Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs
How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?
Learn how ANY.RUN’s Threat Intelligence Feeds , Sandbox, and Threat Intelligence Lookup help MSSP scale by making threat analysts efficient.
Cloud sovrano e nazionale: la sicurezza del dato in Italia ed Europa
Il futuro del cloud sovrano sarà sempre più integrato con sistemi di AI capaci di proteggere dati, infrastrutture e servizi critici in modo adattivo e automatizzato. La combinazione tra sovranità digitale, AI for security e governance europea punta a creare ecosistemi cloud più resilienti, trasparenti e indipendenti da giurisdizioni esterne
Drupal critical update to fix bug with high exploitation risk
Drupal has announced a "core security release" scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure.
Senator presses CISA for answers about alleged GitHub repository leak
GitHub confirms being hacked by TeamPCP, says customer data unaffected
Exploit released for new PinTheft Arch Linux root escalation flaw
PinTheft, a recently patched Linux privilege escalation vulnerability, now has a publicly available proof-of-concept (PoC) exploit that allows local attackers to gain root privileges on Arch Linux systems.
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
Technical analysis of CVE-2026-40369, a 12-byte Windows kernel write reachable from browser sandboxes via NtQuerySystemInformation, leading to SYSTEM.
Da Mozilla a NordVPN: guida alle soluzioni VPN per Firefox tra cifratura del browser e suite enterprise
Guida alle VPN per Firefox: scopri le differenze e le suite all-in-one di NordVPN, Surfshark, ProtonvPN e ExpressVPN.
Il labirinto della verifica dell’età
Sempre più stati e organismi regolatori stanno imponendo restrizioni ai servizi online sulla base dell’età. L’obiettivo è proteggere i minori dai contenuti inappropriati. Ma quali sono i rischi per la privacy e la sicurezza degli utenti?
Cybersecurity360 Awards 2026: come cambia la governance tra CIO, CISO e Board nell’era dell’AI
I dati della survey e la voce dei board member: come trasformare la conformità normativa e l’AI in leve strategiche di business.
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).
Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution
ChromaDB FastAPI vulnerability CVE-2026-45829 (ChromaToast) enables pre-auth RCE via HuggingFace models; affects v1.0.0–1.5.8; high exposure risk now.
Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution
ChromaDB FastAPI vulnerability CVE-2026-45829 (ChromaToast) enables pre-auth RCE via HuggingFace models; affects v1.0.0–1.5.8; high exposure risk now.
GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
Microsoft shares mitigation for YellowKey Windows zero-day
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives.
Chanhassen Dinner Theatres Cyberattack Forces More ‘Guys and Dolls’ Cancellations
The Chanhassen Dinner Theatres cyberattack and illness outbreak forced “Guys and Dolls” cancellations and disrupted operations.
Perché anche la leadership IT espone le aziende al phishing. E non solo
Dal classico furto di dati all’uso improprio dell’IA: i dati di Arctic Wolf mostrano perché la sicurezza non è solo una questione tecnologica, ma culturale. C'è una marcata disconnessione tra percezione e realtà del rischio
Volume Obfuscation Game: The Lead Data Brokers Out To Waste Your Time
An increasing number of data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. But are they credible?
US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks
The telecom sector launches a private ISAC to strengthen cyber intelligence sharing against AI-powered cyberattacks and espionage.
UK Regulator Ofcom Cracks Down on Viral Deepfake Nude Content
Non-consensual intimate images are under scrutiny as Ofcom pushes tougher rules to curb deepfake abuse and force faster content removal online.
Dubai Police Issues Urgent Warning on Fake Travel Offers Flooding Social Media
Dubai Police noted that travel booking fraud incidents typically rise during summer vacations and festive travel periods.
GitHub investigates internal repositories breach claimed by TeamPCP
GitHub is investigating a breach of its internal repositories after the TeamPCP hacker group claimed to have accessed approximately 4,000 repositories containing private code.
Max-severity flaw in ChromaDB for AI apps allows server hijacking
A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers.
Cybercrime service disrupted for abusing Microsoft platform to sign malware
Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company's Artifact Signing service to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals.
AI Threat Report: How Artificial Intelligence Is Used Across Illicit Communities
The monthly AI Threat Report examines how threat actors are using artificial intelligence in real-world illicit environments, drawing on Flashpoint's primary source intelligence.
Discord rolls out end-to-end encryption on voice, video calls
Discord announced that all voice and video calls through the communication platform are now protected by default with end-to-end encryption (E2EE).
Posizione dei dati: la lezione dell’11 settembre e la regola 3-2-1 per un corretto backup
La tragedia dell’11 settembre 2001 ha insegnato al mondo IT una lezione fondamentale sulla posizione dei dati: la distanza geografica deve essere reale, non apparente. Ecco come implementare strategie di backup e di business continuity che proteggano realmente l'organizzazione
FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
The FBI says Americans have lost over $388 million last year to scams using cryptocurrency kiosks, also known as crypto ATMs or Bitcoin ATMs.
Microsoft Self-Service Password Reset abused in Azure data theft attacks
A threat actor targeting Microsoft 365 and Azure production environments is stealing data in attacks that abuse legitimate applications and administration features.