Romanian gets 5 years in prison for hacking Oregon govt network
A Romanian national was sentenced this week to 56 months in federal prison for breaking into an Oregon state government computer network and fr cyberattacks targeting dozens of other U.S. victims.
Webinar: Why network incidents take too long to resolve
Many organizations can detect network issues quickly, but investigations and coordination often slow incident resolution. This webinar explores how automation and AI-assisted workflows can help IT teams reduce delays and improve response times.
Carnival Cruise confirms data breach affecting nearly 6 million people
Carnival Corporation, the world's largest cruise line operator, has confirmed a data breach affecting nearly 6 million people claimed by the ShinyHunters extortion gang in April 2026.
B1ack’s Stash Releases 4.6 Million Payment Cards: Web Skimming Leak Analysis
B1ack's Stash published a new free leak containing 4.6 million payment card records. Our analysis reviews the dataset structure, validation results, affected countries, payment networks,
Italy-specific findings, and the broader phishing and social engineering risks created by exposed personal data
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap
This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format.
Sextortionist sentenced to 33 years for targeting 145 children
A Canadian man was sentenced to 33 years in prison after pleading guilty to targeting more than 145 children across the United States, some as young as 6 years old, in an eight-year-long sextortion scheme.
NIS2 e Cyber Resilience Act: sinergie nelle azioni di adeguamento in ottica multicompliance
Due atti normativi sono destinati a incidere profondamente sulla postura di sicurezza delle organizzazioni: la Direttiva NIS2 e il Cyber Resilience Act. Ecco una lettura combinata delle due norme, evidenziando le sovrapposizioni operative che rendono inefficiente e lacunosa una gestione compartimentale della compliance cyber
Oltre la compliance: come l’AI Act trasforma la fiducia in vantaggio competitivo
L’AI Act non rappresenta un ostacolo, bensì un modello per realizzare un vantaggio competitivo duraturo. Ecco perché il futuro dell’intelligenza artificiale non apparterrà solo alle aziende che si muovono più rapidamente, ma a quelle che sapranno conquistare la fiducia del mercato, trasformandola in vantaggio competitivo
Large Language Models are rapidly becoming load-bearing components of modern applications. This article takes you behind the scenes of how Yarix structures an LLM Security Assessment, from threat modeling to hands-on adversarial testing, combining international standards with the kind of methodical analysis that surfaces…
In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.
SEO poisoning e chatbot AI dirottati per un malware miner
Le campagne di SEO poisoning non sono certo una novità nel panorama cybercriminale. Da decenni gli attaccanti manipolano i motori di ricerca per spingere siti malevoli tra i primi risultati, inducendo gli utenti a scaricare malware credendo di visitare pagine legittime. Ma una nuova campagna analizzata da Microsoft Security Blog mostra un’evoluzione particolarmente interessante del …
CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks
Cybercriminals used the Glassworm botnet to infect open source software projects with malware, and in turn hack the developers and companies that use that software.