Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
Gemini Flash Cyber e la corsa ai modelli AI per la cyber security
L’AI non è più solo assistente per analisti, ma diventa componente specializzato di agenti capaci di cercare vulnerabilità, validarle e contribuire alla generazione di patch. Ecco cosa significa il lancio di Gemini 3.5 Flash Cyber e perché arriva con un programma pilota con accesso limitato a governi e partner scelti
Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center.
Regolamento DORA: come gestire il rischio ICT delle terze parti nel settore finanziario
Registro delle informazioni, due diligence, clausole contrattuali e governance: una guida operativa alla compliance DORA sui fornitori di terze parti per una corretta gestione del rischio ICT
Nuovo monito di Bankitalia: attenti ai rischi dell’AI per il sistema finanziario, ecco cosa fare
Si riduce l’intervallo fra scoperta delle vulnerabilità ed attacco e le banche devono fare presto. L'avvertimento di Bankitalia ai soggetti vigilati sui rischi AI legati sistema finanziario prevede la richiesta di preparare un piano, ecco quale
The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence.
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance.
EU fines Google $1 billion for search, app store antitrust violations
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition.
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
Le sanzioni del Garante privacy a due operatori del settore energetico ridefiniscono le regole del credit scoring automatizzato. Trasparenza, qualità dei dati, governance degli algoritmi e tutela dei diritti diventano i pilastri di un modello destinato a estendersi ben oltre il mercato dell'energia
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
Explore 10 best threat intelligence feeds for SOCs and MSSPs in 2026, including their data sources, integrations, threat context, and common security use cases.
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Il problema non è soltanto l’agente AI che ha superato una sandbox. Il vero punto è che una valutazione delle capacità cyber ha prodotto effetti su un’infrastruttura reale di un soggetto terzo. Per i modelli più avanzati non bastano benchmark e guardrail: servono regole d’ingaggio, responsabilità e gli stessi controlli di un’operazione offensiva
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
During ongoing monitoring of malicious infrastructure, Group-IB identified an exposed staging server that uncovered an active China-nexus operation. Subsequent investigation confirmed intrusion attempts across government, healthcare, and education sectors in Vietnam, Malaysia, and Hong Kong to parallel phishing campaigns in LATAM, all connected through a shared loader tracked as TriBack Loader.
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.