No Hat 2026, a Bergamo l’hacking incontra AI, cyber-spionaggio e droni
Il 10 ottobre torna la conferenza internazionale dedicata alla cybersecurity e all’ethical hacking. Tra i temi dell’ottava edizione, vulnerabilità negli AI coding assistant, attacchi alle infrastrutture di rete, malware, anonimato e compromissione dei sistemi autonomi L’intelligenza artificiale che sta cambiando anche il lavoro di chi cerca vulnerabilità e sviluppa nuove tecniche di attacco è uno …
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday.
Aggiornamenti Android settembre 2026, corrette 180 vulnerabilità: cosa fare subito
Google ha rilasciato il bollettino di sicurezza Android per il mese di settembre 2026 con patch per 180 vulnerabilità, tra cui otto Remote Code Execution critiche nel componente System e quattro falle critiche nel kernel Linux. Ecco un’analisi tecnica e le indicazioni operative per aziende e consulenti
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.
Droni, la nuova linea del fronte: dall’Ucraina ai cieli d’Europa, cosa cambia con le regole Ue
L'episodio recente più emblematico riguarda l'aereo del presidente ucraino Volodymyr Zelensky, sfiorato da un drone al momento del decollo dalla Moldavia, mentre era in rotta verso Oslo. Ecco perché l'escalation dei droni non si ferma in Ucraina e cos'è la dinamica della rana bollita in Europa
La corsa all’IA e l’allarme di chi l’ha costruita: ecco dove sorge la dinamica pericolosa
Jacob Coxon, ricercatore di Anthropic ed ex di OpenAI, ha lasciato il gruppo dei fratelli Amodei, accusando le due aziende di correre verso sistemi sempre più capaci, senza garanzie di sicurezza. Vediamo se sono credibili gli allarmi lanciati da chi sviluppa l’AI, ma nulla dimostra che i modelli attuali possano causare un’estinzione umana
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.
September Windows Server updates break Remote Desktop Services
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality.
Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality.
AI Agents Compromised 440 PaperCut Servers, Researchers Say
GreyNoise says AI agents compromised 440 PaperCut servers in 48 countries. The vulnerabilities are confirmed — the AI orchestration claim is not yet corroborated.
We've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
Incidenti AI e alignment: la lezione di Anthropic per la cyber sicurezza
Addestrare i modelli estremamente potenti del futuro affinché siano saldamente allineati è una sfida tecnica irrisolta che richiede una ricerca continua e un’eccellenza operativa per essere affrontata
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.
Agenti AI fuori dal perimetro: il caso OpenAI riapre il confine tra misalignment e incidente cyber
Agenti AI che usano un wiki pubblico come memoria esterna, condividono istruzioni e si adattano quando l’attività viene ostacolata. Il caso ricostruito da Reuters porta OpenAI a riconoscere una zona grigia tra misalignment e incidente cyber e riapre una questione decisiva: quando un comportamento anomalo deve diventare pubblico?
IDScan confirms breach tied to 153 million stolen driver’s licenses
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans.
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked.