FCC votes to toughen rules in bid to better protect undersea cables
Attacco hacker Trenitalia: ecco tutto quel che sappiamo
Trenitalia ha comunicato ai clienti coinvolti un accesso non autorizzato a dati personali legati ai titoli di viaggio. Esclusi credenziali e pagamenti, resta il rischio di email, sms e chiamate fraudolente costruite su tratte reali
Falsa skill elude gli scanner e a raggiunge più di 26.000 agenti AI
La rapida diffusione degli Agenti AI sta creando un ecosistema sempre più complesso nel quale modelli linguistici, strumenti esterni e componenti aggiuntivi collaborano per svolgere attività operative. Questa architettura modulare, però, sta aprendo una nuova superficie di attacco che ricorda da vicino le vulnerabilità già viste nel mondo open source e nei marketplace di applicazioni. …
Italia nel mirino del gruppo TX-NFC: la nuova tecnica di attacco punta alle carte di credito
Dopo aver operato per mesi in Cina e in Asia, il gruppo di cyber criminali ha allargato il suo raggio d’azione. La tecnica prende di mira Android e permette la clonazione delle carte di credito tramite NFC.
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
The Cyber Express weekly roundup covers the Five Eyes AI warning, TfL cyberattack, KDDI breach, Garfield AI milestone, and FBI cybercrime case.
NIS2, dalla scadenza del 30 giugno al governo della sicurezza: la guida operativa
Ecco come usare la prossima scadenza NIS2 del 30 giugno 2026, entro cui le aziende in perimetro devono completare la categorizzazione delle attività e dei servizi, per costruire un modello proporzionato di rischio, resilienza e investimento cyber
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
The Cyber Express weekly roundup covers the Five Eyes AI warning, TfL cyberattack, KDDI breach, Garfield AI milestone, and FBI cybercrime case.
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
The Cyber Express weekly roundup covers the Five Eyes AI warning, TfL cyberattack, KDDI breach, Garfield AI milestone, and FBI cybercrime case.
NIS2, dalla scadenza del 30 giugno al governo della sicurezza: la guida operativa
Ecco come usare la prossima scadenza NIS2 del 30 giugno 2026, entro cui le aziende in perimetro devono completare la categorizzazione delle attività e dei servizi, per costruire un modello proporzionato di rischio, resilienza e investimento cyber
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
The Cyber Express weekly roundup covers the Five Eyes AI warning, TfL cyberattack, KDDI breach, Garfield AI milestone, and FBI cybercrime case.
NIS2, dalla scadenza del 30 giugno al governo della sicurezza: la guida operativa
Ecco come usare la prossima scadenza NIS2 del 30 giugno 2026, entro cui le aziende in perimetro devono completare la categorizzazione delle attività e dei servizi, per costruire un modello proporzionato di rischio, resilienza e investimento cyber
NIS2, dalla scadenza del 30 giugno al governo della sicurezza: la guida operativa
Ecco come usare la prossima scadenza NIS2 del 30 giugno 2026, entro cui le aziende in perimetro devono completare la categorizzazione delle attività e dei servizi, per costruire un modello proporzionato di rischio, resilienza e investimento cyber
Cloaking, SEO e minacce via web.
Altra tecnica datata ma molto efficace in determinati contesti: il cloaking. Va detto, per prima cosa, che il cloaking è una tecnica considerata poco etica nel mondo della SEO. Consiste nel verific…
American Tower - 216,601 breached accounts
In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.
Governance by design: quando il diritto impone di pensare prima di agire
Le recenti normative europee, come il GDPR, la NIS 2 e l'AI Act, superano la logica dell'adempimento formale e tardivo. Ecco perché, grazie alla governance by design, la progettazione deve precedere l'azione
Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure
Iranian hacker arrested in Montenegro over a $3.4B cyberattack on USA infrastructure. Faces computer fraud, hacking and identity theft charges.
CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access
CVE-2026-20245 let a threat actor gain root access to Cisco Catalyst SD-WAN Manager using a malicious CSV upload and anti-forensic techniques.
Cyber Resilience Act – Part I
Anthropic is testing desktop-like Claude Cowork for mobile
Anthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone.
Poland busts SIM-swapping gang tied to millions in crypto theft
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks.
Polymarket says hackers stole users’ funds
The prediction market giant Polymarket said it's refunding users who had funds stolen due to a third party breach.
Order-tracking app Shop abused to push callback phishing attacks
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software.
DHS chief says president has met with potential CISA nominee; agency plans to hire 600
Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027.
Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027.
Beyond IOCs: AI-enabled threat intelligence
In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.
PreCrime Credentials
PreCrime™ Credentials is a fully managed "Honeypot-as-a-Service" that deceives threat actors by deploying decoy login portals to silently intercept and validate stolen credentials against your actual identity provider.
Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats
Market research company Klue told customers that it believes the hacking group that stole their data is now deleting it. The company, however, warned about a second group of hackers wanting ransom.
New macOS malware embeds fake errors to confuse AI analysis tools
A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable.
PirloTV sports piracy network disrupted as 44 domains seized
A major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains.