OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Bug bounty nell’era AI: come sta cambiando la ricerca di vulnerabilità
La diffusione di strumenti di intelligenza artificiale generativa, che provocano un aumento esponenziale di segnalazioni a basso valore aggiunto, e i modelli AI più avanzati, che stanno iniziando a individuare vulnerabilità reali, riproducibili e sfruttabili con rapidità: due tendenze in evoluzione che ridefiniscono il ruolo del bug bounty
È possibile conciliare la crescita delle infrastrutture necessarie all’intelligenza artificiale con la tutela del territorio? Tutte le contraddizioni e le sfide di uno sviluppo ancora privo di regole chiare.
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Polizia italiana con l’intelligenza artificiale: tutti i nodi giuridici
Il Senato dà il primo via libera allo schema di decreto sull’uso dell’intelligenza artificiale nelle attività di polizia, mentre il Garante Privacy chiede modifiche profonde su biometria, banche dati, riconoscimento facciale e garanzie di controllo previste dall’AI Act. Ecco i termini dello scontro, che preoccupano
French Attack Surge: Unpacking the Drivers Behind the Spike in Data Leak Claims Against French Targets
Executive Summary Between October 2025 and March 2026 (Q4 2025 – Q1 2026), the analysis of activities observed within underground forums monitored by Yarix’s Cyber Threat Intelligence Team revealed a significant increase in publications related to alleged data leaks affecting French targets, with a…
Cloud repatriation: perché sovranità dei dati e compliance stanno cambiando il cloud
Le organizzazioni stanno rivalutando dove collocare i propri workload, riportandone una parte dai public cloud iperscalabili verso infrastrutture on-premises, private cloud o data center in colocation. Ecco cos'è il fenomeno della cloud repatriation e cosa implica
XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens
Dive into a covert Linux XMRig campaign exploiting trusted access, weaponizing PAM to create forensic smokescreens, and deploying self-unlinking payloads.
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts and steal data from cloud services.
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.
Network automation: come automatizzare la configurazione e la gestione delle reti aziendali
Dagli script manuali all'orchestrazione software-defined: la guida pratica a strumenti, linguaggi e processi per ridurre errori, tempi di deployment e costi operativi della rete
Attacco ransomware, in tilt il catasto in Romania: impatto reale e contromisure
Non sono spariti i titoli di proprietà degli immobili dopo l'attacco ransomware contro il catasto in Romania. Tuttavia il cyber criminale ha bloccato l'infrastruttura per consultare l'elenco delle case e i diritti reali, da usare negli atti amministrativi. Ecco come mitigare il rischio anche nel mercato immobiliare
Hackers target over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack."
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI.
Windows 11 KB5101684 update released with 42 changes and fixes
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system.