Wp2shell: Vulnerabilità critiche nel core di WordPress. Necessario aggiornare i sistemi
L’industria della colonizzazione lunare
Mappe, porti, regolamenti e soprattutto rapporti di potere: come funziona la logistica della space economy.
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
The Future of Age Verification: Your Face Never Leaves Your Device
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance.
Abbott Laboratories probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.
FBI arrests man accused of using Steam games to drain victims’ crypto wallets
Prosecutors accused 21-year-old student Zyaire Wilkins of publishing on Steam several fake video games that contained malware, infecting thousands of victims, and stealing crypto from some of them.
Così i Servizi russi hanno compromesso router in tutto il mondo: le contromisure
Una campagna decennale, orchestrata dal “Centro 16” del Servizio Federale di Sicurezza russo, l'FSB, ha compromesso router e dispositivi di rete, configurati in modo debole o non aggiornato, per trasformarli in nodi di appoggio da cui lanciare, in forma anonima, operazioni contro le infrastrutture critiche a livello globale. Il caso Turla
Sintesi riepilogativa delle campagne malevole nella settimana del 11 – 17 luglio
Ernst & Young discloses data breach after support system hack
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
Recupero crediti, Garante Privacy: ecco chi paga il conto della mancata vigilanza
Due provvedimenti "gemelli" del Garante privacy ridisegnano i confini della responsabilità condivisa nella filiera del recupero crediti: non basta nominare un responsabile del trattamento, occorre vigilare sul suo operato e informare il titolare del trattamento. In ambito recupero crediti, ecco il principio che ispira i provvedimenti dell'Autorità
Inside Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer
We analyze Qilin ransomware’s new custom Rust loader, its kernel-level EDR killer, and how organizations can defend against them.
Inside the Search for "Clean" Residential Proxies for Carding
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.
Meglio prima che mai!
Quando la sicurezza cyber non è collocata come priorità su una linea temporale di intervento, è inevitabile che prima o poi la gestione stessa di questo aspetto inizierà a risentirne, sia per accumulo del debito tecnologico sia per aumento dell'incertezza ed aumento della probabilità di subire attacchi
CyberCUBE: la cyber security spaziale passa dalla compliance ai test in orbita
Il 7 luglio un satellite CubeSat è entrato in orbita per farsi “attaccare”. Non è una stranezza: è la risposta dell'ESA a un problema che, chi lavora nella governance del rischio cyber, conosce fin troppo bene: la distanza tra le contromisure scritte nei documenti e la prova che funzionino davvero
Dairy company Fairlife suspends production in US after cyber incident
Navigate360 and P3 Global Intel: From the promise of “20+ years and zero violations” to three months of silence
Zelensky appoints Ukraine's acting security service chief as acting defense minister
ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns
ClickFix attacks are increasingly being used by the UAC-0145 threat group to deliver malware, backdoors, and data-stealing tools.
The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks
The Cyber Express weekly roundup covers TikTok age checks, Partnered Health breach, Qantas review, Microsoft flaws, and major cyberattacks.
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
US Charges Two Over $43M Chinese Money Laundering Operation
Zhuoying Chen and another New York resident face charges over an alleged $43 million Chinese money laundering case.
Can a SIM card run malware?
Exploring SMS-triggered SIM Toolkit applets in a private GSM lab
Windows Server 2022 reach end of mainstream support in 90 days
Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years.
Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available
Notepad++ vulnerabilities fixed in v8.9.7 include PowerShell command injection and CVE-2026-52886, CVE-2026-54758.
Sanzione privacy a Wind Tre: il Garante porta la cyber al centro della compliance GDPR
La sanzione del Garante privacy a Wind Tre per due data breach mostra come la compliance all’articolo 32 del GDPR venga ormai valutata anche attraverso la qualità delle misure di cyber security. Dalla gestione delle credenziali alle API, la resilienza dei sistemi diventa il vero parametro di conformità
Una società di cyber security europea ha nascosto per anni i suoi collegamenti con la Russia
La società spagnola Passwork per anni ha tenuto i clienti all’oscuro di quanto il suo software fosse esposto alle analisi dei servizi segreti russi. Per farlo, ha perfino cercato di manipolare le informazioni elaborate dall’intelligenza artificiale
Passwork
4 offerte antivirus da non perdere a luglio 2026
Le offerte per i migliori antivirus propongono servizi utili a proteggere i propri dispositivi: ecco le promo imperdibili a luglio 2026.