Found 34370 bookmarks
Newest
Don’t swing at everything
Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
·blog.talosintelligence.com·
Don’t swing at everything
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
·bleepingcomputer.com·
Russian hackers exploit Zimbra zero-click flaw for email theft
Hackers abuse Notepad++ plugins to stealthily install malware
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
·bleepingcomputer.com·
Hackers abuse Notepad++ plugins to stealthily install malware
Gemini Flash Cyber e la corsa ai modelli AI per la cyber security
Gemini Flash Cyber e la corsa ai modelli AI per la cyber security
L’AI non è più solo assistente per analisti, ma diventa componente specializzato di agenti capaci di cercare vulnerabilità, validarle e contribuire alla generazione di patch. Ecco cosa significa il lancio di Gemini 3.5 Flash Cyber e perché arriva con un programma pilota con accesso limitato a governi e partner scelti
·cybersecurity360.it·
Gemini Flash Cyber e la corsa ai modelli AI per la cyber security
Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center.
·bleepingcomputer.com·
Microsoft 365 outage affects Teams, SharePoint and other services
Ransomware in 2026: Same Business, New Rules
Ransomware in 2026: Same Business, New Rules
The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence.
·group-ib.com·
Ransomware in 2026: Same Business, New Rules
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance.
·bleepingcomputer.com·
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
EU fines Google $1 billion for search, app store antitrust violations
EU fines Google $1 billion for search, app store antitrust violations
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition.
·bleepingcomputer.com·
EU fines Google $1 billion for search, app store antitrust violations
New RefluXFS Linux flaw lets attackers gain root privileges
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
·bleepingcomputer.com·
New RefluXFS Linux flaw lets attackers gain root privileges
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
Le sanzioni del Garante privacy a due operatori del settore energetico ridefiniscono le regole del credit scoring automatizzato. Trasparenza, qualità dei dati, governance degli algoritmi e tutela dei diritti diventano i pilastri di un modello destinato a estendersi ben oltre il mercato dell'energia
·cybersecurity360.it·
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
Explore 10 best threat intelligence feeds for SOCs and MSSPs in 2026, including their data sources, integrations, threat context, and common security use cases.
·any.run·
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
Preview: Cisco Talos at Black Hat USA 2026
Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
·blog.talosintelligence.com·
Preview: Cisco Talos at Black Hat USA 2026
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
·blog.talosintelligence.com·
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
·bleepingcomputer.com·
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Il problema non è soltanto l’agente AI che ha superato una sandbox. Il vero punto è che una valutazione delle capacità cyber ha prodotto effetti su un’infrastruttura reale di un soggetto terzo. Per i modelli più avanzati non bastano benchmark e guardrail: servono regole d’ingaggio, responsabilità e gli stessi controlli di un’operazione offensiva
·cybersecurity360.it·
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
During ongoing monitoring of malicious infrastructure, Group-IB identified an exposed staging server that uncovered an active China-nexus operation. Subsequent investigation confirmed intrusion attempts across government, healthcare, and education sectors in Vietnam, Malaysia, and Hong Kong to parallel phishing campaigns in LATAM, all connected through a shared loader tracked as TriBack Loader.
·group-ib.com·
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
·bleepingcomputer.com·
Check Point warns of SmartConsole zero-day exploited in attacks