Sintesi riepilogativa delle campagne malevole nella settimana del 11 – 17 luglio
Ernst & Young discloses data breach after support system hack
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
Recupero crediti, Garante Privacy: ecco chi paga il conto della mancata vigilanza
Due provvedimenti "gemelli" del Garante privacy ridisegnano i confini della responsabilità condivisa nella filiera del recupero crediti: non basta nominare un responsabile del trattamento, occorre vigilare sul suo operato e informare il titolare del trattamento. In ambito recupero crediti, ecco il principio che ispira i provvedimenti dell'Autorità
Inside Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer
We analyze Qilin ransomware’s new custom Rust loader, its kernel-level EDR killer, and how organizations can defend against them.
Inside the Search for "Clean" Residential Proxies for Carding
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.
Meglio prima che mai!
Quando la sicurezza cyber non è collocata come priorità su una linea temporale di intervento, è inevitabile che prima o poi la gestione stessa di questo aspetto inizierà a risentirne, sia per accumulo del debito tecnologico sia per aumento dell'incertezza ed aumento della probabilità di subire attacchi
CyberCUBE: la cyber security spaziale passa dalla compliance ai test in orbita
Il 7 luglio un satellite CubeSat è entrato in orbita per farsi “attaccare”. Non è una stranezza: è la risposta dell'ESA a un problema che, chi lavora nella governance del rischio cyber, conosce fin troppo bene: la distanza tra le contromisure scritte nei documenti e la prova che funzionino davvero
Dairy company Fairlife suspends production in US after cyber incident
Navigate360 and P3 Global Intel: From the promise of “20+ years and zero violations” to three months of silence
Zelensky appoints Ukraine's acting security service chief as acting defense minister
ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns
ClickFix attacks are increasingly being used by the UAC-0145 threat group to deliver malware, backdoors, and data-stealing tools.
The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks
The Cyber Express weekly roundup covers TikTok age checks, Partnered Health breach, Qantas review, Microsoft flaws, and major cyberattacks.
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
US Charges Two Over $43M Chinese Money Laundering Operation
Zhuoying Chen and another New York resident face charges over an alleged $43 million Chinese money laundering case.
Can a SIM card run malware?
Exploring SMS-triggered SIM Toolkit applets in a private GSM lab
Windows Server 2022 reach end of mainstream support in 90 days
Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years.
Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available
Notepad++ vulnerabilities fixed in v8.9.7 include PowerShell command injection and CVE-2026-52886, CVE-2026-54758.
Sanzione privacy a Wind Tre: il Garante porta la cyber al centro della compliance GDPR
La sanzione del Garante privacy a Wind Tre per due data breach mostra come la compliance all’articolo 32 del GDPR venga ormai valutata anche attraverso la qualità delle misure di cyber security. Dalla gestione delle credenziali alle API, la resilienza dei sistemi diventa il vero parametro di conformità
Una società di cyber security europea ha nascosto per anni i suoi collegamenti con la Russia
La società spagnola Passwork per anni ha tenuto i clienti all’oscuro di quanto il suo software fosse esposto alle analisi dei servizi segreti russi. Per farlo, ha perfino cercato di manipolare le informazioni elaborate dall’intelligenza artificiale
Passwork
4 offerte antivirus da non perdere a luglio 2026
Le offerte per i migliori antivirus propongono servizi utili a proteggere i propri dispositivi: ecco le promo imperdibili a luglio 2026.
US charges two over laundering $43 million from investment fraud
U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams.
Smart grid e GDPR: quando l’energia diventa dato personale
La smart grid è quel salto tecnologico che rende possibile la transizione energetica, ma non è soltanto un’infrastruttura tecnologica, bensì un ecosistema informativo dove si intrecciano responsabilità, obblighi e relazioni tra i soggetti coinvolti. Ecco cosa succede quando la disciplina del GDPR incontra quella sulla sicurezza delle reti
CISA urges immediate action on actively exploited Fortinet flaws
CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform.
Zoom Patches Critical Windows Flaw Enabling Account Takeover
Zoom patches CVE-2026-53412, a critical Improper Input Validation flaw in Zoom Desktop Client that could enable Windows account takeover.
TikTok Age Verification Under Investigation as UK Tightens Child Safety Rules
TikTok age verification is under investigation by Ofcom over concerns it may be failing to protect children under the UK's Online Safety Act.
New ClickLock macOS malware traps users into revealing login password
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation
Coca-Cola says Fairlife ransomware attack halts US dairy production
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
New OkoBot framework deploys 20 payloads to steal data, crypto
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.