MetaEncryptor Claims Attack on EllisDon: “409 GB of Data Stolen, We Are Still Accessing the Systems”
Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality.
Surfshark VPN says hackers breached internal testing, proxy servers
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Multiple crypto companies warn customers of phishing emails after alleged provider breach
AI Agents Compromised 440 PaperCut Servers, Researchers Say
GreyNoise says AI agents compromised 440 PaperCut servers in 48 countries. The vulnerabilities are confirmed — the AI orchestration claim is not yet corroborated.
Cyber Command turns to veteran of intelligence agencies for top AI role
We've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
BforeAI Partners with Food and Ag-ISAC to Advance Predictive Attack Intelligence
BforeAI has partnered with the Food and Ag-ISAC to bring predictive, preemptive attack intelligence to targeted supply chains.
Incidenti AI e alignment: la lezione di Anthropic per la cyber sicurezza
Addestrare i modelli estremamente potenti del futuro affinché siano saldamente allineati è una sfida tecnica irrisolta che richiede una ricerca continua e un’eccellenza operativa per essere affrontata
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.
BforeAI Partners with Food and Ag-ISAC to Advance Predictive Attack Intelligence
BforeAI has partnered with the Food and Ag-ISAC to bring predictive, preemptive attack intelligence to targeted supply chains.
Agenti AI fuori dal perimetro: il caso OpenAI riapre il confine tra misalignment e incidente cyber
Agenti AI che usano un wiki pubblico come memoria esterna, condividono istruzioni e si adattano quando l’attività viene ostacolata. Il caso ricostruito da Reuters porta OpenAI a riconoscere una zona grigia tra misalignment e incidente cyber e riapre una questione decisiva: quando un comportamento anomalo deve diventare pubblico?
IDScan confirms breach tied to 153 million stolen driver’s licenses
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans.
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked.
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
Interfacce HMI e continuità di processo: mitigare i rischi sui terminali di linea
Gli HMI collegano operatori e processi industriali, ma possono anche diventare punti critici. Accessi, sistemi embedded, connessioni remote e backup devono essere protetti per evitare che un terminale compromesso si trasformi in fermo produzione
UK appoints new commander of National Cyber Force
Cyble Introduces Major Upgrade to its Executive Monitoring Module
Cyble has rolled out a significant upgrade to Executive Monitoring inside Cyble Vision, bringing unified findings, AI-driven scoring, and expanded alerting
From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline
How infostealer malware fuels the credential theft pipeline — from harvesting and stealer logs to enrichment and dark web marketplace listings.
Microsoft says September updates fix mouse settings reset issues
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update.
EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act
The EU Cyber Resilience Act's 24-hour vulnerability reporting duty starts Sept. 11, 2026. Deadlines, scope, ENISA's platform and €15M penalties explained.
it-sa Expo&Congress 2026: a Norimberga la cyber security europea guarda alle nuove sfide
Dal 27 al 29 ottobre, it-sa Expo&Congress 2026 riunisce a Norimberga la community europea della cyber security per confrontarsi su AI, resilienza, sovranità digitale e nuove minacce. Per i nostri lettori è disponibile un biglietto gratuito valido per i tre giorni della manifestazione
Cyberoo: “L’MDR non basta. Ecco come cambia la cyber security”
Di fronte a uno scenario sempre più complesso, limitare l’intervento a logiche legate a scelte tecnologiche non è sufficiente. Serve un ecosistema completo che permetta il salto di qualità
ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings
Discover why ANY.RUN is a G2 Malware Analysis Leader and how it helps SOC teams deliver measurable value to their enterprises.
Inside an Indonesian phishing kit factory
This article was written by an AI agent working under human supervision; the human it works for verified and approved it before publication. An open directory on a freshly-registered Indonesian dom…
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.
Surfshark: pacchetto VPN e Antivirus da 2,49 €/mese, come cambia la protezione degli endpoint illimitati
Surfshark al prezzo di 2,49 euro al mese offre una VPN con antivirus integrato su dispositivi illimitati: ecco come attivarla e come funziona