OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN).
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges.
Council of Europe investigates ShinyHunters data breach claims
The Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend.
Contratto SLA e sicurezza: come strutturare le penali nelle forniture tecnologiche
Il contratto SLA è il presidio legale della sicurezza nelle forniture IT. Strutturare correttamente KPI, penali e clausole di sicurezza non è solo una questione tecnica: è la traduzione in diritto degli obblighi normativi imposti da NIS2, DORA e GDPR. Questa guida illustra come farlo in modo efficace
Cybersecurity vets protest ‘dangerous’ US government ban on Anthropic’s most powerful models
A group made up of dozens of cybersecurity experts urged the White House to remove export control restrictions on Anthropic’s models Fable and Mythos, arguing that the order is going to limit the ability of cybersecurity defenders to secure their software and products.
FBI: Fraudsters use couriers to steal money in crypto scams
The U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims of cryptocurrency investment scams, also known as pig butchering or romance baiting.
Pink Extortion infetta le imprese con una telefonata: come difendersi dal finto ransomware
Il malware si mimetizza da personale IT interno, per indurre le vittime a immettere le password su pagine fasulle, in modo da accedere velocemente a SharePoint, OneDrive e altri sistemi aziendali della galassia Microsoft 365. Ecco come mitigare il rischio di Pink Extortion
GreatXML e BitLocker: cosa sappiamo davvero sul presunto zero-day che aggira la cifratura di Windows
GreatXML è stato presentato come un exploit zero-day capace di aggirare BitLocker sfruttando WinRE e Microsoft Defender Offline Scan. Le verifiche indipendenti, però, raccontano una storia meno lineare. Tra dubbi sul PoC e assenza di una CVE, il caso riapre il dibattito sulla sicurezza del recovery path di Windows
Chinese hackers breach REDCap servers, steal medical research
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl
Employees are increasingly building automations, agents, and apps with AI tools outside traditional security oversight. Tines explores how CISOs are handling AI-driven code sprawl, shadow tooling, and governance challenges.
Strategia nazionale per la resilienza dei soggetti critici: la fine del confine tra minacce fisiche e digitali
Il documento è rilevante perché riconosce formalmente che quel problema è più complesso, interconnesso e urgente di quanto la postura regolatoria italiana abbia storicamente riflesso. Ecco i punti salienti, i vantaggi e criticità della Strategia nazionale per la resilienza dei soggetti critici
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March.
L’uso dell’AI Generativa come supporto alla conformità normativa
Implementare, gestire e verificare la conformità normativa, con impatti sul sistema informativo e sulla sicurezza, può essere molto oneroso. Un aiuto per lo svolgimento delle attività può derivare dall’uso degli strumenti di AI generativa che, anche nella loro versione gratuita, consentono l’esecuzione di operazioni complesse
Webinar: How behavioral AI stops phishing and account takeovers
Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and accelerate response times.
One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion
A real-world ClickFix intrusion observed from both sandbox and endpoint telemetry, revealing the complete attack path from a compromised WordPress site to a blocked GULoader execution, including a full process creation call stack from the Windows Run dialog to the kernel.
Preamble
In April 2026, we responded to an endpoint detection alert triggered by a rundll32.exe execution with anomalous arguments on a corporate workstation. The investigation traced the execution back to a compromised Euro
In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data.
In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications, advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".