UK warns businesses to address cyber risks amid Anthropic AI panic
Attività promozionali, l’Agenzia assicurativa è titolare del trattamento: la sanzione privacy
Il Garante privacy ha sanzionato un’agenzia assicurativa che, ritenendo erroneamente di agire quale responsabile del trattamento per conto della Compagnia mandante, ha inviato e-mail promozionali in assenza di una propria informativa e autonomo consenso. Ecco gli insegnamenti da trarre
QR code scam e ingegneria sociale: come evolvono le truffe digitali
Dai falsi avvisi di violazione stradale ai QR code malevoli: l’attacco si sposta sul mobile e sfrutta fiducia, urgenza e automatismi cognitivi. Ecco l'analisi tecnica, i modelli di attacco e le strategie di difesa
CISA flags Windows Task Host vulnerability as exploited in attacks
CISA warned U.S. government agencies to secure their systems against a Windows Task Host privilege escalation vulnerability that could allow attackers to gain SYSTEM privileges.
OpenAI svela GPT-5.4-Cyber: ecco l’approccio graduale all’AI applicata alla sicurezza
Dopo l'anteprima di Anthropic Claude Mythos, arriva GPT-5.4-Cyber con cui OpenAI, usando un approccio dideployment iterativo e controllato che diventa punto di riferimento utile per l'intera industria, espande il proprio programma Trusted Access for Cyber (TAC)
LmCompatibilityLevel and the PDC Trap
LmCompatibilityLevel determines which NTLM and LM authentication protocols are accepted for inbound and outbound connections for Windows machines. On domain controllers, the minimum recommended set…
Educational company McGraw Hill says Salesforce misconfiguration led to data leak
Rolling Networks: Securing the Transportation Sector
Modern trucks are rolling networks packed with sensors, connectivity, and attack surfaces, creating new cyber risks. NMFTA's Cybersecurity Conference brings industry leaders together to tackle emerging threats in transportation.
MACOBOX is back from San Francisco
AI agents, on-premise inference, IoT scanning and PDF reports: a roundup of the latest features
How Cyble Blaze AI Delivers 360° Threat Visibility Across Dark Web and Enterprise Systems
Cyble Blaze AI unifies threat intelligence, automates response, and predicts cyber risks with AI-driven insights across enterprise and dark web data.
Sweden says pro-Russian hackers attempted to breach thermal power plant
Threat landscape for industrial automation systems in Q4 2025
The report contains industrial threat statistics for Q4 2025. It covers various infection vectors and malware types, as well as regional statistics and statistics by industry.
MiningDropper – A Global Modular Android Malware Campaign Operating at Scale
Cyble analyzes a surge in an ongoing campaign to deliver MiningDropper — a modular Android malware framework - at scale.
Microsoft: April updates trigger BitLocker key prompts on some servers
Microsoft confirmed on Tuesday that some Windows Server 2025 devices will boot into BitLocker recovery after installing the April 2026 KB5082063 Windows security update.
Chile’s Cybersecurity Framework Law: How SOCs Achieve Compliance and Response Readiness
See how ANY.RUN helps SOC teams in Chile improve threat detection, investigation, and response under the new Cybersecurity Framework Law.
Cybersecurity e ROI
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
Aggiornamenti Microsoft aprile 2026: corretta una zero-day in SharePoint già sfruttata
Il Patch Tuesday di aprile 2026 corregge 165 vulnerabilità tra cui una zero-day su SharePoint già attivamente sfruttata, l'exploit BlueHammer su Microsoft Defender rilasciato pubblicamente da un ricercatore scontento e una falla critica nel servizio IKE di Windows. Urgente l’updati dei propri sistemi
Microsoft fixes bug behind Windows Server 2025 automatic upgrades
Microsoft has finally fixed a known issue that was causing systems running Windows Server 2019 and 2022 to "unexpectedly" upgrade to Windows Server 2025.
Unpacking the Unpackable: Malformed APKs as an Anti-Analysis Technique
This article explores the most common malformation techniques in the wild and introduces Malfixer, a new open-source tool developed by Cleafy's TIR team to detect and repair malformed APKs, enabling more effective malware analysis and response.
The n8n n8mare: How threat actors are misusing AI workflow automation
Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026.
La Cina è in vantaggio sui robot umanoidi
AgiBot, Unitree, UBTech e non solo: mentre negli Stati Uniti si attende l’arrivo di Optimus di Tesla, le società cinesi di robotica sono pronte a invadere il mercato, puntando soprattutto sulle applicazioni industriali
Ivanti Neurons ITSM Vulnerabilities Could Allow Session Persistence
ITSM vulnerabilities in Ivanti Neurons (CVE-2026-4913, 4914) may allow session hijacking and persistence.
La sicurezza delle interfacce cervello-computer
Il mercato delle interfacce cervello-computer (BCI) si condensa di concorrenti e si addensa di nubi. Uscite dai laboratori, queste interfacce si stanno guadagnando un’utilità pratica che pone interrogativi tecnici, etici e normativi
OpenAI Expands Access to Advanced AI for Cybersecurity Testing
The expansion of the Trusted Access for Cyber program reflects a growing recognition that restricting access alone is not a sustainable strategy.
JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign
Unlike large ransomware groups that focus on high-value enterprise targets, JanaWare ransomware appears to follow a different strategy.
Microsoft Fixes 167 Vulnerabilities in Latest Patch Tuesday Update
Microsoft Patch Tuesday April 2026 security update fixes 167 flaws, including zero-days in SharePoint, Defender, and critical remote code risks.
Big tech fails to opt-out users requesting not to be tracked much of the time, new research says
Microsoft adds Windows protections for malicious Remote Desktop files
Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (.rdp) files, adding warnings and disabling risky shared resources by default.
Crypto-exchange Kraken extorted by hackers after insider breach
The Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data.
Patch Tuesday, April 2026 Edition
Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed "BlueHammer." Separately, Google Chrome fixed its…