Why AI SOC Agents Need Context to Investigate Alerts
AI SOC agents need more than an alert to investigate threats. See how telemetry, asset data, identities and threat intelligence help explain each verdict.
One SOC can protect dozens of customers, but every customer works differently. See how multi-level agents give security teams one shared way to investigate alerts, while keeping the local context needed to make the right call.
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
This article details how TDR pivoted from a forum advertisement to identify confirmed operator infrastructure, analyzes the Exvicy infection chain, and provides code evidence establishing that this emerging MaaS is a direct copycat of the adopted ErrTraffic framework.
Allarme russo in Europa, il caso Kaspersky-SIC riapre il nodo della fiducia nell’intelligence
Gli attuali allarmi europei sulla minaccia ibrida russa e il caso Kaspersky-SIC non hanno un collegamento dimostrato. Ma letti insieme pongono una questione più ampia: quanto sono state esposte le catene tecnologiche e informative dell’intelligence occidentale e quali garanzie esistono oggi sulla loro integrità?
Ryuk ransomware member sentenced to 24 months in prison
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.
Attacchi cyber iraniani contro navi Usa: il conflitto può estendersi al dominio marittimo
Le autorità statunitensi non hanno confermato se dietro gli attacchi vi sia l'Iran oppure altri attori statali, tra cui vengono citati come possibili Russia e Cina. Ma gli attacchi informatici alle navi Usa, mentre transitavano nello Stretto di Gibilterra nel mese di agosto, comportano un rischio tecnico legato a questi attacchi non trascurabile
RemControl: AI Built the Overlays. Victims Lose their PINs
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
Il dato tra GDPR e AI Act: filiera, lineage e accountability
Dalla raccolta al modello, i dati attraversano fonti, sistemi, trasformazioni e riusi. GDPR e AI Act richiedono una governance capace non solo di mappare i trattamenti, ma di ricostruire e dimostrare la storia del dato
L’azienda italiana di cyber armi che ha conquistato l’elite dell’intelligence israeliana
Fondata in Veneto da un giovane hacker, Dataflow sviluppa codici per entrare in pc e smartphone. Da gennaio le sue attività in Israele sono guidate da Eyal Tsir Cohen, ex alto dirigente del Mossad e nel 2025 candidato alla guida dello Shin Bet
Rogue external MFA providers can steal passwords during logins
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts.
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.
Chinese hackers exploit multiple technologies to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases.
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
Flashpoint analysts examine Process Parameter Poisoning—a novel EDR evasion technique we validated in Rust—and detail how abusing undocumented process parameters allows attackers to inject code and bypass standard security products.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps.
Check Point warns of Management Server zero-day exploited in attacks
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset
La gestione del rischio non può prescindere da una visibilità completa dei sistemi IT/OT. Il progetto sviluppato da Lutech per un'importante azienda manifatturiera mostra come monitoraggio passivo, Cyber Asset Management e Continuous Threat Exposure Management trasformano l'inventario degli asset in strumento strategico di cyber resilience
Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio
Un solo errore dell’algoritmo può bastare per spingere gli analisti a ricontrollare ogni decisione automatica. Ma la sfiducia ha un costo: rallenta l’incident response e può offrire agli attaccanti tempo prezioso. Per i CISO, progettare l’automazione significa quindi progettare anche la fiducia di chi dovrà utilizzarla
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California
Con ponderazione ma con urgenza, il 18 settembre 2026 il governatore della California Gavin Newsom ha firmato l’ordine esecutivo N-9-26 dedicato ai modelli di frontiera. Ecco cosa comporta in termini di supervisione indipendente e sicurezza dei sistemi di intelligenza artificiale e le differenze con la SB 1047 respinta nel 2024
PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco
Niente malware sui PC, nessun file cifrato e nessun processo sospetto da intercettare. In un incidente analizzato da Kaspersky, gli attaccanti hanno utilizzato le Group Policy di Active Directory per colpire contemporaneamente l’intero dominio, trasformando uno degli strumenti più fidati dell’amministrazione Windows in un meccanismo di estorsione