India's Telegram ban draws criticism from Durov as company challenges order in court
La sfida industriale dei computer quantistici
Materie prime rare, filiere fragili e pochissimi talenti: gli ostacoli sulla strada del quantum computing non sono solo scientifici, ma anche industriali e umani
Introducing Session Switcher. Swap Burp Sessions with One Click!
Introducing Session Switcher. Swap Burp Sessions with One Click!
Why India Temporarily Blocked Telegram Ahead of NEET UG 2026
Telegram Ban in India remains in effect until June 22 as authorities act against exam fraud ahead of the NEET UG 2026 Re-examination.
GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say
Microsoft working on Defender patch for RoguePlanet zero-day
Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago.
UK Cybercrime Journal: Sustained DragonForce Campaign
What Happened Throughout May 2026, affiliates of the DragonForce ransomware-as-a-service (RaaS) platform claimed seven UK-based companies ...
Kodak confirms data breach claimed by ShinyHunters extortion gang
Kodak has confirmed that it's working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's data.
GitBait: Phishing the Mexican Financial Sector
A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation.
Malicious JetBrains Marketplace plugins steal AI API keys from developers
At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers.
New Rokarolla Android malware targets 217 banking, crypto apps
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands.
Bug in FIFA World Cup internal system gave anyone ability to modify TV stream
A security researcher said a flaw in FIFA’s online platforms allowed her to access several internal systems, including one that could have allowed her to take control of the TV stream of every World Cup match.
WordPress PBN Plugin Drops Dual Webshells via Database Injection
Learn about the WordPress PBN Plugin infection that employs fake plugins and hidden techniques to exploit your site.
Steam Workshop abused to spread malware via Wallpaper Engine app
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages.
India temporarily blocks Telegram over medical exam cheating fears
Zscaler porta la Zero Trust nell’era degli agenti AI
Sebbene il numero di casi d’uso nel nostro Paese sia ancora molto basso, le previsioni di tutti gli esperti dicono che gli agenti AI diventeranno i veri “operati” dell’automazione dei processi in azienda. Il problema è che chi dovrà gestirne la sicurezza non ha ancora l’esperienza necessaria per farsi un quadro chiaro di come questi …
UK to require ID or face scan before you can make social media accounts
Opening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security experts warn the age checks are easy to circumvent and create new data-breach risks.
Archiviazione dei dati: oltre una Pmi europea su 2 non sa dove avviene
In uno scenario normativo sempre più complesso, la sovranità dei dati non è più soltanto tema tecnico, ma diventa una reale scelta operativa. Ecco perché le Pmi devo essere consapevoli su dove avviene l'archiviazione dei dati
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected.
Imaging di sicurezza: perché standardizzare i sistemi riduce rischi, costi e tempi
L’imaging di sicurezza è una pratica spesso sottovalutata, ma fondamentale per ridurre vulnerabilità, errori di configurazione e costi operativi. Standardizzare sistemi e baseline consente di rafforzare la cybersecurity, semplificare la gestione degli endpoint e migliorare la governance del rischio
IT Security Audit: la checklist per valutare i partner tecnologici
L'IT Security Audit dei sistemi partner è lo strumento operativo con cui le organizzazioni verificano sul campo ciò che i contratti SLA e i questionari di assessment dichiarano sulla carta. Questa guida fornisce metodologie, checklist strutturate per dominio e standard di riferimento per condurlo in modo efficace e conforme a NIS2
FTC warns of record $3.5 billion losses to imposter scams in 2025
The U.S. Federal Trade Commission (FTC) warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020.
Advait Patel on How SRE and Security Engineering Are Converging
Advait Patel explains how SRE and security engineering in cloud systems, covering DevSecOps, IAM, AI, and large-scale observability challenges.
Come funziona un Command and Control (C2)
IntroduzioneFunzionamento di baseStageless vs. StagedCanale di comunicazioneLab si esempioDetectionConclusione Chi segue il blog o il canale YouTube da un po’ è a conoscenza dei miei obiettiv…
Estonia to quarantine emails sent from Russian .ru domain before they reach government officials
Estonia to quarantine emails sent from Russian .ru domain before they reach government officials
China Spent Over a Year Inside U.S. Medical Research Networks — And Used Google’s Own Email Rules to Steal Data
The attackers, tracked as "UNC6508," did not write new malware to steal emails. They created an administrator rule inside Google Workspace, named it "Patroit"
CISA warns of another cPanel plugin flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin.
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.
The New Standard for URL Analysis: Closing Phishing Blind Spots with In-Browser Data Inspection
See how full browser visibility transforms URL analysis, helping analysts investigate phishing threats with confidence.
Cyber Shield: la resilienza dell’Italia nella protezione dei mega-eventi
Analisi della cybersecurity per i mega-eventi italiani: le strategie di difesa per le Olimpiadi e il Giubileo a Roma.