Sanzione privacy a Wind Tre: il Garante porta la cyber al centro della compliance GDPR
La sanzione del Garante privacy a Wind Tre per due data breach mostra come la compliance all’articolo 32 del GDPR venga ormai valutata anche attraverso la qualità delle misure di cyber security. Dalla gestione delle credenziali alle API, la resilienza dei sistemi diventa il vero parametro di conformità
Una società di cyber security europea ha nascosto per anni i suoi collegamenti con la Russia
La società spagnola Passwork per anni ha tenuto i clienti all’oscuro di quanto il suo software fosse esposto alle analisi dei servizi segreti russi. Per farlo, ha perfino cercato di manipolare le informazioni elaborate dall’intelligenza artificiale
US charges two over laundering $43 million from investment fraud
U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams.
Smart grid e GDPR: quando l’energia diventa dato personale
La smart grid è quel salto tecnologico che rende possibile la transizione energetica, ma non è soltanto un’infrastruttura tecnologica, bensì un ecosistema informativo dove si intrecciano responsabilità, obblighi e relazioni tra i soggetti coinvolti. Ecco cosa succede quando la disciplina del GDPR incontra quella sulla sicurezza delle reti
CISA urges immediate action on actively exploited Fortinet flaws
CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform.
Coca-Cola says Fairlife ransomware attack halts US dairy production
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
New OkoBot framework deploys 20 payloads to steal data, crypto
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.
UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group
Owen Flowers and Thalha Jubair, two members of the prolific Scattered Spider hacking group, pleaded guilty and were sentenced to five years and six months in jail for hacking London’s metropolitan transit system.
Shadow AI in azienda: come scoprirla, classificarla e governarla
Secondo l'Osservatorio del Politecnico di Milano, un quinto degli utenti Ai generativa lo fa esclusivamente attraverso soluzioni aziendali approvate, mentre supera la metà dei dipendenti chi userebbe strumenti non autorizzati quando manca l’alternativa ufficiale. Ecco il fenomeno della Shadow AI in azienda, tutt’altro che marginale
HelloNet campaign — new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
AI Agents Broke the Security Playbook. Here's What Replaces It.
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments.
23andMe to pay $18 million in new genetics data breach settlement
Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data.
Intro Nel primo post di questa serie ho riportato soprattutto la teoria della disciplina e l’estrema sintesi è che il Threat Hunting è un processo strutturato utile ad identificare e mitigare…
Scattered Spider members behind TfL hack get five years in prison
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.
Windows 11 24H2 Home and Pro reach end of support in 90 days
Microsoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months.