House passes bill to equip local law enforcement with scam-fighting tools
Data Broker Radaris Loses Domains in Privacy Fight
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
Managed Detection & Response: perché la vera sfida oggi è personalizzare la detection
Nel settore finanziario, dove DORA e NIS2 impongono requisiti sempre più stringenti in materia di resilienza operativa, un MDR standard può non essere sufficiente. Il progetto sviluppato da Certego insieme a TrendAI mostra come trasformare la telemetria degli endpoint in intelligence operativa, migliorando detection e capacità di risposta
Spain reports first alleged AI-powered data theft attack
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
International Meteor Organization says cyberattack dealt ‘critical blow’ to website
Supply chain cyber risk: come AI e automazione stanno cambiando il Vendor Risk Management
La NIS2 impone di estendere la gestione del rischio anche ai fornitori. Il progetto SupplyShield di Arsenalia mostra come trasformare il Third Party Risk Management da processo manuale e frammentato a modello continuo, automatizzato e integrato con i processi aziendali, grazie ad AI, threat intelligence e integrazione nativa con SAP
Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts
Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts
I costi del downtime industriale da attacco cyber: come quantificare l’impatto economico dei blocchi di produzione
Il downtime causato da un attacco cyber può trasformare rapidamente un incidente OT in una perdita economica rilevante. Mancata produzione, ripristino, penali e danni alla supply chain devono essere misurati per quantificare il rischio e definire investimenti efficaci in resilienza
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery.
Flock camera use by internal affairs unit puts DC police at odds with officers’ union
Flock camera use by internal affairs unit puts DC police at odds with officers’ union
EU chief wants joint response to cyberattacks, sabotage
From Alert Triage to Threat Hunting: The New SOC Analyst Priority
Ask what changed on the shift schedule, and the answer usually gets a lot less clear. I want to talk about the part that gets less attention: when that work actually happens. Only 33% say they actually discover incidents that way ( Devo/Wakefield, April 2025 ). 47% of organizations still discover incidents primarily through alerts ( Devo/Wakefield, 2025 ), so the old scheduling logic is still running underneath even where AI triage sits in front of it. Microsoft describes its own agentic SOC model in a similar way, saying analysts move “from triaging alerts to supervising outcomes.” I like that phrasing because it gets at the real shift. What the Week Actually Looks Like Now In practice, four things need to replace what the queue used to do: protected hunt blocks, AI-output review loops with clear depth, escalation paths for ambiguity, and handoffs that carry reasoning instead of ticket counts. Rhythm element Cadence (illustrative) What it produces What it replaces Hunt block Two protected hours, twice a week, per analyst, scheduled like an on-call shift A written hypothesis and a recorded result Hunting when the queue happens to be quiet AI-output review loop Every shift, depth set by consequence, not a fixed sampling percentage Agent verdicts confirmed or overturned, with the reason attached Rubber-stamping, or re-doing the agent's work Escalation window A standing slot per shift plus a named path for ambiguity A second opinion on the unclear, not just the severe Escalation routed by ticket severity Shift handoff 15 minutes, structured on reasoning The next analyst starts where you stopped Open ticket counts and tool status Hunt blocks are calendar objects, not intentions Hunting that gets scheduled happens. Unprotected time is exactly what a staffing shortage, customer escalation, or noisy day will eat first. Hunt time needs the same treatment. Case management is the top unmet capability gap Devo/Wakefield respondents named, at 77% ( Devo/Wakefield, 2025 ). Review loops need defined depth, not a spot-check percentage AI review does not make analyst attention disappear. Review depth should follow consequence, not a fixed sample rate. A mixed-methods study of explainable AI in SOCs found that analysts sometimes accepted lower-accuracy outputs when the explanation looked evidence-based, and that they preferred contextual depth over dashboard summaries ( Rastogi et al., arXiv, July 2025 ). Set review depth by consequence. Escalation paths built for ambiguity, not severity Queue-era escalation ran on severity because severity was the main signal a ticket carried. Analysts at 84% of organizations unknowingly re-investigate the same incident multiple times a month, and 60% of those teams do it weekly or more ( Devo/Wakefield, 2025 ). 85% of analysts already spend substantial time manually gathering and connecting evidence into a case ( Devo/Wakefield, 2025 ). That is the work that gets repeated when the next analyst has to reconstruct the story. Without hunt blocks, defined review depth, and a real escalation path, the hours an agent frees up do not automatically become better investigations or more careful review. I have run delivery organizations at scale, and I have seen what happens instead: the open time gets swallowed by whatever is loudest that day. Fewer than one-third of organizations use AI for automated alert triage, and 36% use it for enrichment ( Devo/Wakefield, 2025 ). That is the harder half of this problem, and it is where SOC leaders need to spend real time next.
Ukraine moves to crack down on scam call centers after corruption scandal
CenterPoint Energy Tells SEC Customer Data Was Stolen After 7.5Mn Records Advertised Online
CenterPoint Energy told the SEC that customer data was stolen via an external-facing system after a forum post advertised about 7.5 million utility records.
Falso “Bonus Vacanze” dell’Agenzia delle Entrate ruba dati personali
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse.
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users.
Critical ScreenConnect flaw now actively exploited in attacks
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Caso Revolut, il giallo dei dati istituzionali italiani sottratti dai criminali
Il caso Revolut porta dentro le infrastrutture istituzionali italiane: una PEC riconducibile alla Prefettura di Reggio Calabria sarebbe stata compromessa e gli attaccanti rivendicano 147 GB di dati sottratti alle forze dell’ordine. Un dato ancora da verificare, ma che sposta l’indagine dalla fintech alla sicurezza dei sistemi dello Stato
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.
10 Best Brand Protection Solutions (Ranked and Compared)
Compare the 10 best brand protection solutions of 2026 — Cyble, BrandShield, Red Points, and more — to find the right fit for your threat profile.
VPN illimitata e sicura per 12 mesi: è il momento di attivare Total VPN per proteggere traffico, banda e privacy
VPN Illimitata e sicura per 12 mesi: quanto costa Total VPN, come si richiede e quali sono i servizi inclusi tra banda, cifratura e privacy
The MRI Scan That Wasn’t: Inside Iran’s ‘Chosen Brick’ Malware Campaign Against Its Critics Abroad
NCSC, FBI and AIVD expose CHOSEN BRICK, Iranian spyware that hijacks microphones and messaging apps to hunt dissidents, activists and journalists worldwide.
Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center
Ukraine cybersecurity coordination gets a new leader as Ihor Klymenko is appointed to head the National Cybersecurity Coordination Center.
Manhattan D.A. Seizes 12 Deepfake Porn Websites Targeting 1,200 People
Manhattan District Attorney seizes 12 domains linked to AI-generated deepfake videos involving approximately 1,200 people.
Apple Patches 273 Vulnerabilities as iOS 26.7 Rolls Out
Apple security update iOS 26.7 patches 273 vulnerabilities across iPhone, iPad, and Mac. Here's what iPhone users need to know before updating.
Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout
Pakistan's CSWC finalizes a cybersecurity action plan spanning 90 days to launch a Federal CERT, provincial CERTs, and a national cyber framework.
ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response
Eliminate context switching, accelerate incident response, and drive higher ROI by integrating ANY.RUN in your SentinelOne workflows.