Progettazione del cablaggio strutturato: la spina dorsale fisica del data center
Perché il modo in cui vengono posati i cavi in fibra e di rame e come vengono disposti i rack incide sulla stabilità e sulla sicurezza di un data center
Agenti AI che attaccano: la lezione dai casi Anthropic e OpenAI
Anche Anthropic riporta un caso di un'agente AI che fa attacchi cyber. Si aggiunge al pericoloso precedente OpenAI-Hugging Face, che è il primo esempio di attacchi AI autonomi senza (anzi contro) la volontà umana. Ecco che succede e cosa imparare
Il jailbreak universale alla vigilia dell’AI Act: ecco l’impatto nella sicurezza aziendale
Il prossimo 2 agosto si applicherà l'articolo 55 dell'AI Act, che impone ai fornitori di modelli general purpose, a rischio sistemico, obblighi stringenti di red teaming, gestione degli incidenti e resilienza. Tra rivendicazioni social, ricerca accademica e obblighi normativi: cosa cambia nella postura delle aziende contro le minacce alla GenAI
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Chi si occupava di protezione dei dati cercava nella normativa un elenco di cose da fare. Nella struttura dell’articolo 24 del Regolamento, il GDPR mostra che una normativa fondata su principi e rischio non è più debole, ma più esigente. Ecco perché il regolamento europeo non ha abolito il diritto dell’obbedienza, ma lo ha reso insufficiente
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Chi si occupava di protezione dei dati cercava nella normativa un elenco di cose da fare. Nella struttura dell’articolo 24 del Regolamento, il GDPR mostra che una normativa fondata su principi e rischio non è più debole, ma più esigente. Ecco perché il regolamento europeo non ha abolito il diritto dell’obbedienza, ma lo ha reso insufficiente
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
Claude uploaded malware to PyPI in Anthropic's botched test
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations.
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution.
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies — like Microsoft and now Google — are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools.
Postel avvisa (con sei settimane di ritardo) che le PEC di Poste Italiane sono finite per errori ad altri
La segnalazione arriva da un nostro lettore che ha ricevuto la segnalazione direttamente da Postel. Le richieste? Non aprire le mail, cancellarle e rispondere dicendo di averlo fatto. Peccato che siano passate sei settimane
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI.
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a…
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.
Analisi dei flussi di rete: l’importanza del monitoraggio del traffico aziendale
Come la telemetria dei flussi offre visibilità completa sull'infrastruttura, aiuta a individuare colli di bottiglia e minacce, oltre a diventare la base dati per l'automazione della rete
In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
Cybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but traditional cybersecurity defense.
After the Break-In: What Attackers Do Once They're Already Inside
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware.