JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution.
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies — like Microsoft and now Google — are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools.
Postel avvisa (con sei settimane di ritardo) che le PEC di Poste Italiane sono finite per errori ad altri
La segnalazione arriva da un nostro lettore che ha ricevuto la segnalazione direttamente da Postel. Le richieste? Non aprire le mail, cancellarle e rispondere dicendo di averlo fatto. Peccato che siano passate sei settimane
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI.
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a…
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.
Analisi dei flussi di rete: l’importanza del monitoraggio del traffico aziendale
Come la telemetria dei flussi offre visibilità completa sull'infrastruttura, aiuta a individuare colli di bottiglia e minacce, oltre a diventare la base dati per l'automazione della rete
In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
Cybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but traditional cybersecurity defense.
After the Break-In: What Attackers Do Once They're Already Inside
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware.
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Bug bounty nell’era AI: come sta cambiando la ricerca di vulnerabilità
La diffusione di strumenti di intelligenza artificiale generativa, che provocano un aumento esponenziale di segnalazioni a basso valore aggiunto, e i modelli AI più avanzati, che stanno iniziando a individuare vulnerabilità reali, riproducibili e sfruttabili con rapidità: due tendenze in evoluzione che ridefiniscono il ruolo del bug bounty
È possibile conciliare la crescita delle infrastrutture necessarie all’intelligenza artificiale con la tutela del territorio? Tutte le contraddizioni e le sfide di uno sviluppo ancora privo di regole chiare.
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Polizia italiana con l’intelligenza artificiale: tutti i nodi giuridici
Il Senato dà il primo via libera allo schema di decreto sull’uso dell’intelligenza artificiale nelle attività di polizia, mentre il Garante Privacy chiede modifiche profonde su biometria, banche dati, riconoscimento facciale e garanzie di controllo previste dall’AI Act. Ecco i termini dello scontro, che preoccupano
French Attack Surge: Unpacking the Drivers Behind the Spike in Data Leak Claims Against French Targets
Executive Summary Between October 2025 and March 2026 (Q4 2025 – Q1 2026), the analysis of activities observed within underground forums monitored by Yarix’s Cyber Threat Intelligence Team revealed a significant increase in publications related to alleged data leaks affecting French targets, with a…