'Wrench' attacks against crypto holders appear to be on the rise
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services.
Acn: nel primo semestre 2026 resta elevata la pressione da parte delle minacce cyber
Secondo l'operational summary dell'Acn, nel primo semestre 2026 si sta consolidando il sistema nazionale di cyber security, mentre l'entrata a regime degli obblighi di notifica previsti dalla direttiva NIS2 rafforza la resilienza del Paese. Ecco cosa emerge nei dettagli e cosa brilla per la sua assenza
Sintesi riepilogativa delle campagne malevole nella settimana del 18 – 24 luglio
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline.
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19.
AIncident Responsible
Il recente caso exploitgym, con i server di Huggingface compromessi dall'azione degli agenti di OpenAI offre non pochi spunti per ragionare circa il gap cognitivo fra rischio incalcolabile e non calcolato nella gestione della sicurezza cyber
Backup su larga scala: dagli indicatori di stato “verde” alla reale capacità di ripristino
In caso di incidenti, dovuti ad attacchi ransomware, interruzioni di servizio o cancellazioni accidentali, ciò che conta è se esistono punti di ripristino, quanto questi siano recenti e se i backup siano rapidamente e ripetutamente eseguibili, anche in situazioni di stress. Ecco come effettuare il backup su larga scala
The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats
The latest TCE weekly roundup covers ransomware attacks, data breaches, online scams, piracy takedowns, and global threats impacting organizations.
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups.
Man gets six years for hacking 750 women's Snapchat accounts
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos.
Malware nella supply chain software: gli sviluppatori sono il punto più vulnerabile
Il nuovo malware individuato da Doctor Web non si limita a sottrarre credenziali o installare backdoor: compromette i progetti C++ e C# trasformando gli ambienti di sviluppo in vettori di attacco. Un’evoluzione che conferma come la supply chain software sia ormai uno dei principali fronti della minaccia cyber
Ionos, l’offerta per l’hosting europeo: un anno gratis con dominio incluso e 200 GB di spazio
Per chi cerca un servizio di hosting europeo, Ionos ha l'offerta perfetta: dominio e 200 GB di spazio sono gratuiti, ecco gli altri servizi.
CRA e Direttiva UE sui prodotti difettosi: come cambia la responsabilità cyber delle imprese
Il Cyber Resilience Act definisce i requisiti di sicurezza dei prodotti digitali, ma la nuova Direttiva UE 2024/2853 sulla responsabilità per danno da prodotti difettosi aggiunge un tassello decisivo: la cyber security esce dall'ambito della compliance e diventa un fattore di responsabilità civile e di rischio d'impresa
NordVPN, sconto VPN del 75% con 3 mesi extra: quanto costa e cosa include l’offerta
NordVPN: propone uno sconto sulla VPN del 75% e aggiunge anche tre mesi extra: ecco le tariffe per navigare su una rete privata virtuale.
European Commission Fines Google €890 Million for DMA Breaches
Google fined €890 million by the European Commission for breaching the Digital Markets Act over self-preferencing and anti-steering practices.
2.2 Million Vehicles Exposed to KARR Bluetooth Security Flaw
Update your KARR Security System using an iPhone or Android app to fix a Bluetooth flaw affecting over 2.2 million dealer-installed alarms.
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Smart grid e transizione energetica: perché la governance dei dati è un vantaggio competitivo
La trasparenza nella gestione dei dati non costituisce un vincolo, ma si traduce in un elemento di differenziazione competitiva presso consumatori sempre più consapevoli dei propri diritti. Ecco come principi, progettazione e vantaggio competitivo agevolano la fiducia dei consumatori
Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack
Bitkub cyberattack case draws Thailand SEC complaint over 2021 disclosures as the exchange says customer assets remained safe and intact.
Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit
Zimbra phishing campaign linked to Russian state-supported actors exploits CVE-2025-66376 to steal emails, credentials and sensitive data.
One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States
1,721 ransomware attacks hit the United States between January and June, according to new research from Cyble Research and Intelligence Labs (CRIL)
How AI guardrails are impeding the work of offensive cybersecurity researchers
We spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work.
New Dolphin X malware uses AI to rank high-value targets
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.
Australian energy provider Origin says data breach exposes client data
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others.
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.
Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
International alert spotlights Russia-linked attacks on Zimbra webmail
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
State Department imposes visa restrictions on foreign cyber scammers