WhatsApp Lets You View Photos Without Unlocking Smartphone
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone remains locked. Before discussing the issue, it is important to understand a key […]
La cyber security come leva di competitività: da costo necessario a leva strategica
Serve un approccio che quantifichi il cyber risk: tradurre il rischio cyber in impatti finanziari potenziali, al fine di supportare decisioni più consapevoli. Ecco quando la cyber security smette di essere un costo operativo e diventa uno strumento a supporto delle scelte strategiche
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links.
A detailed timeline of 108 cyber attacks from 1-15 August 2026, with charts on motivations, attack vectors, initial access, sectors, and target countries.
US charges Russian for infecting 80,000 freelancers with malware
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.
I navigatori ottimizzano il viaggio del singolo, ma quando tutti seguono la stessa logica l’effetto si ribalta: il traffico si concentra, le emissioni aumentano e il costo dell’efficienza individuale ricade sulla città.
Infostealer contro Claude: le sessioni rubate consumano credito, Anthropic rimborsa
Un infostealer diffuso tramite software pirata ruba le sessioni attive del browser per accedere agli account Claude e consumarne il credito. Anthropic disattiva le sessioni compromesse, rimuove le carte salvate e rimborsa gli addebiti non autorizzati
Manchester Airports Group - 8,728,451 breached accounts
In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG advised that "at no point has passenger safety or aviation security been compromised".
Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.
La geopolitica della fiducia tra alleati: cosa rende obsoleto lo spionaggio nell’era AI
Dall'arresto di Biwei Zhang alle manovre di contro-intelligence al quartier generale NATO a Mons: l'infiltrazione umana ad alta tecnologia smantella la blindatura burocratica dei nulla osta. Ecco perché threat intelligence, vertici aziendali e decisori politici devono ripensare la difesa degli asset strategici e le relazioni di fiducia tra alleati
Key Takeaways The DFIR Report Offerings Check out our Products here and our Services here. Want a demo, more information on our services, pricing or just want to chat? Get in Touch Contact us today for pricing or a demo! Case Summary In March 2026, our team identified an SEO poisoning campaign leading to malware deployment […]
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys.
Claude supera i confini dei test: Anthropic rallenta e ripensa la sicurezza dell’AI
Dopo gli incidenti in cui alcuni modelli Claude hanno raggiunto sistemi reali durante test cyber, Anthropic ha sospeso parte delle valutazioni e rafforzato sandbox, monitoraggio e controlli. Il caso mostra perché la sicurezza dell'AI agentica non può dipendere da un'unica barriera
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.