Sintesi riepilogativa delle campagne malevole nella settimana del 22 – 28 agosto
From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO
Learn how cyber risk quantification helps CFOs measure financial exposure, prioritize security investments, and turn cyber threats into business insight.
I cyber criminali sfruttano Free Flow
Free Flow è un recente sistema di gestione dei pedaggi autostradali che ha portato all'abolizione dei classici caselli. Attraverso un sistema di sensori e telecamere viene registrato l'ingresso e l'uscita dei singoli veicoli dalle tratte austradali, valutata la classe del veicolo ed conseguentemente
Phishing a danno del Registro delle Imprese
D3Lab ha sempre cercato di evidenziare quanto il phishing rappresenti ancora oggi una minaccia concreta e attuale, nonostante venga talvolta percepito come un attacco banale, quasi elementare.
Le simulazioni di phishing che svolgiamo per i nostri clienti, finalizzate a valutare il livello di espo
Microsoft rolls out fix for Windows 11 crashes, gaming issues
Microsoft has started rolling out a permanent fix for a known issue that causes system crashes and gaming issues on Windows 11 devices.
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks.
Android 17 adds ECH support to make web browsing harder to track
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks.
How Threat Research and MDR Help SMBs Build a Defensive Edge
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses.
Manchester Airports Group says hackers stole travelers' data
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports.
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board.
Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search.
ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks.
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees.
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation.
68-year-old imprisoned after making $1.3 million by pirating IPTV services
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years.
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.
PaperCut releases second emergency patch for exploited flaws
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.
Exploits and vulnerabilities in Q2 2026
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
Threat landscape for industrial automation systems. Q2 2026
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
AI IR Overlay – Incident Response Specification for AI Agents
AI IR Overlay specifies containment for agents using valid credentials, with a working kill-switch contract and an admitted gap when no SOC is staffed.
AliExpress webpage keeping multipoint Bluetooth headphones active with WebAudio fingerprinting
Recently I ran into a strange problem with my Bluetooth headphones. They support multipoint Bluetooth audio, so they can be connected to my ...
I accidentally logged hundreds of thousands of phone calls to military bases
How an expired nameserver let me take over e164.arpa zones for multiple territories, and why I probably should have checked my logs sooner.
Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE.
Phishing ai danni del Ministero della Salute sfrutta un falso “rimborso ticket sanitario”
SickKids data breach exposes employee and job applicant info
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264)
Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates
Explore ransomware attack vectors hiding in endpoint blind spots, from remote access tools and credentials to vendors, OT systems and phishing.
Automazione e gestione del rischio nel SOC moderno
L'impatto dell'automazione e dell'IA sulla gestione del rischio e l'evoluzione dei ruoli operativi nel SOC moderno.