AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
We built a vulnerability vending machine: AI tokens in, zero-days out
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure.
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega
Le nuove FAQ dell’ACN ribadiscono che la nomina di un CISO non esaurisce gli obblighi previsti dalla NIS2. La cyber security entra stabilmente nella governance d’impresa: le attività operative si delegano, ma responsabilità, indirizzo e supervisione restano in capo al CdA
Tre punti non negoziabili per i CISO nell’era AI agentica
L’era agentica sta già cambiando il modo in cui avvengono gli attacchi, il comportamento dei sistemi e le responsabilità dei team di sicurezza. Ecco i tre punti per i CISO per affrontare l'AI agentica
Patch Tuesday, il record che nessuno voleva: 622 CVE e un nuovo modo di fare sicurezza
Il Patch Tuesday di luglio 2026 stabilisce il record assoluto nella storia di Microsoft: 622 CVE corrette, incluse due zero-day già sfruttate in attacchi reali su SharePoint e Active Directory. Eppure, nessuna delle due supera il CVSS 6. Un segnale inequivocabile: il punteggio non è più lo strumento giusto per decidere cosa patchare per primo
OkoBot: new sophisticated malware framework targets cryptocurrency users
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
CISA warns admins to patch actively exploited SharePoint flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances.
Come le AI agentiche impattano sulla nostra autonomia cognitiva
Le AI agentiche non si limitano a elaborare dati: possono modellare pensieri, preferenze e giudizi. Un'analisi dei rischi emergenti, delle responsabilità e delle soluzioni interdisciplinari è doverosa. E gli esperti di questo settore ci aiutano a farla
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.
In molti ambiti dell’IT capita di costruirsi piccoli tools per automatizzare alcuni task o rendere più comodo alcune operazioni e solitamente questi tools vengono utilizzati localmente sulle …
US charges alleged operators of Russian bulletproof hosting service
U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide.
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.
Explore the crucial reasons why delaying WordPress updates can lead to increased security risks for your website and how to minimize these vulnerabilities.
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates.
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical".
Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.
CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it
Spanish Police take down €140 million cyber fraud ring, arrest four
The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks.
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft…
Nearly 300 GitHub repos pose as legit software to push malware
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware.