US unseals indictment against alleged operators of Russian bulletproof hosting service
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft…
Nearly 300 GitHub repos pose as legit software to push malware
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware.
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes.
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Today is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed.
Windows 11 KB5101650 & KB5099414 cumulative updates released
Microsoft has released Windows 11 KB5101650 and KB5099414 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
Finland issues wanted notice for hacker behind massive psychotherapy data breach
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw.
LastPass, Bitwarden users targeted with fake security alerts
LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites.
Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says
The Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war.
Minacce cyber abilitate dall’AI: i 4 fronti al centro della lettera della BCE alle banche
La lettera del 7 luglio alle banche dell'Eurozona da parte della BCE chiede loro di presentare, entro il 31 ottobre 2026, un piano d'azione per rafforzare la cyber resilience contro le minacce abilitate dall'intelligenza artificiale, collegando il tema alla resilienza operativa richiesta da DORA. Ecco perché è importante anche per le aziende
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Gli assistenti AI di coding sono sicuri? Il caso xAI
Gli strumenti di AI per lo sviluppo software promettono di aumentare la produttività degli sviluppatori, ma una recente analisi indipendente riaccende il dibattito sulla sicurezza dei dati affidati agli assistenti di coding. Al centro della vicenda c’è Grok Build, il tool a riga di comando di xAI, accusato di aver trasmesso (in chiaro) ai server …
You Don't Have to Run an Exploit to Know If You're Vulnerable
Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depends on, without launching the exploit itself.
Q2 2026 Cyber Attacks Statistics Infographic
Cyber Attacks Statistics — Q2 2026 Q2 Threat Intelligence Briefing Cyber AttacksQ2 2026 543 confirmed incidents between 1 April and 30 June 2026. Financially motivated Cyber Crime drove over 7 in 1…
Q2 2026 Cyber Attacks Statistics
See the Q2 2026 cyber attack statistics: 578 incidents worldwide, 71.1% cyber crime, malware-driven, US hit hardest across 79 countries. HACKMAGEDDON data.
Sicurezza aziendale, le fondamenta vanno aggiunte prima
Le fondamenta della cyber security si costruiscono prima dello sviluppo, non dopo il rilascio. La security by design dimostra che progettare sistemi sicuri significa proteggere processi, persone e organizzazioni, riducendo il costo degli incidenti e rafforzando la resilienza
New phishing kits target Microsoft 365 accounts, evade MFA
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA).
Microsoft Entra ID gets passkeys default authentication starting September
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026.
SAP warns of critical flaws in NetWeaver and Commerce Cloud
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter.
Hackers steal Lidl customer data from external service provider
Microsoft starts testing cleaner Windows Search without ads
Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content.
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.
Spionaggio russo su Signal, il caso dei bersagli italiani
Politici, giornalisti e manager italiani sono nel mirino di una campagna di spionaggio russa su Signal. La tecnica aggira la crittografia attraverso l’utente, punta agli account e si inserisce nella pressione cyber contro istituzioni, media e figure pubbliche europee
Kratos PhaaS Targets US and EU Companies: How to Reduce Microsoft 365 Account Takeover Risk
Discover how Kratos PhaaS threatens Microsoft 365 accounts and how ANY.RUN helps security teams reduce fraud risk, speed detection, and contain compromise.
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.
The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets
Group-IB discovers a sophisticated multi-layered scam scheme targeting fans with fake ticket sales on two fronts: social network platforms and fraudulent websites impersonating official distributors.
US sanctions VPN, malware providers for enabling ransomware attacks
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations.
L’AI inventa un nuovo ransomware nel browser: il rischio vero è che riduce la soglia tecnica
La tipica allucinazione generativa, a una prima occhiata, si è invece trasformata in un'AI in grado di generare ransomware nel browser, collegando il rischio ipotetico dei browser a una tecnica di cifratura, classica da attacco ransomware, attivabile senza competenze evolute. Ecco come proteggersi dall'AI che genera ransomware nei browser
Nihon Kotsu Cyberattack Disrupts Japan’s Largest Taxi Operator
The Nihon Kotsu cyberattack disrupted Japan taxi service operations, forcing system shutdowns as the company investigates a malware-related breach.