B{r}owser's Castle
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group.
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server.
Justices rule that cellphone location histories are protected by the Fourth Amendment
WhatsApp rolls out usernames to help users hide their phone number
WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list.
US racks up about 400 wins over illegal World Cup streaming sites
Microsoft extends Windows Server 2022 hotpatching until October 2027
Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026.
In major privacy win, Supreme Court rules geofence warrants are protected by privacy rights
The Supreme Court's decision to limit geofence warrants is a win for privacy advocates, who called their use unconstitutional but sought an outright ban.
Kali Linux 2026.2 Release (GNOME 50, KDE 6.6, Helper Scripts, APT Formats & VM Boot Tweaking)
It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we think you will appreciate.
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
Come calcolare il ROSI: metriche e modelli finanziari per convalidare la spesa in sicurezza
Metodologie di calcolo del ROSI, metriche finanziarie e tecniche per misurare l'efficacia degli investimenti in sicurezza e comunicarne il valore al board aziendale
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
The U.S. Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services.
Unmasking the Digital Trail: Essential Techniques for Vetting AI-Generated Content
We outline the practical, human-driven techniques threat intelligence teams must deploy to detect synthetic media, protect corporate RAG ecosystems, and filter through the noise of AI-polluted networks.
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux.
Agentic AI Has an Identity Problem and Attackers Know It
AI agents can access data, trigger workflows, and take action across enterprise systems. Token Security explains why governing these privileged identities is becoming essential for enterprise security.
Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in May of 2025 Cyjax reported on a campaign using this method again, impersonating various IT tools. We observed a similar campaign in […]
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs […]
ChatGPT Enterprise e IA generativa in azienda: gli obblighi tra normative, proprietà intellettuale e cyber
Il recente intervento del Garante Privacy nei confronti della start-upMyndoor dimostra che l'introduzione di ChatGPT Enterprise in azienda è ormai un tema giuridico e organizzativo, e non più solo tecnologico. Ecco le misure di governance necessarie per coniugare innovazione, tutela dei lavoratori, protezione dei dati e cyber
Ukraine to use seized crypto from cybercrime group to buy war bonds
Hackers now exploit critical Oracle E-Business flaw in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused.
Webinar: Why business email compromise attacks keep succeeding
Business email compromise attacks increasingly rely on convincing impersonation rather than malware, making them harder for employees and traditional email defenses to detect. This webinar explores how behavioral AI can help identify sophisticated email threats and automate response workflows.
GPT-5.6 Sol, la nuova frontiera dell’AI per la cyber: ecco cosa cambia per i defender
OpenAI ha annunciato la preview di GPT-5.6 Sol, il suo modello AI più avanzato per la cyber security. Capacità di vulnerability research superiori, safety stack inedito e rilascio controllato con supervisione governativa USA. Un’analisi per chi deve decidere se e come adottarlo
US seizes hundreds of FIFA World Cup illegal streaming domains
The U.S. Justice Department's Criminal Division has seized nearly 400 web domains used for illegally streaming matches at the FIFA World Cup.
The Gentlemen are knocking: сustom backdoors and evolving tactics
Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.
Sanzione all’AUSL di Modena per misure di sicurezza inadeguate: la lezione per tutti
L’Autorità Garante per la protezione dei dati ha multato un'azienda sanitaria per diecimila euro per la mancata adozione di misure di sicurezza adeguate dei sistemi, violati a seguito di un cyber attacco
Piani NordVPN: fino al 75% di sconto sui nuovi abbonamenti con 3 mesi extra
I nuovi piani NordVPN garantiscono la massima sicurezza per la tua rete virtuale privata: scopriamo "Base", "Completo" e "Ultimate Max".
Il collettivo GreyVibe e l’impiego di AI generative contro l’Ucraina
Il gruppo di criminal hacker GreyVibe sta sfruttando strumenti di AI generativa per rendere le rispettive iniziative più difficili da interpretare. Dallo scorso mese di agosto l’obiettivo è colpire obiettivi sensibili in Ucraina
Operation Endgame Disrupts SocGholish, StealC Malware Networks
Operation Endgame has disrupted the SocGholish, Amadey, and StealC malware infrastructure, seizing EUR 41 million in crypto assets.
Il grafo della supply chain come strumento di conformità NIS: i 3 vantaggi operativi
Con la Determinazione 127437 del 13 aprile 2026, ACN ha ridefinito il perimetro di sicurezza dei soggetti essenziali e importanti. Ecco perché è necessario adottare un modello rappresentativo a grafo della supply chain, affinché l'adempimento sia sostanzialmente conforme e non meramente formale
UAE Cybersecurity Council Calls for Stronger Digital Footprint Protection
UAE Cybersecurity Council urges users to protect digital footprints by following cybersecurity best practices against growing cyber threats.