New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Il problema non è soltanto l’agente AI che ha superato una sandbox. Il vero punto è che una valutazione delle capacità cyber ha prodotto effetti su un’infrastruttura reale di un soggetto terzo. Per i modelli più avanzati non bastano benchmark e guardrail: servono regole d’ingaggio, responsabilità e gli stessi controlli di un’operazione offensiva
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
During ongoing monitoring of malicious infrastructure, Group-IB identified an exposed staging server that uncovered an active China-nexus operation. Subsequent investigation confirmed intrusion attempts across government, healthcare, and education sectors in Vietnam, Malaysia, and Hong Kong to parallel phishing campaigns in LATAM, all connected through a shared loader tracked as TriBack Loader.
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
85 confirmed cyber attacks, July 1-15 2026: cyber crime drove 76% of incidents, malware led at 43%, and IT & communications was the hardest-hit sector.
85 confirmed incidents, July 1-15 2026: Cyber Crime drove 76.5% of attacks, Malware led techniques at 43.5%, and Info & Communication was the top-hit sector.
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats.
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers.
How enterprise GenAI can amplify ransomware risk — and how to contain it
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption.
Wp2shell, le vulnerabilità in WordPress: le patch sono urgenti, ma non bastano
Nel caso dell'attacco Wp2shell, le vulnerabilità si correggono con una patch. L’assenza di governance, invece, continua a produrre vittime: ecco perché non è sufficiente sanare le falle
New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.