US charges Iranians for sprawling hacking campaign on government agencies, universities
Microsoft fixes known issue causing Windows Defender crashes
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems.
Hunt Malware & Phishing Threats with ANY.RUN for Proactive Enterprise Security
Learn how ANY.RUN helps SOC teams hunt malware and phishing threats to strengthen enterprise security.
Critical RCE flaw in Windows IKE Extension now actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component.
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
La protezione dell’identità digitale e delle credenziali: il ruolo dei password manager crittografati contro le violazioni dati
Proton Pass offre un servizio di gestione delle password con crittografia end-to-end a 2,49 € al mese: ecco come funziona e come si attiva.
La protezione della rete domestica multipiattaforma: l’impatto dei servizi VPN a dispositivi illimitati sulla cybersecurity
Surfshark offre la VPN per dispositivi illimitati a 2,49 €, aggiungendo anche 3 mesi extra gratis: ecco come funziona l'offerta e come averla
Windows 11 24H2 Home and Pro reach end of support in 2 months
Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months.
Quando la prassi sostituisce la procedura: la lezione per le imprese
Una recente sentenza del Tribunale di Udine mostra che l’ente produce policy e linee guida, ma l'operatività quotidiana si sviluppa attraverso relazioni organizzative differenti, costruite su rapidità decisionale, consuetudini operative e tolleranze manageriali. Ecco perché la sentenza assume rilievo per privacy, cyber security e governance
UT San Antonio Shuts Systems, Delays Classes After Cyber Incident
A UT San Antonio cyber incident has delayed fall classes to August 24 after attempted unauthorized activity disrupted university technology systems.
UK Cybercrime Journal: Carding Tactics & Youth Money Muling
What Happened Recent operational successes by UK law enforcement have exposed sophisticated domestic carding networks and the growing threat...
CISA: Medusa ransomware hit over 500 critical infrastructure orgs
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.
Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking
Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities.
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
GitLab patches CVE-2026-19478 and CVE-2026-19650, addressing critical and high-severity flaws affecting self-managed CE and EE instances.
Il problema non è il fattore umano. Perché il modello cyber va ripensato
Il nodo della cyber security non è la persona che sbaglia, ma un modello di sicurezza non allineato ai flussi di lavoro reali. Quando i processi sono complessi e poco usabili, la sicurezza viene aggirata invece di essere adottata. Ma anche la formazione deve cambiare
What Is PreCrime?
Explore how PreCrime uses predictive AI to stop cyberattacks before they start, going beyond reactive defenses to safeguard brands, domains, and digital assets.
Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender
ARMA cyberattack has disrupted Ukraine's asset recovery agency as officials investigate possible interference linked to the IDS Ukraine.
Oz Hair and Beauty - 1,988,331 breached accounts
In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.
Fanlore - 144,520 breached accounts
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.
Comcast turns your Xfinity WiFi into a home motion detector
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors.
More than 200 victims of Medusa ransomware identified over the last year, CISA says
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files.
Berlin cuts two state ministries off government network after security breach
University of Texas forced to take systems offline in San Antonio after cyberattack
Hackers target Ukrainian agency managing assets seized from sanctioned Russians
Your Controls Block Known Attacks. What About the Behavior?
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps.
Pulire github
Negli anni ho preso l’abitudine di creare subito un progetto su git (private o public, dipende dal progetto) appena mi viene una mezza idea e spesso nelle ore successive butto giù appunti, te…
Furto di identità via phishing Wise
Nella giornata odierna il team anti-frode D3Lab ha rilevato la settima campagna di phishing dell'anno a danno dei clienti italiani di Wise, servizio per il trasferimento di denaro a livello globale, con bassi costi di trasferimento e di cambio.
Campagne di phishing a danno degli utenti italiani W
Behavioural AI: FAQ & Myths
Ukrainian software developer faces 12 years in Swiss ransomware trial