US, Britain to coordinate on scam center takedowns
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
Sintesi riepilogativa delle campagne malevole nella settimana del 29 agosto – 4 settembre
UK account-hack losses surge as new reporting system exposes hidden cases
Il budget? Non basta mai
Che la sicurezza cyber debba coinvolgere anche l'IA è vero, ma non è possibile delegarla a questi sistemi o, peggio ancora, considerarli come un focus principale sia d'attacco che di difesa. Perché altrimenti il rischio è quello di perdere quella visione d'insieme necessaria per mantenere una corretta postura di sicurezza cyber
Il phishing sfrutta le difficoltà economiche: come prevenire l’attacco che induce a telefonare all’attaccante
L’ultima campagna phishing, che scommette sulle difficoltà economiche delle vittime, trasforma l’ansia economico-finanziaria in vettore di ingegneria sociale, incoraggiando le vittime a chiamare un numero di telefono sotto il controllo dei cyber criminali. Ecco come mitigare i rischi nelle interazioni telefoniche
Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems.
AI-Driven Threat Intelligence for Gulf Enterprises: Why Detection Speed Is Now a Regulatory Requirement
See how AI-powered threat intelligence helps GCC enterprises detect breaches faster and meet 6-to-72-hour cybersecurity reporting requirements.
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography.
Cyber Resilience Act, l’11 settembre scattano gli obblighi di segnalazione: cosa cambia per le aziende
Dall’11 settembre 2026 il Cyber Resilience Act entra nella sua prima fase operativa con gli obblighi di segnalazione previsti dall’articolo 14. Una scadenza che impone a produttori e sviluppatori di preparare processi di incident response, vulnerability management e CVD senza aspettare la piena applicazione del 2027
Russian data centers face new security requirements amid Ukraine's drone threats
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems.
G7 urges organizations to prepare for quantum cyber threats
Exchange Online outage causes email delays, 'Server busy' errors
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains.
Control Gap dell’AI: la corsa all’adozione lascia i dati vulnerabili
Con il debutto di Claude Mythos, il tempo che intercorre tra la scoperta di una vulnerabilità e la compromissione attiva (con accessi non autorizzati) si sta azzerando. Ecco cosa implica il fatto che la velocità delle minacce ha subito un’accelerazione senza precedenti e come cambia il ritmo del cybercrime
Google warns of new Chrome zero-day flaw exploited in attacks
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks
The Cyber Express Weekly Roundup covers Claude session hijacking, PaperCut exploits, Boston Scientific, X attacks, and Citrix NetScaler flaws.
CBI Searches 89 Locations Across 20 States in Digital Arrest Cases, Arrests Three
CBI searched 89 locations across 20 states in three digital arrest cases under Operation Chakra-VI, arresting three accused of laundering ₹42.4 crore in fraud.
Gestione delle credenziali e architetture Zero-Knowledge: come Proton Pass integra crittografia E2EE, alias email e Passkey contro il phishing
Proton Pass offre una gestione delle password E2EE e l'uso di Passkey a 2,49 € al mese: ecco come funziona l'offerta e come attivarla.
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
Server Exchange, cinque scudi per la posta elettronica
La sicurezza dei server Exchange dipende dalla capacità di ridurne l’esposizione, correggere rapidamente le vulnerabilità e riconoscere un’intrusione già avvenuta. Di cosa tenere conto e quali strumenti sono d’aiuto
Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach
Kentucky Appellate Court data was compromised in a Thomson Reuters CMS C-Track breach. The AOC says the investigation is ongoing.
Organizzazioni “buone” o “brave” negli adempimenti GDPR: il futuro si progetta
La distinzione tra organizzazioni “buone” - che rispettano le regole già definite da altri - e quelle “brave” - che comprendono i trattamenti, valutano i rischi, trasformando gli adempimenti in strumenti di governo - è messa alla prova sugli strumenti quotidiani. Ecco come le lingue costruiscono il futuro dal dovere (shall) e dalla volontà (will)
One Adversary: The 90-Day Fusion Playbook
Fusion is a capability you mature into, not a team you hire. Here is the honest maturity path, the metrics that fund it, and the on-ramp that costs no headcount, startable this quarter.
Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk
Citrix NetScaler vulnerabilities affect ADC and Gateway products, with ASD's ACSC urging organisations to assess and patch affected systems.
Pegasus, New NoviSpy Variant Found on Serbian Students and Opposition Figures
SHARE Foundation says 14 Serbian students, activists and opposition figures were hit with Pegasus and a new NoviSpy variant, some during police detention.
French hospital fined €500,000 after breach exposes data of 727,000
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data.
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
Large group of Serbian opposition, activist figures targeted with spyware
HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.