Sintesi riepilogativa delle campagne malevole nella settimana del 14 – 20 febbraio
Why the shift left dream has become a nightmare for security and developers
The "shift left" approach has increased pressure on developers, as speed demands override security checks in modern CI pipelines. Qualys explains how analyzing 34,000 public container images revealed 7.3% were malicious and why security must be enforced at the infrastructure layer by default.
Musk and X launch legal appeal against EU’s record €120 million fine
Russia stepping up hybrid attacks, preparing for long standoff with West, Dutch intelligence warns
PayPal discloses data breach that exposed user info for 6 months
PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year.
Hackers breach contractor linked to Ukraine’s central bank collectible coin store
Mississippi medical center closes all clinics after ransomware attack
The University of Mississippi Medical Center (UMMC) closed all its clinic locations statewide on Thursday following a ransomware attack.
The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape
AI-driven fraud, GDPR probes, ransomware, and deepfake risks reshape global cybersecurity in this week’s Cyber Express roundup.
French National Bank Authority Breach Exposed 1.2 Million Accounts
French national bank authority confirmed a major data breach affecting 1.2 million bank accounts after a malicious actor stole credentials belonging to a
Operation Olalampo: Inside MuddyWater’s Latest Campaign
FBI: Over $20 million stolen in surge of ATM malware attacks in 2025
The FBI warned that Americans lost more than $20 million last year amid a massive surge in ATM "jackpotting" attacks, in which criminals use malware to force cash machines to dispense money.
What Big Tech Leaders Said On AI’s Future at India AI Impact Summit 2026
While global CEOs discussed capability growth, the panel on Responsible AI at Scale shifted attention to emerging cyber risks.
Cyberattack Forces Clinic Closures, Surgery Cancellations at University of Mississippi Medical Center
A UMMC cyberattack forced clinic closures, surgery cancellations and IT shutdowns as federal agencies investigate the breach.
Two Petabytes Worth Data of Israeli’s Siphoned, Says Cyber Head
Israel data breach reaches two petabytes as Yossi Karadi warns phishing rose 35% and cyber influence attacks surged 170% in 2025.
ClickFix: la nuova frontiera del social engineering, tra DNS e Google Ads
È stata identificata una nuova variante del malware ClickFix che, usando lo staging via DNS per distribuire payload su sistemi Windows e Google Ads per indurre le vittime a eseguire comandi malevoli, sta di fatto trasformando l’utente nel vero vettore di infezione. Ecco tutti i dettagli
Ukrainian gets 5 years for helping North Koreans infiltrate US firms
A Ukrainian national was sentenced to five years in prison for providing North Korean IT workers with stolen identities that helped them infiltrate U.S. companies.
Indicatori di compromissione
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
La compliance che non protegge. Quando il GDPR resta solo sulla carta
Il GDPR diventa inefficace se ridotto a un insieme di adempimenti scollegati dalle decisioni che modellano realmente l’organizzazione. Da sola, la conformità formale non è una garanzia. Ecco come trasformare la compliance in tutela effettiva delle persone e in qualità reale delle organizzazioni
CarMax - 431,371 breached accounts
In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt. The data included 431k unique email addresses along with names, phone numbers and physical addresses.
Leading Japanese semiconductor supplier responding to ransomware attack
PromptSpy is the first known Android malware to use generative AI at runtime
Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google's Gemini model to adapt its persistence across different devices.
PromptSpy is the first Android malware to use generative AI at runtime
Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google's Gemini model to adapt its persistence across different devices.
Cellebrite cut off Serbia citing abuse of its phone unlocking tools. Why not others?
Cellebrite, which makes phone unlocking and hacking tools, stopped sales to countries that allegedly abused its tools. But after new allegations in Jordan and Kenya, the company has changed its approach.
FBI: More than 700 ATM jackpotting incidents with losses over $20 million occurred in 2025
Researchers warn Volt Typhoon still embedded in US utilities and some breaches may never be found
West Virginia sues Apple for alleged child sexual abuse material failures
Using AI to defeat AI
In this week’s newsletter Martin considers how defenders can turn offensive AI tools against themselves.
Google blocked over 1.75 million Play Store app submissions in 2025
Google says that through 2025, it blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data and rejected over 1.75 million apps from being published on Google Play due to policy violations.
UK to require tech firms to remove nonconsensual intimate images within 48 hours or face fines
Attacco hacker cinese al Viminale: una violazione mirata per esfiltrare identità di agenti Digos
La violazione, definita "mirata" e non distruttiva - finalizzata cioè all'acquisizione silenziosa di informazioni strategiche piuttosto che al sabotaggio dei sistemi -ha comportato l’esfiltrazione di dati relativi a circa 5mila agenti della Digos. Ecco cosa sappiamo