Why the Supreme Court's Chatrie case could change the meaning of privacy in America
Commissione europea: la classificazione dei sistemi di AI ad alto rischio in linea con l’AI Act
La Commissione europea ha elaborato le linee guida, al momento in bozza, riguardanti la classificazione dei sistemi di intelligenza artificiale ad alto rischio conformemente all’AI Act. Ecco perché è un punto di arrivo importante
Canadian man arrested, charged for running KimWolf DDos botnet
Sintesi riepilogativa delle campagne malevole nella settimana del 16 – 22 maggio
L’attacco cyber non è come il morbillo!
L'erronea convinzione che essere stati vittima di un attacco cyber, o più in generale di una violazione, faccia diminuire la probabilità che questa si ripeta in futuro non solo è profondamente erronea, ma espone ancor più le organizzazioni a subire nuovi disastri cyber
Trend Micro warns of Apex One zero-day exploited in the wild
Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems.
Password in chiaro e disclosure ritardate: ecco perché il Garante sanziona Ambrosetti
Il provvedimento del Garante Privacy nei confronti di The European House – Ambrosetti nasce da una violazione di dati personali notificata dalla società nell’aprile 2024 a seguito di un accesso non autorizzato ai propri sistemi, ma è di natura più culturale che meramente tecnica. Ecco i motivi della sanzione
Why Chargebacks are Just One Piece of the Fraud Puzzle
Fraud losses don't stop at chargebacks. False declines, account takeovers, and abuse also damage revenue and trust. IPQS breaks down why fraud teams need broader visibility into risk and customer impact.
Drupal: Critical SQL injection flaw now targeted in attacks
Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week.
Belarus-linked hackers use fake training certificates to target Ukrainian officials
Ubiquiti patches three max severity UniFi OS vulnerabilities
Ubiquiti has released security updates to patch three maximum severity vulnerabilities in Unify OS that can be exploited by remote attackers without privileges.
The Cyber Express Weekly Roundup: Supply Chain Breaches, AI Content Enforcement, And Event Disruption Attacks
The Cyber Express weekly roundup highlights cybersecurity threats, AI misuse, supply chain attacks, and global incidents in 2026.
Belarus-linked hackers use fake training certificates to target Ukrainian officials
AI-Powered Marketing Service “Active Listening” Deceived Customers: FTC
The pitch for "Active Listening," an AI-powered advertising service that listened to consumers' real-world conversations through their smartphones and smart
Vulnerability Exploitation Overtakes Stolen Credentials in AI-Driven Cyberattacks
Beyond vulnerability exploitation, the DBIR identified major changes in social engineering tactics.
Hackers steal patient and billing data from German hospitals via third-party provider
Kaspersky: gli agenti IA cambiano la fiducia aziendale
Da ChatGPT contraffatto a OpenClaw, gli attaccanti sfruttano la corsa all’IA. Per Dmitry Galov, però, non bisogna fermare l’adozione degli agenti ma renderla controllata, verificabile e sicura.
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
The experienced Cloud Atlas group remains active, continuing to target government sectors and diplomatic entities in Russia and Belarus, employing both new and established techniques.
Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems
Microsoft confirms active exploitation of CVE-2026-41091 and CVE-2026-45498 in Defender, with CVSS-rated risks, KEV listing, and urgent patches issued.
Cyber security in boardroom: comunicare il rischio ai vertici
Le boardroom devono imparare a leggere il rischio cyber come un rischio d’impresa trasversale, integrandolo nei processi decisionali strategici e smettendo di confinarlo ai reparti IT. Ecco come, alla luce delle normative europee come NIS2, GDPR, DORA e AI Act
Online Payment Fraud Prevention: Best Practices for Organizations
A practical guide to online payments fraud prevention: map risks, layer signals, and measure impact while keeping approval rates high and friction low.
Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems
Microsoft confirms active exploitation of CVE-2026-41091 and CVE-2026-45498 in Defender, with CVSS-rated risks, KEV listing, and urgent patches issued.
US and Canada arrest and charge suspected Kimwolf botnet admin
U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide.
European Agencies Shutter VPN Service Used for Ransomware Attacks
Under the banner name "Operation Saffron," the authorities shuttered 33 critical servers of the First VPN service provider during the seizure and detained the alleged administrator of the service in Ukraine, in a coordinated operation.
Il rischio informativo: ecco perché il sistema di produzione e distribuzione di contenuti è instabile
In un sistema aperto, veloce e dispersivo, in cui ogni informazione può essere modificata lungo il percorso, il rischio informativo non è un evento eccezionale, ma una condizione strutturale. Vediamo cosa è in gioco
EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks
Financial Services DDoS Attacks surge as AI botnets target banks across EMEA and global financial networks.
Cisco Secure Workload Flaw CVE-2026-20223 Gets Maximum CVSS 10 Rating
Cisco patches CVE-2026-20223, a critical Secure Workload REST API flaw tied to CWE-306 that could expose sensitive tenant data.
INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks
INJ3CTOR3 deploys JOMANGY and ZenharR malware toolkit in a self-healing campaign targeting vulnerable FreePBX systems globally.
Data poisoning nei modelli AI: rischi e soluzioni di remediation
Secondo uno studio, modificare lo 0,1% del dataset di addestramento per ottenere effetti misurabili sul comportamento del modello. Una volta avvenuto, l'avvelenamento è difficile da rimediare. Ecco come mitigare il rischio di attacco di data poisoning su un modello di machine learning
UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal
The Government Office for Technology Transfer played a key role in helping the NCSC bring the cyber security device to market.