Microsoft: September updates break File History backup feature
Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates.
Revolut: la paper compliance e la favola della PEC come e-mail sicura
La compromissione di una PEC istituzionale può trasformare un canale considerato sicuro in uno strumento di social engineering. Il caso Revolut mostra perché certificazioni e procedure non bastano: servono verifiche out-of-band, controlli indipendenti e processi capaci di resistere alla pressione dell'autorità
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.
Commerciale o open source, l’AI in azienda tra rischi noti e trappole nascoste
Sempre più organizzazioni devono scegliere tra soluzioni in cloud e modelli installati internamente. Ma il dibattito sulla sicurezza è impostato male. Il perché ce lo spiega Mirco Marchetti, professore associato di UniMoRe e direttore del Centro di Ricerca Interdipartimentale sulla Sicurezza
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.
Researchers escape OpenAI Codex sandbox to run commands on host
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
Le Migliori 10 Librerie Open-Source per React Native Che Abbiamo Starrato Questa Stagione
Il tooling per React Native ha avuto un vero momento di gloria tra le nostre stelle GitHub questo agosto-settembre - ecco le 10 librerie da aggiungere al tuo stack, per lo più del team Margelo.
Il colosso cinese ZPMC ha conquistato i porti di tutto il mondo con le sue gru iper-tecnologiche, connesse ed efficienti. E adesso si trova al centro dei timori geopolitici e di sicurezza degli USA.
Viral AI actress' hotline face-scans every caller, watches their mood
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print.
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs.
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
Calling viral AI actress Tilly Norwood? Agree to a face scan first
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print.
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
Four Countries Attribute “Contagious Interview” Fake-Job Malware Campaign to North Korea’s WaterPlum
Japan, the US, Australia and Germany tied the Contagious Interview campaign to North Korea's WaterPlum — 30,000 infected PCs and $10.7M in crypto stolen.
The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown
The Cyber Express weekly roundup covered a Nintendo Switch flaw, 12 deepfake sites seized, the GUARD Act, AI in offensive security, and a UAE X Cyble MOU.
Quando c'è un incidente provocato da un modello di IA, o da un agente, il discorso viene convenientemente orientato verso il disallineamento evitando di parlare di gestione del rischio. Uno spostamento d'attenzione che giova più alla spregiudicatezza di chi vuole restringere al minimo le responsabilità che alla sicurezza cyber
Il SOC non basta più: perché la cyber resilience richiede un nuovo modello di Security Operations
L'evoluzione delle minacce, la convergenza tra IT/OT e gli obblighi normativi stanno ridefinendo il ruolo dei Security Operations Center. Il progetto HyperSOC di HWG Sababa propone un modello SOC-as-a-Service che integra AI, automazione, threat intelligence e risk governance per trasformare il SOC in leva strategica della resilienza aziendale
Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements.
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access.
Cyber security e safety: perché la resilienza industriale passa dalla comprensione del contesto operativo
Negli ambienti industriali un incidente cyber può produrre conseguenze che vanno ben oltre il perimetro digitale. Il progetto sviluppato da Gyala mostra come integrare cyber, safety e resilienza operativa attraverso un modello context-aware capace di interpretare il significato degli eventi e adattare le risposte allo stato reale dell'impianto