Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
Red Hat npm packages compromised to steal developer credentials
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma."
Spain arrests doxer leaking sensitive data of govt employees
The Spanish National Police has arrested an individual for leaking sensitive information related to members of various key state organizations, including the National Cybersecurity Institute (INCIBE).
Asset Management & Data Classification: You Can’t Protect What You Can’t See
Part 4 of a series on creating information security policies.
Visibility before Protection
Organizations often invest heavily in cybersecurity tools: endpoint protection, firewalls, SIEM platforms, MFA, cloud security solutions, and threat detection services. Unfortunately, many security incidents still come down to a surprisingly simple problem: organizations do not fully understand what they own or where their sensitive data resides.
Before an organization can protect its environment, it fi
Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access
Several users on social media reported having their Instagram accounts hacked over the weekend. Meta's own support chatbot was blamed for allowing hackers to hijack accounts.
Dashlane password manager users locked out by brute force attacks
Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices.
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's…
Senza una policy DMARC robusta, le organizzazioni lasciano i propri domini esposti agli abusi, permettendo agli attaccanti di utilizzare l’identità del brand come arma su larga scala. Ecco come una solida applicazione blocca lo spoofing di dominio e protegge la fiducia nel brand alla base
Race Against Time: Why Faster Vulnerability Alerts Matter
Attackers are exploiting vulnerabilities faster than many organizations can identify and patch them. SecAlerts explains why faster vulnerability alerts can help reduce exposure and improve response times.
Contenuti generati dall’AI: watermark obbligatori ma la tecnologia non basta, ecco perché
La Commissione UE ha pubblicato tre studi tecnici che fanno il punto sull’applicazione del watermarking e sulla rilevazione dei contenuti generati dall'intelligenza artificiale, alla luce degli obblighi più tecnici introdotti dall'AI Act. Ecco i punti salienti
I dirigenti delle PMI italiane sono il bersaglio preferito: ma non lo sanno e il problema è sistemico
Dal manager impreparato alle multe che arrivano: perché pagare un professionista certificato non è un lusso, ma l’unica scelta razionale per chi fa impresa in Italia. Il passaggio dalla security awareness alla security education è urgente
Microsoft fixes outage affecting MFA setup, MySignIn service
Microsoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform.
Critical Windows Netlogon RCE flaw now exploited in attacks
The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon vulnerability in attacks.
ENISA NIS360 2026: la fotografia impietosa della cyber security nei settori critici NIS2
Il terzo rapporto annuale ENISA NIS360 sulla maturità cyber dei settori ad alta criticità rivela progressi reali ma disomogenei. Banche, telecomunicazioni ed elettricità guidano la classifica. Acqua, spazio e PA restano nella "risk zone". Ecco cosa devono fare le aziende per non restare indietro
Webinar tomorrow: From alert to resolution in network incident response
Network incidents are often detected quickly, but investigations and coordination can delay resolution. Join our webinar tomorrow to learn how automation and AI-assisted workflows can help IT teams accelerate incident response.
Microsoft confirms outage affecting MFA, My Sign-Ins platform
Microsoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform.
Microsoft fixes KB5089549 Windows security update install issues
Microsoft has resolved a known issue causing installation failures and 0x800f0922 errors when deploying the May 2026 Windows 11 security update (KB5089549).