Il phishing si evolve, soprattutto nell'era dell'Intelligenza Artificiale e con l'impiego degli agenti, ma sta solo cambiando le vesti di una tecnica d'attacco che è e rimane fondamentalmente umana
The Cyber Express Weekly Roundup: Campus Cyberattack, Januscape VM Escape, Router Backdoors, UniFi Flaw, and Wireshark Security Updates
Enterprise infrastructure is increasingly under pressure as attackers and researchers alike expose weaknesses across the technology stack. This week, a
La guerra ucraina cambia la cybersecurity delle infrastrutture critiche
La guerra in Ucraina non si combatte solo sul terreno, nel mare o nello spazio aereo. Il cyberspazio è uno degli scenari più attivi, dove vengono perpetrati quotidianamente decine di attacchi mirati alle infrastrutture civili e militari. Il continuo bersagliamento di infrastrutture energetiche, reti di comunicazione e servizi pubblici ha praticamente trasformato l’intero Paese in …
Zimbra urges customers to patch critical web client XSS flaw
The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite.
Anonimizzazione, le nuove linee guida EDPB: dalla tecnica al processo di assessment
Le nuove Guidelines 02/2026 dell’EDPB trasformano l’anonimizzazione da tecnica a processo di assessment continuo. Tra rischio di re-identificazione, AI e accountability, l’obiettivo non è solo uscire dall’ambito del GDPR, ma rafforzare la tutela dei diritti fondamentali
Governance by design: come costruire organizzazioni che pensano prima di agire
Bisogna smettere di progettare faldoni di documenti e, finalmente, iniziare a progettare le decisioni. Ecco i pilastri della governance by design come modello integrato di direzione aziendale
L’AI ridefinisce la sovranità dei dati: le nuove priorità per i leader IT
Con l’accelerazione dell’adozione dell’AI enterprise, le organizzazioni sono sottoposte a una crescente pressione per mantenere visibilità, governance e controllo sui dati sensibili in ambienti digitali sempre più complessi. Ecco perché l’AI introduce nuovi livelli di incertezza, rendendo essenziali trasparenza, accountability e supervisione
Governance by design: come costruire organizzazioni che pensano prima di agire
Bisogna smettere di progettare faldoni di documenti e, finalmente, iniziare a progettare le decisioni. Ecco i pilastri della governance by design come modello integrato di direzione aziendale
L’AI ridefinisce la sovranità dei dati: le nuove priorità per i leader IT
Con l’accelerazione dell’adozione dell’AI enterprise, le organizzazioni sono sottoposte a una crescente pressione per mantenere visibilità, governance e controllo sui dati sensibili in ambienti digitali sempre più complessi. Ecco perché l’AI introduce nuovi livelli di incertezza, rendendo essenziali trasparenza, accountability e supervisione
Former ransomware negotiator gets 4 years for BlackCat attacks
A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks.
Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases.
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are
With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data
See the 30 malware families and phishing kits hitting US businesses most right now, ranked by live sandbox data — including MFA-bypass phishing kits, stealers, RATs, and ransomware-enabling tools, with industries at risk.
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data
See the 30 malware families and phishing kits hitting US businesses most right now, ranked by live sandbox data — including MFA-bypass phishing kits, stealers, RATs, and ransomware-enabling tools, with industries at risk.
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data
See the 30 malware families and phishing kits hitting US businesses most right now, ranked by live sandbox data — including MFA-bypass phishing kits, stealers, RATs, and ransomware-enabling tools, with industries at risk.
With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data
See the 30 malware families and phishing kits hitting US businesses most right now, ranked by live sandbox data — including MFA-bypass phishing kits, stealers, RATs, and ransomware-enabling tools, with industries at risk.
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data
See the 30 malware families and phishing kits hitting US businesses most right now, ranked by live sandbox data — including MFA-bypass phishing kits, stealers, RATs, and ransomware-enabling tools, with industries at risk.
With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."
With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."