Found 35733 bookmarks
Newest
Chinese hackers exploit multiple technologies to steal govt data
Chinese hackers exploit multiple technologies to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases.
·bleepingcomputer.com·
Chinese hackers exploit multiple technologies to steal govt data
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
Flashpoint analysts examine Process Parameter Poisoning—a novel EDR evasion technique we validated in Rust—and detail how abusing undocumented process parameters allows attackers to inject code and bypass standard security products.
·flashpoint.io·
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
·bleepingcomputer.com·
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
New ClosedQuorum Windows malware uses AI for attack decisions
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.
·bleepingcomputer.com·
New ClosedQuorum Windows malware uses AI for attack decisions
Reducing shadow IT visibility gaps with Wazuh
Reducing shadow IT visibility gaps with Wazuh
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps.
·bleepingcomputer.com·
Reducing shadow IT visibility gaps with Wazuh
Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset
Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset
La gestione del rischio non può prescindere da una visibilità completa dei sistemi IT/OT. Il progetto sviluppato da Lutech per un'importante azienda manifatturiera mostra come monitoraggio passivo, Cyber Asset Management e Continuous Threat Exposure Management trasformano l'inventario degli asset in strumento strategico di cyber resilience
·cybersecurity360.it·
Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset
Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio
Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio
Un solo errore dell’algoritmo può bastare per spingere gli analisti a ricontrollare ogni decisione automatica. Ma la sfiducia ha un costo: rallenta l’incident response e può offrire agli attaccanti tempo prezioso. Per i CISO, progettare l’automazione significa quindi progettare anche la fiducia di chi dovrà utilizzarla
·cybersecurity360.it·
Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
·bleepingcomputer.com·
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California
Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California
Con ponderazione ma con urgenza, il 18 settembre 2026 il governatore della California Gavin Newsom ha firmato l’ordine esecutivo N-9-26 dedicato ai modelli di frontiera. Ecco cosa comporta in termini di supervisione indipendente e sicurezza dei sistemi di intelligenza artificiale e le differenze con la SB 1047 respinta nel 2024
·cybersecurity360.it·
Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California
PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco
PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco
Niente malware sui PC, nessun file cifrato e nessun processo sospetto da intercettare. In un incidente analizzato da Kaspersky, gli attaccanti hanno utilizzato le Group Policy di Active Directory per colpire contemporaneamente l’intero dominio, trasformando uno degli strumenti più fidati dell’amministrazione Windows in un meccanismo di estorsione
·cybersecurity360.it·
PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
·bleepingcomputer.com·
D-Link warns of max severity zero-day bug in DIR-822A routers
Webinar tomorrow: Inside real-world Google Workspace breaches
Webinar tomorrow: Inside real-world Google Workspace breaches
Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference.
·bleepingcomputer.com·
Webinar tomorrow: Inside real-world Google Workspace breaches
Incogni Unlimited cancella i dati personali dal web
Incogni Unlimited cancella i dati personali dal web
Incogni Unlimited cancella i dati personali dal web: ecco come funziona il piano, come si può attivare e quali sono i costi da sostenere.
·cybersecurity360.it·
Incogni Unlimited cancella i dati personali dal web
New Windows Defender zero-day blocks Microsoft antivirus updates
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
·bleepingcomputer.com·
New Windows Defender zero-day blocks Microsoft antivirus updates
The Closed Quorum: Inside the first reported autonomous AI C2 implant
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.
·blog.talosintelligence.com·
The Closed Quorum: Inside the first reported autonomous AI C2 implant
LimeLeads - 17,838,396 breached accounts
LimeLeads - 17,838,396 breached accounts
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including state, city and postcode.
·haveibeenpwned.com·
LimeLeads - 17,838,396 breached accounts
Rapporto CRIF 2026: il cybercrime non ruba più solo credenziali, costruisce identità digitali
Rapporto CRIF 2026: il cybercrime non ruba più solo credenziali, costruisce identità digitali
Il vero rischio non è più il singolo dato rubato, ma ciò che i criminali possono costruire aggregandolo agli altri. Il rapporto CRIF 2026 mostra come infostealer, dark web e AI stiano trasformando credenziali e informazioni personali in identità digitali utilizzabili per frodi sempre più credibili. E l'Italia è tra i Paesi più esposti
·cybersecurity360.it·
Rapporto CRIF 2026: il cybercrime non ruba più solo credenziali, costruisce identità digitali
CISA orders feds to patch Zyxel flaw exploited for data theft
CISA orders feds to patch Zyxel flaw exploited for data theft
​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
·bleepingcomputer.com·
CISA orders feds to patch Zyxel flaw exploited for data theft
August 2026 Cyber Attacks Statistics
August 2026 Cyber Attacks Statistics
218 cyber attacks analyzed for August 2026 — top motivations, attack vectors, initial access techniques, and the sectors and countries hit hardest.
·hackmageddon.com·
August 2026 Cyber Attacks Statistics