UK plans sweeping overhaul of policing amid surge in online crimes
Have I Been Pwned: SoundCloud data breach impacts 29.8 million accounts
Hackers have stolen the personal and contact information belonging to over 29.8 million SoundCloud user accounts after breaching the audio streaming platform's systems.
AI nella cyber security: tra opportunità di difesa e nuovi rischi per la sicurezza digitale
L’AI può diventare da minaccia ad alleata, trasformandosi in un moltiplicatore di forza per la sicurezza informatica, purché sia abbinata al pensiero critico, a misure di sicurezza etiche e a una supervisione umana informata
Your Cloud(s). Adversaries’ Chance At Control
I primi minuti di un incidente di sicurezza come fondamento della prova forense
La qualità e la spendibilità di una prova forense si giocano nei primi minuti successivi alla scoperta dell’incidente. Ecco il ruolo decisivo del tempo, della volatilità dei dati e dei comportamenti iniziali, e come come azioni banali possano preservare o distruggere le evidenze in maniera irreversibile
HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns
Kaspersky researchers analyze updated CoolClient backdoor and new tools and scripts used in HoneyMyte (aka Mustang Panda or Bronze President) APT campaigns, including three variants of a browser data stealer.
SoundCloud - 29,815,722 breached accounts
In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform. The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, usernames, avatars, follower and following counts and, in some cases, the user’s country. The attackers later attempted to extort SoundCloud before publicly releasing the data the following month.
New malware service guarantees phishing extensions on Chrome web store
A new malware-as-a-service (MaaS) called 'Stanley' promises malicious Chrome extensions that can clear Google's review process and publish them to the Chrome Web Store.
Google agrees to pay $68 million to settle voice recording lawsuit
Here’s the tech powering ICE’s deportation crackdown
From phone spyware and facial recognition to phone unlocking technology and databases and more, this tech powers Trump's deportation machine.
New ClickFix attacks abuse Windows App-V scripts to push malware
A new malicious campaign mixes the ClickFix method with fake CAPTCHA and a signed Microsoft Application Virtualization (App-V) script to ultimately deliver the Amatera infostealing malware.
Supreme Court to hear Facebook pixel tracking case
Supreme Court to hear Facebook pixel tracking case
Microsoft patches actively exploited Office zero-day vulnerability
Microsoft has released emergency security updates to patch a high-severity Office zero-day vulnerability exploited in attacks.
Digital Networks Act (Dna): i punti chiave su cyber security e protezione degli utenti
Connettività, investimenti infrastrutturali e resilienza digitale sono gli aspetti principali del Digital Networks Act, proposto dalla Commissione europea il 21 gennaio 2026, mira a sostituire il Codice europeo delle comunicazioni Elettroniche del 2018. Ecco le disposizioni rilevanti in materia di cyber security e protezione degli utenti
Cloudflare misconfiguration behind recent BGP route leak
Cloudflare has shared more details about a recent 25-minute Border Gateway Protocol (BGP) route leak affecting IPv6 traffic, which caused measurable congestion, packet loss, and approximately 12 Gbps of dropped traffic.
EU launches investigation into X over Grok-generated sexual images
The European Commission is now investigating whether X properly assessed risks before deploying its Grok artificial intelligence tool, following its use to generate sexually explicit images.
Judge awards British critic of Saudis $4.1 million, finds the regime hacked his devices
Data Act, c’è un aggiornamento delle FAQ: cosa cambia per aziende e utenti
La Commissione Europea aggiorna le FAQ sul Data Act, fornendo chiarimenti pratici su accesso e uso dei dati, interoperabilità dei servizi digitali e rispetto delle norme UE, tra cui il GDPR, per supportare aziende e professionisti nella compliance e nella gestione sicura dei dati. Tutto quello che c’è da sapere
Stanley — A $6,000 Russian Malware Toolkit with Chrome Web Store Guarantee
A new malware toolkit called 'Stanley' spoofs websites while keeping the address bar intact and guarantees Chrome Web Store approval.
Russian state hackers likely behind wiper malware attack on Poland’s power grid
Nearly 800,000 Telnet servers exposed to remote attacks
Internet security watchdog Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils telnetd server.
6 Okta security settings you might have overlooked
Okta misconfigurations can quietly weaken identity security as SaaS environments evolve. Nudge Security shows six Okta security settings teams often overlook and how to fix them.
Romania probes two suspects over alleged hitman-for-hire website
C’è Sandworm dietro l’attacco contro il settore energetico polacco
I ricercatori di ESET hanno scoperto che il tentativo di attacco contro le infrastutture del settore energetico in Polonia sarebbe opera di Sandworm.
Attacco cyber russo alla Polonia: la guerra è in UE e nessuno si sorprende
Negli ultimi dodici mesi l’attività cyber della Russia è aumentata contro Paesi Nato ed europei, colpendo più spesso infrastrutture critiche. Il caso più recente è l’attacco di fine dicembre 2025 alla rete elettrica polacca. La cosa più grave è che il conflitto si è normalizzato. Può essere un passo verso l'escalation
Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies
The defense mechanisms that NPM introduced after the 'Shai-Hulud' supply-chain attacks have weaknesses that allow threat actors to bypass them via Git dependencies.
EU launches formal investigation into X and Grok over sexual images
CISA says critical VMware RCE flaw now actively exploited
CISA has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered U.S. federal agencies to secure their servers within three weeks.
Fix Staff Shortage & Burnout in Your SOC with Better Threat Intelligence
Learn how high-quality TI feeds reduce alert fatigue, prevents analyst burnout, and compensate for staff shortages in your SOC.
L’eclissi della cifratura: AI, quantum e la sfida satellitare cinese nel 2026
La Cina sta blindando le proprie comunicazioni investendo nella cifratura quantistica, mentre sta potenziando la capacità di calcolo dedicata alla "decryption" dei sistemi altrui. Questa asimmetria dà vita a un rischio che molti sottovalutano, ma che è già operativo: la strategia "Harvest Now, Decrypt Later". Ecco il triangolo del rischio, fra AI, Quantum e spazio