Non‑Human Identity (NHI) e sicurezza dell’IA. Quanto si rischia
L’adozione accelerata dell’IA sta trasformando le Non‑Human Identity nel principale punto cieco della cyber security. Il report CSA mostra come governance, automazione e ownership siano oggi il vero fattore critico.
CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack.
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face.
CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
Gestione del data breach: i protocolli operativi di segnalazione e notifica alle autorità
Dalla scoperta dell'incidente alla chiusura del caso: la guida operativa alle 72 ore, alla notifica telematica al Garante e agli obblighi di comunicazione verso gli interessati previsti dal GDPR
Aziende e PMI sotto attacco (simulato): la cyber security in azienda si allena così
Il Cyber Arena Tour di WINDTRE Business coinvolge aziende e PMI italiane in simulazioni realistiche di attacchi cyber: gamification, decisioni sotto pressione e competenze specialistiche per trasformare la sicurezza informatica da tema tecnico a priorità strategica d'impresa
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect.
Cyber Resilience Act, con le nuove linee guida la conformità ha finalmente una mappa
La Commissione europea pubblica le linee guida attuative del Cyber Resilience Act: chiarimenti su ambito applicativo, software open source, modifiche sostanziali e obblighi di segnalazione. Una guida non vincolante, ma strategica in vista delle scadenze di settembre 2026 e dicembre 2027
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.
Sistemi aperti o chiusi? Il falso dilemma della sicurezza
Open source o sistemi proprietari? Il dibattito tra architetture aperte e chiuse rischia di semplificare eccessivamente il problema. La sicurezza informatica nasce da progettazione, governance e strategie di difesa multilivello, non dalla sola trasparenza o segretezza del codice
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.