation, runtime visibility and limits on AI agents.
AI, il costo nascosto della produttività: quando generare costa meno che verificare
L’intelligenza artificiale sta abbattendo drasticamente il costo necessario per produrre codice, documenti, analisi e informazioni. Verificarli, però, continua a richiedere tempo, competenza e responsabilità. Il rischio è trasformare la produttività individuale in un debito di verifica collettivo