Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions.
China-Linked Fire Ant Turned Cisco Routers, TACACS Servers Into Espionage Platforms
The China-nexus espionage group Fire Ant has moved from compromising virtualization platforms to implanting Cisco IOS XR routers and TACACS authentication servers.
Il tuo nuovo sviluppatore lavora per Pyongyang: i rischi dell’onboarding remoto
Un attaccante non deve violare la rete se può farsi assumere come sviluppatore, ricevere un laptop aziendale e ottenere credenziali valide. Le infiltrazioni di lavoratori IT nordcoreani mostrano il punto cieco dell’onboarding remoto: la cybersecurity autentica dispositivi e accessi, ma troppo spesso presume l’identità della persona
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.
RWA e tokenizzazione on-chain nel 2026: T-Bills, azioni tokenizzate e i provider da conoscere
Guida tecnica alla tokenizzazione degli RWA nel 2026: come funzionano i T-Bill on-chain e le azioni tokenizzate, i provider più rilevanti (BUIDL, BENJI, Ondo, xStocks, Dinari, Robinhood) e i vantaggi rispetto a un broker tradizionale.
I migliori wallet per criptovalute nel 2026: guida tecnica completa
Guida tecnica ai migliori wallet crypto del 2026: confronto tra Rabby, Rainbow, Phantom, Trust Wallet ed Exodus, più hardware wallet e soluzioni multisig, con link ufficiali e best practice di sicurezza.
Gli Stack perfetti per siti web e landing page nel 2026
Guida tecnica agli stack più usati per costruire landing page nel 2026: Astro, Next.js, SvelteKit, Nuxt, Eleventy e htmx, con librerie UI, CMS headless e analytics open source, tutti con link ai repository GitHub ufficiali.
Mac Mini M5 Pro: perché l'architettura a memoria unificata cambia le regole del training locale di LLM
Con M6 e M5 Pro il nuovo Mac mini porta i Neural Accelerators sulla scrivania: cosa significano davvero per il fine-tuning locale di LLM, tra benchmark ufficiali Apple e i limiti che nessuno vi dice.
Meta paga 17 miliardi e vince: la sicurezza dei minori online e il paradosso dell’age assurance
Per verificare l'età degli utenti servono informazioni sufficienti a distinguere adulti e minorenni. Il caso Meta apre così una questione destinata ad andare oltre i social: come applicare l’age assurance senza trasformarla in un'infrastruttura capace di identificare e classificare tutti
Colleferro, Bulgaria e Lipsia: cosa c’è davvero dietro gli attacchi con droni, sabotaggi e disinformazione
Una delle piste da verificare è l'ipotesi di un possibile sabotaggio di matrice russa. Ecco il fil rouge che lega una serie di eventi analoghi verificatisi nelle stesse settimane a Colleferro in Italia, in Bulgaria, a Lipsia in Germania e in Francia
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Nei servizi di ascolto e segnalazione per soggetti vulnerabili, il “pulsante di aiuto” sui siti web degli Enti del terzo settore non è una pagina di contatti. Ecco il perimetro giuridico del problema, le 4 posizioni soggettive coinvolte e il rapporto fra anonimato e possibilità concreta di prestare aiuto
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million.
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.
How AI could make it harder for governments to use hacking tools
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.