ChatGPT Sandbox Flaw Let a Planted Prompt Ship Victim’s Gmail Data to Another Account
Check Point found a ChatGPT sandbox flaw that let planted prompts move a victim's Gmail data to an attacker's account through a shared Artifactory cache.
Man gets 15 years for extorting women with AI-generated porn videos
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content.
L’AI non sfugge all’uomo, si fa più capace. Cosa ci insegna il caso OpenAI-Hugging Face
Si è acceso il dibattito nella comunità degli esperti di intelligenza artificiale circa la capacità di questo modelli di colpire obiettivi sensibili in totale autonomia. Quanto c'è di vero e, soprattutto, come regolamentare l’autonomia degli agenti AI
New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates.
Google warns of new Chrome zero-day bug exploited in attacks
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth.
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
The EU CRA's Real Question: What Shipped, and When Did You Know?
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements.
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
Microsoft releases Windows 10 KB5122878 extended security update
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes.
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
Robotica collaborativa e sicurezza dei Cobot: la tutela dei flussi operativi nelle linee ad alta automazione
La robotica collaborativa porta persone e macchine a condividere spazi e processi produttivi. Ma Cobot connessi, sensori e software ampliano anche il rischio cyber: proteggere reti, firmware e logiche di controllo diventa essenziale per garantire sicurezza degli operatori e continuità della produzione
August updates trigger 0xc0000409 errors on Windows Server 2016
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled.
Sycophancy nell’AI: quando l’algoritmo ci dà ragione anche se stiamo sbagliando
Cos’è la Sycophancy nell’AI e perché gli LLM tendono ad assecondare l’utente? Ecco come il bias di conferma può trasformarsi in rischio cyber e come mitigarlo
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.
Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet
A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries,