Wyden blocks Rudd confirmation to lead Cyber Command, NSA
Previously harmless Google API keys now expose Gemini AI data
Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data.
Henry IV, Hotspur, Hal, and hallucinations
Intellexa founder, three others sentenced to 8 years in prison over Greek spyware scandal
Trend Micro warns of critical Apex One code execution flaws
Trend Micro has patched two critical Apex One vulnerabilities that allow attackers to gain remote code execution (RCE) on vulnerable Windows systems.
European DYI chain ManoMano data breach impacts 38 million customers
DIY store chain ManoMano is notifying customers of a data breach personal data, which was caused by hackers compromising a third-party service provider.
Critical Juniper Networks PTX flaw allows full router takeover
A critical vulnerability in the Junos OS Evolved network operating system running on PTX Series routers from Juniper Networks could allow an unauthenticated attacker to execute code remotely with root privileges.
Attacchi con la GenAI offensiva, compromessi oltre 600 firewall: come proteggersi
Amazon accusa criminali informatici russi di aver sferrato cyber attacchi via AI generativa offensiva al fine di violare oltre 600 firewall FortiGate di Fortinet. Ecco come mitigare i rischi di intrusione con la GenAI
DL Sicurezza e cyber: poteri, funzioni e finalità su sistemi digitali e flussi informativi
Il testo normativo del DL Sicurezza non introduce novità cyber, ma interviene sul perimetro di utilizzo di strumenti tecnologici e informatici da parte dello Stato. Ecco gli effetti rilevanti e le implicazioni nel dominio digitale
Google disrupts Сhina-linked cyberespionage campaign spanning dozens of countries
Spyware maker sentenced to prison in Greece for wiretapping politicians and journalists
A Greek court on Thursday sentenced the founder of Intellexa, a collective of spyware makers, to eight years in prison for illegal wiretapping and privacy
O ancora meglio: DL Sicurezza e cyber: poteri, funzioni e finalità su sistemi digitali e flussi informativi
Il testo normativo del DL Sicurezza non introduce novità cyber, ma interviene sul perimetro di utilizzo di strumenti tecnologici e informatici da parte dello Stato. Ecco gli effetti rilevanti e le implicazioni nel dominio digitale
Olympique Marseille confirms 'attempted' cyberattack after data leak
French professional football club Olympique de Marseille has confirmed a cyberattack after a threat actor claimed on Monday that it breached the club's systems earlier this month.
Ransomware payment rate drops to record low as attacks surge
The number of ransomware victims paying threat actors has dropped to 28% last year, an all-time low, despite a significant increase in the number of claimed attacks.
Apache ActiveMQ Exploit Leads to LockBit Ransomware
Key Takeaways An audio version of this report can be found on Spotify, Apple, YouTube, Audible, & Amazon. This intrusion began in mid-February 2024 after a threat actor exploited a vulnerability (CVE-2023-46604) on an exposed Apache ActiveMQ server. The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring […]
What to Know About the Notepad++ Supply-Chain Attack
A critical Notepad++ supply-chain flaw (CVE-2025-15556) enabled stealthy APT access. Understand the attack chain and how to defend your systems.
Cyber security industriale: gli elementi essenziali per creare un SOC ad alte prestazioni
Il SOC è il centro nevralgico della protezione informatica di un’organizzazione, che monitora, rileva e risponde continuamente alle minacce. Negli ambienti industriali è essenziale che sia proattivo e basato sull'intelligence, oltre il monitoraggio tradizionale. Ecco come realizzare un SOC ad alte prestazioni
After years of government cyber trouble, UK turns to automated scanning to speed fixes
Ransomware payment rate drops to record low as attacks surge
The number of ransomware victims paying threat actors has dropped to 28% last year, an all-time low, despite a significant increase in the number of claimed attacks.
Ransomware payments dropped in 2025 as attack numbers reached record levels: Chainalysis
Ransomware payments dropped in 2025 as attack numbers reached record levels: Chainalysis
Microsoft expands Windows restore to more enterprise devices
Microsoft now allows more enterprise users to restore their personal settings and Microsoft Store apps from a previous Windows 11 device.
New York sues Valve for promoting illegal gambling via game loot boxes
New York Attorney General Letitia James sued video game developer and publisher Valve Corporation for using game loot boxes to facilitate illegal gambling activities among children and teenagers.
PromptSpy ushers in the era of Android threats using GenAI
ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow.
L’IA cinese è un rischio per l’Europa: ma le Pmi hanno 3 motivi per preferire questi modelli
L'IA cinese pone il Vecchio Continente di fronte a una scelta strategica: chiudersi per timore della dipendenza tecnologica da Pechino o sfruttare questa opportunità per rafforzare la propria competitività digitale, soprattutto considerando che gli Stati Uniti potrebbero non rivelarsi più un partner affidabile come in passato
ENISA’s Updated Cybersecurity Methodology Aligns with NIS2 and EU Cybersecurity Act
New Dohdoor malware campaign targets education and health care
Cisco Talos discovered an ongoing malicious campaign since at least as early as December 2025 by a threat actor we track as “UAT-10027,” delivering a previously undisclosed backdoor dubbed “Dohdoor.”
Assalto al trono di Nvidia
Rivali che puntano a eroderne il dominio, startup innovative e la rincorsa cinese: il gigante fondato da Jensen Huang deve iniziare a guardarsi alle spalle
ANY.RUN & Splunk Enterprise: Stronger Detection, Faster Response in Your SOC
See how your SOC can accelerate monitoring, triage, and response with ANY.RUN by working inside Splunk Enterprise.
Samsung SDS Identifies Top Cybersecurity Threats of 2026 as AI Risks Escalate
Samsung SDS’s reveals the cybersecurity threats of 2026, highlighted by AI risks, ransomware, cloud misconfigurations, phishing, and data breaches.
Fiducia zero nell’AI: la convergenza tra verifica, sicurezza offensiva e disinformazione
Il nuovo numero della rivista IEEE Computer accende un faro sulla convergenza tra reti di agenti AI, la verifica dell'identità delle macchine e la resilienza dei sistemi cognitivi. Ecco tre risposte autorevoli e scientifiche alla domanda chiave del CISO, mentre la fiducia algoritmica non sarà più un attributo implicito, ma una metrica da verificare continuamente