HelloNet campaign — new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
AI Agents Broke the Security Playbook. Here's What Replaces It.
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments.
23andMe to pay $18 million in new genetics data breach settlement
Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data.
Intro Nel primo post di questa serie ho riportato soprattutto la teoria della disciplina e l’estrema sintesi è che il Threat Hunting è un processo strutturato utile ad identificare e mitigare…
Scattered Spider members behind TfL hack get five years in prison
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.
Windows 11 24H2 Home and Pro reach end of support in 90 days
Microsoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months.
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
Zoom, scoperta una vulnerabilità che apre le porte all’account takeover su Windows
È stata corretta una vulnerabilità critica nel client Windows di Zoom che potrebbe consentire a un attaccante non autenticato di violare gli account via rete. Coinvolti anche VDI Client e Meeting SDK: ecco impatti, superficie di attacco e contromisure per i team di sicurezza aziendali
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application.
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT.
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
The Hunter's Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.
ANY.RUN uncovers how PhantomEnigma abused 20+ Brazilian government websites, hid behind trusted infrastructure, and put banks and public agencies at risk.
Dalle password alle passkey: ecco come usarle per il click to pay
Secondo un'indagine di Thales, quasi 7 utenti su dieci ammettono di condividere o prendere in prestito credenziali, evidenziando quanto rapidamente la difficoltà si trasformi in rischio. Ecco perché il superamento delle password, per migrare alle passkey, è urgente, in vista del click to pay
Le 12 best practice dell’ingegneria dei sistemi di intelligenza artificiale
Le pratiche non vanno intese come una sequenza procedurale o una checklist, ma come un quadro di riferimento per le decisioni progettuali. Ecco una sintesi e un'analisi critica del documento aggiornato sull'ingegneria dei sistemi di intelligenza artificiale con le 12 raccomandazioni del Software Engineering Institute (SEI)
Analysis of ClickLock, a modular macOS stealer delivered via ClickFix that uses fake dialogs, kill loops, and a GSocket backdoor to steal passwords, browser data, and crypto wallets.
Qantas Did Everything “Right” — And Got Breached Anyway. Regulators Say That’s the Point.
The Office of the Australian Information Commissioner (OAIC) closed the book this week on its year-long preliminary inquiry into the June 2025 Qantas data breach
Dutch police bust investment fraud ring stealing over €100 million
The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims.