Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Claude supera i confini dei test: Anthropic rallenta e ripensa la sicurezza dell’AI
Dopo gli incidenti in cui alcuni modelli Claude hanno raggiunto sistemi reali durante test cyber, Anthropic ha sospeso parte delle valutazioni e rafforzato sandbox, monitoraggio e controlli. Il caso mostra perché la sicurezza dell'AI agentica non può dipendere da un'unica barriera
Clonazione account WhatsApp su iPhone: abbiamo replicato l'exploit e segnalato a Meta
Clonazione account WhatsApp su iPhone: abbiamo replicato l'exploit zero-click e lo abbiamo segnalato a Meta. Come agisce e come proteggersi.
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing
Threat actors are leveraging prepackaged, safeguard-free AI, weaponizing stolen session data, and directly targeting defenders’ security stacks.
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions.
China-Linked Fire Ant Turned Cisco Routers, TACACS Servers Into Espionage Platforms
The China-nexus espionage group Fire Ant has moved from compromising virtualization platforms to implanting Cisco IOS XR routers and TACACS authentication servers.
Il tuo nuovo sviluppatore lavora per Pyongyang: i rischi dell’onboarding remoto
Un attaccante non deve violare la rete se può farsi assumere come sviluppatore, ricevere un laptop aziendale e ottenere credenziali valide. Le infiltrazioni di lavoratori IT nordcoreani mostrano il punto cieco dell’onboarding remoto: la cybersecurity autentica dispositivi e accessi, ma troppo spesso presume l’identità della persona
Iranian cyber spies target aviation, fintech developers with new malware
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.
Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns
RWA e tokenizzazione on-chain nel 2026: T-Bills, azioni tokenizzate e i provider da conoscere
Guida tecnica alla tokenizzazione degli RWA nel 2026: come funzionano i T-Bill on-chain e le azioni tokenizzate, i provider più rilevanti (BUIDL, BENJI, Ondo, xStocks, Dinari, Robinhood) e i vantaggi rispetto a un broker tradizionale.
I migliori wallet per criptovalute nel 2026: guida tecnica completa
Guida tecnica ai migliori wallet crypto del 2026: confronto tra Rabby, Rainbow, Phantom, Trust Wallet ed Exodus, più hardware wallet e soluzioni multisig, con link ufficiali e best practice di sicurezza.
Gli Stack perfetti per siti web e landing page nel 2026
Guida tecnica agli stack più usati per costruire landing page nel 2026: Astro, Next.js, SvelteKit, Nuxt, Eleventy e htmx, con librerie UI, CMS headless e analytics open source, tutti con link ai repository GitHub ufficiali.
Mac Mini M5 Pro: perché l'architettura a memoria unificata cambia le regole del training locale di LLM
Con M6 e M5 Pro il nuovo Mac mini porta i Neural Accelerators sulla scrivania: cosa significano davvero per il fine-tuning locale di LLM, tra benchmark ufficiali Apple e i limiti che nessuno vi dice.
Meta paga 17 miliardi e vince: la sicurezza dei minori online e il paradosso dell’age assurance
Per verificare l'età degli utenti servono informazioni sufficienti a distinguere adulti e minorenni. Il caso Meta apre così una questione destinata ad andare oltre i social: come applicare l’age assurance senza trasformarla in un'infrastruttura capace di identificare e classificare tutti
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks.
Colleferro, Bulgaria e Lipsia: cosa c’è davvero dietro gli attacchi con droni, sabotaggi e disinformazione
Una delle piste da verificare è l'ipotesi di un possibile sabotaggio di matrice russa. Ecco il fil rouge che lega una serie di eventi analoghi verificatisi nelle stesse settimane a Colleferro in Italia, in Bulgaria, a Lipsia in Germania e in Francia
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Nei servizi di ascolto e segnalazione per soggetti vulnerabili, il “pulsante di aiuto” sui siti web degli Enti del terzo settore non è una pagina di contatti. Ecco il perimetro giuridico del problema, le 4 posizioni soggettive coinvolte e il rapporto fra anonimato e possibilità concreta di prestare aiuto
Ionos e il commercio elettronico per le PMI: come l’integrazione di IA e sicurezza Cloud trasforma la creazione dei negozi online
Ionos propone la sua offerta E-Commerce Plus, permettendo di aprire un negozio online con IA a 1 € al mese: ecco come funziona e cosa fare.
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk
Explore major cyber attacks from August 2026 targeting US and EU organizations, including session hijacking, remote access threats and insider risk.
Questel - 1,226,209 breached accounts
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
Vulnerability & Patch Roundup — August 2026
Discover important WordPress vulnerabilities in August 2026 and how to safeguard your site with essential security updates.
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million.
Five plead guilty in latest federal ATM jackpotting case
Fraudsters steal $6 million from Tectonic crypto platform after inflating token price
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.