The hacker who humiliated spyware makers and was never caught
An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide.
OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance.
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services.
Acn: nel primo semestre 2026 resta elevata la pressione da parte delle minacce cyber
Secondo l'operational summary dell'Acn, nel primo semestre 2026 si sta consolidando il sistema nazionale di cyber security, mentre l'entrata a regime degli obblighi di notifica previsti dalla direttiva NIS2 rafforza la resilienza del Paese. Ecco cosa emerge nei dettagli e cosa brilla per la sua assenza
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline.
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19.
Il recente caso exploitgym, con i server di Huggingface compromessi dall'azione degli agenti di OpenAI offre non pochi spunti per ragionare circa il gap cognitivo fra rischio incalcolabile e non calcolato nella gestione della sicurezza cyber
Backup su larga scala: dagli indicatori di stato “verde” alla reale capacità di ripristino
In caso di incidenti, dovuti ad attacchi ransomware, interruzioni di servizio o cancellazioni accidentali, ciò che conta è se esistono punti di ripristino, quanto questi siano recenti e se i backup siano rapidamente e ripetutamente eseguibili, anche in situazioni di stress. Ecco come effettuare il backup su larga scala
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups.
Man gets six years for hacking 750 women's Snapchat accounts
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos.
Malware nella supply chain software: gli sviluppatori sono il punto più vulnerabile
Il nuovo malware individuato da Doctor Web non si limita a sottrarre credenziali o installare backdoor: compromette i progetti C++ e C# trasformando gli ambienti di sviluppo in vettori di attacco. Un’evoluzione che conferma come la supply chain software sia ormai uno dei principali fronti della minaccia cyber
CRA e Direttiva UE sui prodotti difettosi: come cambia la responsabilità cyber delle imprese
Il Cyber Resilience Act definisce i requisiti di sicurezza dei prodotti digitali, ma la nuova Direttiva UE 2024/2853 sulla responsabilità per danno da prodotti difettosi aggiunge un tassello decisivo: la cyber security esce dall'ambito della compliance e diventa un fattore di responsabilità civile e di rischio d'impresa
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Smart grid e transizione energetica: perché la governance dei dati è un vantaggio competitivo
La trasparenza nella gestione dei dati non costituisce un vincolo, ma si traduce in un elemento di differenziazione competitiva presso consumatori sempre più consapevoli dei propri diritti. Ecco come principi, progettazione e vantaggio competitivo agevolano la fiducia dei consumatori