Penetration test e AI: non serve un’AI più potente, ma un pentester più strategico
La competenza distintiva di un tester offensivo cambia ai tempi dell'intelligenza artificiale. Ecco come effettuare penetration test efficaci nell'era dell'AI
Mythos e Chronos, la corsa contro il tempo di Anthropic e le domande senza risposta
Un modello troppo capace per essere rilasciato al pubblico. Questo è Mythos, del quale si sa quel poco che basta per alimentare dubbi, legati anche alla corsa contro il tempo di Anthropic per sbarcare in borsa. Anche unendo i punti, i quesiti rimangono irrisolti
Patch Tuesday agosto 2026: un driver Windows, il gruppo Lazarus e 400 vulnerabilità sullo sfondo
Il Patch Tuesday di agosto 2026 interviene per correggere 421 vulnerabilità tra cui una zero-day nel driver WinSock già sfruttata da Lazarus e quattro RCE unauthenticated con CVSS 9.8. E conferma che con l’adozione l'AI-driven discovery il triage per contesto batte il triage per punteggio
6G, infrastruttura di sorveglianza pervasiva: rischi cyber, minaccia cinese e Golden power
Integrated Sensing and Communication (ISAC), consenso informato e resilienza delle reti mobili di sesta generazione: un'analisi tecnico-scientifica del 6G come infrastruttura di sorveglianza pervasiva
NIS2, ACN chiarisce come funzionerà la vigilanza: ora bisogna dimostrare la compliance
Le nuove FAQ di ACN chiariscono come funzioneranno monitoraggio e vigilanza NIS2. Per le imprese non basterà avere procedure e documenti: serviranno evidenze capaci di dimostrare l'effettiva applicazione delle misure e una governance che colleghi rischi, decisioni, responsabilità e controlli
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
A new NFC relay malware designated as WindRelay, paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out.
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity.
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May.
FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures
In a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns.
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices.
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention.
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
Intro Praticamente tutte le reti, salvo alcune eccezioni, devono esporre qualche servizio verso internet. Se riprendiamo il nostro schema “brutto” possiamo riportare visivamente un esempio molto se…
Cost of a Data Breach 2026: l’AI fa esplodere costi e velocità degli attacchi
Il report IBM 2026 fotografa una cyber security a due velocità: violazioni a quota 4,99 milioni di dollari (3,55 milioni in Italia), attacchi AI-driven +56% e modelli di AI aziendali sotto attacco. Ecco i numeri chiave e le contromisure per i team di sicurezza e i CISO
Attacco hacker a Levi’s: il dipendente non è l’anello debole, va ripensata la sicurezza
Tre dipendenti colpiti con tecniche di social engineering sono bastati agli attaccanti per accedere ai sistemi Levi's ed esfiltrare dati aziendali. Il caso dimostra perché la formazione non basta: la sicurezza deve partire dall'errore umano e impedirgli di trasformarsi in un incidente