FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation.
Data Center Physical Security: Mitigating FPV Drone Threats
We explore how shifting online sentiment and low-cost FPV technology are creating an unprecedented airborne threat vector.
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity
Poland uncovers second heat plant cyberattack that went hidden for months
Russian military hackers pose as recruiters to target Ukrainian IT workers
AI, ora controlli preventivi sui modelli: il blocco di Astra, le regole di Trump
Gli Usa procedono con cautela contro il rischio incontrollato dell'AI. OpenAI ha sospeso parte delle attività interne sul nuovo modello Astra, per pericoli cybersecurity. Il Governo Trump sperimenta un patto volontario per la sicurezza AI. Si cerca un difficile equilibrio tra sicurezza e innovazione, con conseguenze globali
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies.
British ‘Com’ member who abused more than 100 girls worldwide jailed for two years
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams
A ransomware incident response plan helps teams prepare for rising attacks. Explore 2025-2026 ransomware data, RaaS threats, recovery and prevention.
Member of The Com sent to prison for blackmail, sextortion
A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide.
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
New Zealand sanctions Russian hackers, propaganda groups over Ukraine war
LexisNexis shuts down services after suspicious activity on servers
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor.
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics.
InPost, mancano dati per la consegna. Ma è phishing!
Nella giornata odierna il team anti-frode D3Lab ha individuato un sito di phishing riproducente la grafica di InPost, note servizio di consegna basato su locker sparsi su tutto il territorio nazionale.
Pagina di phishing principale
Comunicando l'impossibilità di effettuare una consegna
IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
Suisun City Declares Emergency After Cyberattack Disrupts Systems
Suisun City Emergency declared after a cyberattack disrupts IT systems, affects 911 routing and prompts a federal investigation into the attack.
NIS2 e gestione incidenti: dall’impatto operativo al costo del fermo e alle decisioni di business
La gestione degli incidenti non può essere considerata solo una procedura tecnica di risposta. In ottica NIS2, deve diventare un processo decisionale capace di collegare evento cyber, attività impattate, servizi IT coinvolti, fornitori, continuità operativa, comunicazioni e costo del fermo
Cifratura dei dati e reti VPN: le architetture avanzate per la protezione dei flussi
Per chi cerca la massima sicurezza per la sua VPN, ProntoVPN ha un'offerta dedicata: a 2,99 euro al mese sono tanti i servizi da scoprire.
ATED // Cyber Security Day 2026
L’associazione ATED di Lugano mi ha invitato anche quest’anno all’evento Cyber Security Day. È la mia seconda partecipazione (nella pagina dedicata alle conferenze trovate i detta…
Ransomware Kingpin Gets 16 Years for Global Cyberattacks
Ransom Cartel ransomware creator Maksim Silnikau has been sentenced to 16 years in prison over an international ransomware scheme.
AI Agent Exploits Gym System Vulnerability, Cancels Waitlist Booking in Australia
An AI agent exploited a gym system vulnerability in Australia, cancelling a waitlisted booking and raising concerns over AI safety, security, liability.
Gestione delle password aziendali: gli standard per azzerare i rischi di intrusione
NordPass offre servizi per la gestione delle password aziendali e dire basta agli accessi abusivi: per l'estate è previsto lo sconto del 50%
Hotel nel mirino: perché il settore alberghiero è un cyber-bersaglio facile
Dal furto di documenti d'identità nei check-in italiani alle campagne contro gli hotel di Milano-Cortina, fino alla violazione di Booking.com: tre episodi diversi raccontano la stessa vulnerabilità strutturale, che le regole attuali intercettano solo in parte.