L’associazione ATED di Lugano mi ha invitato anche quest’anno all’evento Cyber Security Day. È la mia seconda partecipazione (nella pagina dedicata alle conferenze trovate i detta…
AI Agent Exploits Gym System Vulnerability, Cancels Waitlist Booking in Australia
An AI agent exploited a gym system vulnerability in Australia, cancelling a waitlisted booking and raising concerns over AI safety, security, liability.
Hotel nel mirino: perché il settore alberghiero è un cyber-bersaglio facile
Dal furto di documenti d'identità nei check-in italiani alle campagne contro gli hotel di Milano-Cortina, fino alla violazione di Booking.com: tre episodi diversi raccontano la stessa vulnerabilità strutturale, che le regole attuali intercettano solo in parte.
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.
Google’s top hacker hunter explains why hacking groups get codenames
Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally.
נפתלי בנט 3: ספר הטלפונים של נפתלי הגרוטאה הצולעת שהבטיח לאמא החורגת שלו מרים אדלסון קזינו באילת
נפתלי בנט 3: ספר הטלפונים של נפתלי הגרוטאה הצולעת שהבטיח לאמא החורגת שלו מרים אדלסון קזינו באילת להלן ספר הטלפונים של נפתלי בנט. אילולא האלמנה של שלדון אדלסון לא היתה שופכת עליו כסף, הליצן הזה בכלל לא היה מענין מישהו. היא מסדרת לו סקרים מזויפים
Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.
Info di servizio: accesso agli approfondimenti tecnici
Cari lettori / amici / sostenitori, oltre alla creazione di contenuti tecnici (video, articoli, newsletter) sto sempre di più curando anche la forma di quello che condivido oltre che la qualità e q…
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.
Controlli di filiera inadeguati o mancanti comportano una serie di rischi per l'organizzazione, nonché in alcuni casi una violazione di obblighi normativi cogenti. Considerate le minacce diffuse, però, la gestione dei fornitori è un elemento imprescindibile per la governance di sicurezza cyber
Real emails, hijacked payments: Two H1 2026 attack chains
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments.
North Carolina Ports confirms cyberattack disrupting operations
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.