Armenia probes alleged sale of 8 million government records on hacker forum
CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks
CISA has ordered government agencies to secure their systems against a high-severity Gogs vulnerability that was exploited in zero-day attacks.
Hungary grants asylum to former Polish minister implicated in spyware probe
'Bad actor' hijacks Apex Legends characters in live matches
Apex Legends players over the weekend experienced disruptions during live matches as threat actors hijacked their characters, disconnected them, and changed their nicknames.
Sweden detains ex-military IT consultant suspected of spying for Russia
University of Hawaii Cancer Center hit by ransomware attack
University of Hawaii says a ransomware gang breached its Cancer Center in August 2025, stealing data of study participants, including documents from the 1990s containing Social Security numbers.
Fintech firm Betterment confirms data breach after hackers send fake crypto scam notification to users
Hackers gained access to some Betterment customers’ personal information through a social engineering attack, then targeted some of them with a crypto-related phishing message.
Target's dev server offline after hackers claim to steal source code
Hackers are claiming to be selling internal source code belonging to Target Corporation, after publishing what appears to be a sample of stolen code repositories on a public software development platform. After BleepingComputer notified Target, the files were taken offline and the retailer's developer Git server was inaccessible.
Apple confirms Google Gemini will power Siri, says privacy remains a priority
Apple and Google have confirmed that the next version of Siri will use Gemini and Google Cloud in a multi-year collaboration between the two tech giants.
Ispezioni NIS2: come funzionano e quali responsabilità ricadono sulle organizzazioni
Ispezioni NIS2: regime ispettivo ex ante ed ex post, incidenti gravi e responsabilità organizzativa. Quando ACN verifica.
Hidden Telegram proxy links can reveal your IP address in one click
A single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add warnings to proxy links after researchers demonstrated that such one-click interactions could reveal a Telegram user's real IP address.
Microsoft is retiring the Lens scanner app for iOS, Android
Microsoft has started retiring the Microsoft Lens PDF scanner app for Android and iOS devices on Friday, January 9th, with plans to remove it from app stores next month.
Spanish energy giant Endesa discloses data breach affecting customers
Spanish energy provider Endesa and its Energía XXI operator are notifying customers that hackers accessed the company's systems and accessed contract-related information, which includes personal details.
Cos’è la guerra cognitiva e qual è la posizione della NATO
Il paradigma della sicurezza globale è al centro di un cambiamento sostanziale. La NATO ha formalizzato la guerra cognitiva come nuova frontiera per la superiorità strategica. Cosa è la guerra cognitiva e quali sono i rischi che la caratterizzano
Raccolta dati e AI, come informare correttamente gli interessati: le raccomandazioni
La CNIL chiarisce come informare gli utenti/interessati quando si utilizzano sistemi di intelligenza artificiale, rendendo note delle linee guida molto operative e altrettanto dettagliate circa gli obblighi di trasparenza quando si raccolgono dati con l’AI. Il tutto in perfetta linea con i dettami del GDPR. Vediamo meglio
Dutch court sentences hacker who used port systems to smuggle cocaine to 7 years
Prevent cloud data leaks with Microsoft 365 access reviews
Microsoft 365 has made file sharing effortless, but that convenience often leaves organizations with little visibility into who can access sensitive data. Tenfold explains how access reviews for shared cloud content can help organizations regain visibility, reduce unnecessary permissions, and prevent data leaks in Microsoft 365.
Black Axe, arrestati oltre trenta individui legati alla cybergang
La Polizia Nazionale spagnola ha arrestato trentaquattro persone, tra cui i leader del gruppo, legate al gruppo cybercriminale Black Axe.
UK launches formal investigation into X over ‘nudification’ of children images
Max severity Ni8mare flaw impacts nearly 60,000 n8n instances
Nearly 60,000 n8n instances exposed online remain unpatched against a maximum-severity vulnerability dubbed "Ni8mare."
Il caso OVH, quando il Canada sfida la sovranità digitale UE: i rischi per i nostri dati
Un tribunale canadese ha ordinato a OVHcloud di consegnare dati di clienti archiviati in Europa, creando un conflitto con il diritto francese e mettendo alla prova la sovranità digitale europea. Un caso in cui non è la geografia dei server a determinare la giurisdizione, ma chi è giuridicamente responsabile e può accedervi
Gestire il rischio cyber dei sistemi di AI: le prime indicazioni operative del NIST
L’intelligenza artificiale è ormai parte integrante dei sistemi e delle decisioni delle organizzazioni. Il suo impatto sulla cyber security non può essere affrontato come un tema tecnico isolato, ma come una questione di governo. È questo l’obiettivo del Cyber AI Profile del NIST. Ecco i punti salienti
Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools
Anthropic is bringing Claude for healthcare, following a similar move by OpenAI for ChatGPT.
CERT-AGID 3-9 gennaio: phishing e malware aprono il 2026
Settantatrè campagne rilevate in Italia nella prima settimana dell’anno, con smishing INPS e finte sanzioni PagoPA. Oltre a una nuova vulnerabilità critica in n8n.
California bans data broker reselling health data of millions
The California Privacy Protection Agency (CalPrivacy) has taken action against the Datamasters marketing firm that sold the health and personal data of millions of users without being registered as a data broker.
Instagram denies breach amid claims of 17 million account data leak
Instagram says it fixed a bug that allowed threat actors to mass-request password reset emails, amid claims that data from more than 17 million Instagram accounts was scraped and leaked online.
Instagram - 6,215,150 breached accounts
In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum. The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated email address, and some also contained a phone number. The scraped data appears to be unrelated to password reset requests initiated on the platform, despite coinciding in timeframe. There is no evidence that passwords or other sensitive data were compromised.
Filtering Cisco API Output
Previously, we created a simple script to print a table of CDP neighbors for all interfaces in the fabric. While writing it, we realized it could be optimized.
To optimize the script, we need to change the way we retrieve data.
Info Sec Unplugged – CISO e vCISO
Le ultime due puntate del podcast, che in realtà sono la prima e la seconda parte di una unica registrazione, sono tornate su un tema che sia io che Andrea, nonostante il nostro percorso profession…
Detecting Vectored Exception Handling Squared in an EDR
A deep Windows internals walkthrough: detecting Vectored Exception Handling Squared (VEH²) by reading DR0-DR3 from thread context in kernel mode, resolving target modules, and raising high-fidelity alerts in Sanctum EDR (Rust).