Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention.
Windows 10 KB5120249 cumulative update released with fixes
Microsoft has released Windows 10 KB5120249 cumulative update for versions 22H2 and 21H2 to fix security vulnerabilities and bugs.
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
How to Create a Secure WordPress Staging Site: Beginner’s Guide
Learn how to create and secure a WordPress staging site, safely test updates and changes, and deploy them to your live website with less risk.
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
Delta investigating after someone set up fake Wi-Fi network mid-flight
The Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.
Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident.
CyberSec di base: pubblicazione dei servizi
Intro Praticamente tutte le reti, salvo alcune eccezioni, devono esporre qualche servizio verso internet. Se riprendiamo il nostro schema “brutto” possiamo riportare visivamente un esempio molto se…
Smishing a tema INPS: implementata verifica documentale tramite intelligenza artificiale
Cost of a Data Breach 2026: l’AI fa esplodere costi e velocità degli attacchi
Il report IBM 2026 fotografa una cyber security a due velocità: violazioni a quota 4,99 milioni di dollari (3,55 milioni in Italia), attacchi AI-driven +56% e modelli di AI aziendali sotto attacco. Ecco i numeri chiave e le contromisure per i team di sicurezza e i CISO
Attacco hacker a Levi’s: il dipendente non è l’anello debole, va ripensata la sicurezza
Tre dipendenti colpiti con tecniche di social engineering sono bastati agli attaccanti per accedere ai sistemi Levi's ed esfiltrare dati aziendali. Il caso dimostra perché la formazione non basta: la sicurezza deve partire dall'errore umano e impedirgli di trasformarsi in un incidente
Local governments in four states dealing with cyberattacks that have shut down services
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do.
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year.
Kids’ online safety bill faces dim prospects of passage this session despite progress
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
Network Security Policy Management (NSPM): colmare il gap tra normativa UE e adozione in azienda
Normative come NIS2 e DORA stanno innalzando gli standard in termini di resilienza, responsabilità e governance operativa, imponendo alle organizzazioni di dimostrare l'esistenza dei controlli di sicurezza e l'efficacia nel tempo. Ecco cos'è il Network Security Policy Management, l'anello mancante fra la normativa europea e l'implementazione reale
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks.
Gunra Ransomware Builds a New Attack Network Through RaaS
Gunra ransomware has expanded through a RaaS affiliate program, using double extortion, data theft and encryption to target across sectors.
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
From Detection Gaps to Fraud & Scam Leadership
Input validation: perché la sicurezza applicativa comincia dai dati che lasciamo entrare
Ogni dato proveniente dall'esterno può diventare un vettore di attacco. Per questo l'input validation non dovrebbe essere un controllo aggiunto a valle, ma un requisito di progettazione: un approccio multilivello che riduce la superficie di attacco senza sacrificare l'usabilità
Gestione dei rischi NIS 2: la scelta del metodo determina la qualità del sistema
La scelta del metodo non è una decisione tecnica di secondo piano, ma stabilisce il modo in cui l’organizzazione comprenderà i propri rischi, selezionerà le misure e dimostrerà la coerenza del proprio sistema. Ecco perché la gestione dei rischi occupa il centro esatto della NIS 2
Supply Chain Security: How ANY.RUN Helps US and EU Enterprises Prevent Incidents
See actionable steps for CISOs on how to build stronger supply chain security and reduce risk of third-party attacks.
New Zealand Targets Russian Cyber Actors With Fresh Sanctions
New Zealand sanctions against Russia target 33 individuals and entities, including cyber actors, Russian officials and groups supporting Moscow.