Iranian drone strikes hit Amazon data centers in Gulf, disrupting cloud services
Amazon: Drone strikes damaged AWS data centers in Middle East
Amazon has confirmed that three Amazon Web Services (AWS) data centers in the United Arab Emirates (UAE) and one in Bahrain have been damaged by drone strikes, causing an extensive outage that is still affecting dozens of cloud computing services.
Star Citizen game dev discloses breach affecting user data
Cloud Imperium Games (CIG), the game developer behind Star Citizen and Squadron 42, says attackers breached systems containing some users' personal information in January.
Expanding Phishing Detection at Scale with Automatic SSL Decryption
Automatically decrypt HTTPS in ANY.RUN’s Interactive Sandbox to expose phishing faster and reduce SOC response time.
UH Cancer Center data breach affects nearly 1.2 million people
The University of Hawaii confirmed that a ransomware gang stole the data of nearly 1.2 million individuals in August 2025 after breaching its Cancer Center's Epidemiology Division.
Home Routers in Singapore Must Meet Higher Security Standards by 2027
CSA and IMDA will upgrade residential routers to CLS Level 2, enhancing mandatory cybersecurity requirements in Singapore by 2027.
Android: 129 vulnerabilità corrette, zero-day Qualcomm già sfruttata
Google ha rilasciato gli aggiornamenti di sicurezza Android di marzo correggendo 129 vulnerabilità, tra cui una falla zero-day già sfruttata in attacchi mirati. La vulnerabilità, tracciata come CVE-2026-21385, interessa un componente grafico sviluppato da Qualcomm e, secondo quanto comunicato nel bollettino ufficiale, sarebbe oggetto di “limited, targeted exploitation”, ovvero di uno sfruttamento limitato, ma su …
WinGet Desired State: Initial Access Established
NIS 2: coerenza, aggiornamento e tracciabilità del rischio digitale
Ogni documento si inserisce in un processo unitario e permanente, dove coerenza, aggiornamento e tracciabilità diventano il parametro reale con cui si misura il governo del rischio digitale
Android gets patches for Qualcomm zero-day exploited in attacks
Google has released security updates to patch 129 Android security vulnerabilities, including an actively exploited zero-day flaw in a Qualcomm display component.
Provecho - 712,904 breached accounts
In early 2026, data purportedly sourced from the recipe and meal planning service Provecho was alleged to have been obtained in a breach. The exposed data included 713k unique email address along with username and the creator account holders followed. Provecho has been notified and is aware of the claims surrounding the incident.
University of Hawaii Cancer Center Breach Exposes SSNs of 87,000+ Participants
UH Cancer Center cyberattack exposes research data at University of Hawaii, Impacting 87,493 MEC participants and 1.15M records.
Talos on the developing situation in the Middle East
Cisco Talos continues to monitor the ongoing conflict in the Middle East. As always, we will be watching closely for any cyber-related incidents that are tied to the conflict.
CyberStrikeAI tool adopted by hackers for AI-powered attacks
Researchers warn that a newly identified open-source AI security testing platform called CyberStrikeAI was used by the same threat actor behind a recent campaign that breached hundreds of Fortinet FortiGate firewalls.
Cyber Command disrupted Iranian comms, sensors, top general says
Cyber Command disrupted Iranian comms, sensors, top general says
Fake Google Security site uses PWA app to steal credentials, MFA codes
A phishing campaign is using a fake Google Account security page to deliver a web-based app capable of stealing one-time passcodes, harvesting cryptocurrency wallet addresses, and proxying attacker traffic through victims' browsers.
University of Hawaiʻi Cancer Center confirms data leak following ransomware attack
Alabama man pleads guilty to hacking, extorting hundreds of women
A 22-year-old Alabama man pleaded guilty to extortion, cyberstalking, and computer fraud charges after hijacking the social media accounts of hundreds of young women (including minors).
Una falla in Chrome sfrutta Gemini Live per scopi malevoli
Palo Alto, azienda specializzata in sicurezza informatica, ha scoperto una vulnerabilità nel browser Google Chrome avrebbe potuto trasformare l’assistente AI integrato in uno strumento di sorveglianza e furto dati. Il problema è stato segnalato a Google dopodiché è stata catalogata come CVE-2026-0628 e corretta a gennaio con il rilascio di Chrome 143. Il problema riguardava …
Escalation in the Middle East: Tracking “Operation Epic Fury” Across Military and Cyber Domains
Comprehensive Flashpoint analysis of the evolving U.S.–Israel military campaign against Iran and its multi-domain implications across the Middle East, including cyber threats and infrastructure targeting.
Guerre di Rete - L’AI va in guerra (c’era già, ma qualcosa è cambiato?)
Analisi di una crisi annunciata. E poi assalto a Nvidia.
Florida woman imprisoned for massive Microsoft license fraud scheme
A Florida woman was sentenced to 22 months in prison for running a massive years-long scheme to traffic thousands of stolen Microsoft Certificate of Authenticity (COA) labels.
Hacktivists claim to have hacked Homeland Security to release ICE contract data
A hacking group called Department of Peace said they hacked a specific office within Homeland Security to protest ICE’s mass deportation campaign, and the companies aiding it.
Iran, il blackout informativo come cyber sabotaggio: l’uso dell’AI in battaglia
L'operazione in Iran condotta da Usa e Israele vede una componente cyber e tecnologica fondamentale che ha agito da moltiplicatore di forza. Ecco com'è avvenuto l'isolamento digitale, quali sono i risvolti futuri e le cyber-ritorsioni
Alleged India-linked espionage campaign targeted Pakistan, Bangladesh, Sri Lanka
UK warns of Iranian cyberattack risks amid Middle-East conflict
The United Kingdom's National Cyber Security Centre (NCSC) alerted British organizations to a heightened risk of Iranian cyberattacks amid the ongoing conflict in the Middle East.
L’AI di Anthropic usata nei raid Usa contro l’Iran: la questione non è etica, ma istituzionale
L’escalation del braccio di ferro fra Anthropic e il Dipartimento della Guerra dell'amministrazione Trump ha avuto un esito imprevisto: l'impiego di Claude nella guerra in Iran, nonostante l'ordine esecutivo di Trump che ne vietava l'uso. Anche Palantir utilizza Claude
ClawJacked: quando un sito web prende il controllo del tuo agente AI
La vulnerabilità Clawjacked scoperta nel gateway WebSocket di OpenClaw rivela un vettore d'attacco silenzioso e ad alto impatto: una pagina web malevola può dirottare l’agente AI locale dello sviluppatore, registrarsi come dispositivo fidato e accedere a dati, log e configurazioni. Patch disponibile, ma il contesto è molto più ampio
How Deepfakes and Injection Attacks Are Breaking Identity Verification
Deepfakes and injection attacks are targeting identity verification moments, from onboarding to account recovery. Incode explains why enterprises must validate the full session—media, device integrity, and behavior—to stop synthetic and injected attacks in real time.
German court convicts alleged mastermind behind global investment scam network