FBI, Pentagon warn of Iran hacking groups targeting operational technology
FBI: Americans lost a record $21 billion to cybercrime last year
U.S. victims lost nearly $21 billion to cyber-enabled crimes last year, driven primarily by investment scams, business email compromise, tech support fraud, and data breaches, the Federal Bureau of Investigation says.
Snowflake customers hit in data theft attacks after SaaS integrator breach
Over a dozen companies have suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen.
US warns of Iranian hackers targeting critical infrastructure
Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations.
APT28 colpisce i router per dirottare il DNS e rubare credenziali
Secondo un’analisi pubblicata dal National Cyber Security Centre britannico e supportata da dati di Microsoft Threat Intelligence, il gruppo APT28 continua a compromettere router domestici e per piccoli uffici per manipolare il DNS e intercettare credenziali sensibili, utilizzando infrastrutture di rete apparentemente innocue come trampolino verso obiettivi più rilevanti. La campagna, attribuita al collettivo noto …
Russian government hackers broke into thousands of home routers to steal passwords
Fancy Bear, also known as APT28, has taken over thousands of residential home routers to steal passwords and authentication tokens in a wide-ranging espionage operation.
Max severity Flowise RCE vulnerability now exploited in attacks
Hackers are exploiting a maximum-severity vulnerability, tracked as CVE-2025-59528, in the open-source platform Flowise for building custom LLM apps and agentic systems to execute arbitrary code.
Russia Hacked Routers to Steal Microsoft Office Tokens
Hackers linked to Russia's military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens…
National security veterans warn against delays in FISA 702 reauthorization
Iran recluta cyber criminali russi: nuova escalation nella guerra cibernetica globale
Secondo un report di intelligence, Teheran starebbe integrando attori criminali nelle proprie operazioni offensive per colpire obiettivi USA. Torna Pay2Key in versione “pseudo-ransomware” e cresce l’ambiguità tra cybercrime e attività statali. Ecco quali nuovi rischi introduce la convergenza tra stato e criminalità
Dall’app virale ai mal di testa globali: quando il successo diventa un problema legale
Chiunque fornisca un servizio ha la responsabilità di apprendere i requisiti legali si applicano alla propria situazione e soddisfare tutti quelli di conformità. Ecco una guida pratica per navigare la complessità normativa globale e trasformarla in vantaggio competitivo
Massachusetts hospital turning ambulances away after cyberattack
Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins
An international operation from law enforcement authorities in partnership with private companies has disrupted FrostArmada, an APT28 campaign hijacking local traffic from MikroTik and TP-Link routers to steal Microsoft account credentials.
UK exposes Russian cyber unit hacking home routers to hijack internet traffic
Why Your Automated Pentesting Tool Just Hit a Wall
Automated pentesting tools deliver strong early results, then quickly plateau. Picus Security explains how the "PoC cliff" leaves major attack surfaces untested and creates a dangerous validation gap.
Cyberattack on telecom giant Rostelecom disrupts internet services across Russia
Cyberattack hits Northern Ireland’s centralized school network, disrupting access for thousands
Talos Takes: 2025's ransomware trends and zombie vulnerabilities
In this episode of Talos Takes, Amy and Pierre Cadieux unpack the ransomware and vulnerability trends that defined 2025.
ClickFix Meets AI: A Multi-Platform Attack Targeting macOS in the Wild
How attackers used Claude and other AIs to deliver macOS malware — and what ANY.RUN's new interactive sandbox reveals about the attack chain.
Aggiornamenti Android aprile 2026: corrette solo due vulnerabilità, ma “meno” non significa “meglio”
Google pubblica l’Android Security Bulletin di aprile 2026 che corregge solo due vulnerabilità contro le 129 del mese scorso, ma una delle due riguarda StrongBox, il sottosistema di sicurezza hardware che custodisce chiavi crittografiche, credenziali e dati biometrici nei dispositivi Android più recenti. Ecco i dettagli
Year in Review: Vulnerabilities old and new and something React2
The year was characterized by an unending beat-down on infrastructure that relied on older enmeshed dependencies (e.g., Log4j and PHPUnit), while React2Shell rocketed to the highest percentage of attacks for the entire year within the last three weeks of 2025.
The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines
Cisco Talos has recently observed an increase in activity that is leveraging notification pipelines in popular collaboration platforms to deliver spam and phishing emails.
Esposto il codice sorgente di Claude: ecco i rischi per l’erroneo rilascio da parte di Anthropic
Il caso della pubblicazione per errore di Claude Caude accende i fari su temi cruciali per la cyber security moderna: la gestione dei rilasci software, la protezione della proprietà intellettuale e i rischi connessi all'adozione massiva di strumenti di sviluppo automatizzato
Child Safety at Risk as EU CSAM Detection Law Lapses, Reporting Concerns Rise
EU legal gap on CSAM detection threatens child safety, weakens reporting, and risks rise in child sexual exploitation across digital platforms.
Dal progetto al processo: i 5 errori che bloccano la sicurezza
Governare il passaggio da progetto a processo significa gestire persone, ruoli, responsabilità e il cambiamento culturale che ne consegue. Ecco gli errori e le pratiche per passare dal “fare” al “funzionare”
Common Entra ID Security Assessment Findings – Part 3: Weak Privileged Identity Management Configuration
Germany Names Suspected Leader of REvil and GandCrab Ransomware Gangs
The exposure of a suspected leader behind the REvil ransomware gang is a rare win for law enforcement.
EvilTokens: an AI-augmented Phishing-as-a-Service for automating BEC fraud – Part 2
Explore how EvilTokens uses AI-driven features to automate and scale BEC workflows. Uncover the PhaaS operations on Telegram.
FortiClientEMS Vulnerabilities Under Active Exploitation, Expose Systems to RCE
CVE-2026-35616 and CVE-2026-21643 expose FortiClientEMS to SQL Injection and RCE attacks, with active exploitation observed in the wild.
$20 Billion Lost to Cybercrime as AI and Investment Scams Surge: FBI Report
The FBI Internet Crime Report 2025 highlights a shift in how cybercrime operates today.