77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed.
Hackers steal over $130 million by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms.
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries.
Top Hack e violazioni di dati: ecco la classifica del 2018
L'anno 2018 è ormai un lontano ricordo, eppure ha stabilito un record per quanto riguarda le attività di hacking e di violazioni di dati, le più importanti degli ultimi anni.
How legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
Retelit, operatore cloud e di telecomunicazioni, ha subito un attacco informatico. E non lo dice
Tra i suoi clienti ci sono aziende strategiche, gestori di identità digitali e pubbliche amministrazioni. Migliaia i documenti già disponibili online. Dietro l’attacco Qilin, gruppo cybercriminale attivo almeno dal 2022 che ruba password e accessi
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono
Nessun sistema è immune dai guasti. Il principio del fail secure insegna a progettare applicazioni e infrastrutture che, in caso di errore, proteggano dati e asset critici senza amplificare il rischio. Un approccio che cambia il modo di concepire sicurezza, resilienza e continuità operativa
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI.
NIS2, asset e servizi IT: come costruire un inventario realmente utile alla gestione del rischio
L’inventario degli asset non dovrebbe essere una semplice lista tecnica di server, applicazioni, dispositivi e servizi cloud. In ottica NIS2, deve diventare una mappa ragionata di ciò che sostiene le attività dell’organizzazione, evidenziando criticità, dipendenze, owner, fornitori e impatti sul business
Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers
Explore the major cyber attacks of July 2026, the risks they created across the US and Europe, and the steps security leaders can take to reduce exposure.
Categorizzazione NIS 2: da adempimento a strumento di governo della sicurezza
La categorizzazione NIS2, che non è finita il 30 giugno, entra in una nuova fase: infatti apre il percorso, ma non lo conclude. Ecco perché il valore del lavoro svolto non dipenderà dalla qualità formale di ciò che è stato trasmesso, bensì dall’uso che ogni organizzazione deciderà di farne
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize in computer hacking laws to find out.