Fraudsters steal $6 million from Tectonic crypto platform after inflating token price
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.
OpenAI confirms ChatGPT outage as users report errors
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks.
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers.
How AI could make it harder for governments to use hacking tools
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.
Cyber attacco agli aeroporti britannici: a rischio i dati dei passeggeri in transito
Non risultano esposti dati bancari o di pagamento: il cyber attacco possono diventare una fonte preziosa di intelligence non avrebbe compromesso la sicurezza dei voli né le operazioni aeroportuali. Ma proprio questo dimostra come sistemi periferici possano diventare una fonte preziosa di intelligence. Ecco qual è il vero rischio cyber
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history.
Berlin says it won’t pay ransom after hackers steal government data
File servers are here to stay. Here’s how to manage them securely
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access.
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site.
Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
Slovenian casinos reopen after cyberattack knocked gaming systems offline
PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days
PaperCut shipped a second emergency patch for CVE-2026-81578 and CVE-2026-82078 after researchers bypassed the first fix. Attacks began Aug. 26.
Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems
The Boston Scientific cyberattack disrupted operations, manufacturing and shipping, while an investigation examines unauthorized activity and device impact.
Reward hacking: i confini incerti degli agenti AI autonomi nella sicurezza
Nel caso Hugging Face, gli agenti AI hanno trattato il confine dell'ambiente di test come un ostacolo tra loro e il punteggio massimo. Ecco i precedenti e il fenomeno del Reward hacking nell'era degli agenti AI, pronti a trattare ogni confine, tecnico o procedurale, come un elemento dell'ambiente da aggirare per massimizzare il punteggio
Ecco il Polo Italiano per il Cyber e lo Spazio. Ma ora si deve fare sistema
Il direttore del PICS, Luigi Martino, spiega quali sono i cinque pilastri su cui si fonda il neonato organismo, come l'Italia può valorizzare quello che già esiste nel settore e i nodi da sciogliere per trasformare questa visione in realtà
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update.
Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage
Anthropic says Vidar, LummaC2, StealC, RedLine, Acreed and AMOS malware are stealing Claude session tokens to hijack accounts and drain paid usage.
Shadow IT e organizzazione reale: cosa succede quando la procedura non governa più
La recente sentenza del Tribunale di Udine non riguarda solo l'uso di WhatsApp nei rapporti di lavoro o una controversia disciplinare nata da una comunicazione attraverso un canale improprio, ma la progressiva perdita di coincidenza tra organizzazione formale e quella realmente operante. Ecco cosa mette in luce il provvedimento
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
Backup continui, CDN integrata e strumenti AI: la soluzione per blindare e scalare i progetti sul web
Hostinger propone servizi di hosting web con backup giornalieri a soli 3,99 € al mese: ecco come ottenere lo sconto del 79% della promo.
Nigerians extradited to US for sextortion, deaths of two teens
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina.
AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields
CVE-2026-77846 affects AshSqlite, allowing JSON path injection that may expose hidden fields. Learn affected versions, impact, and fixes.
AI Shared Responsibility Model: chi risponde della sicurezza nell’era della Generative AI
Dai dati agli output, fino a plugin e agenti autonomi, la Generative AI introduce rischi che ridisegnano i confini tra provider e cliente. L'AI Shared Responsibility Model aiuta a stabilire chi deve presidiare ogni controllo e soprattutto quali responsabilità restano sempre in capo all'organizzazione
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem
Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets.
Microsoft asks users to ignore 'Antivirus is turned off' errors
Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates.
Praetorian – Offensive Security Tools Built Around Portable Go Workflows
Praetorian develops portable Go security tools for service fingerprinting, secrets discovery, reconnaissance, credential testing and more.
How to Install Proxmark3 on the ClockworkPi uConsole
The ClockworkPi uConsole is already an interesting portable Linux computer. By connecting a Proxmark3, it can also become portable RFID research for exploring and understanding contactless cards and tags, cloning them and identifying how different cards work and their security. This beginner-friendly guide explains how to install the Proxmark3 client, compile the matching firmware, connect […]
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed.
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures.