Instagram denies breach amid claims of 17 million account data leak
Instagram says it fixed a bug that allowed threat actors to mass-request password reset emails, amid claims that data from more than 17 million Instagram accounts was scraped and leaked online.
In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum. The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated email address, and some also contained a phone number. The scraped data appears to be unrelated to password reset requests initiated on the platform, despite coinciding in timeframe. There is no evidence that passwords or other sensitive data were compromised.
Previously, we created a simple script to print a table of CDP neighbors for all interfaces in the fabric. While writing it, we realized it could be optimized.
To optimize the script, we need to change the way we retrieve data.
Le ultime due puntate del podcast, che in realtà sono la prima e la seconda parte di una unica registrazione, sono tornate su un tema che sia io che Andrea, nonostante il nostro percorso profession…
Detecting Vectored Exception Handling Squared in an EDR
A deep Windows internals walkthrough: detecting Vectored Exception Handling Squared (VEH²) by reading DR0-DR3 from thread context in kernel mode, resolving target modules, and raising high-fidelity alerts in Sanctum EDR (Rust).
Spain arrests 34 suspects linked to Black Axe cyber crime
Authorities in Spain have arrested 34 individuals allegedly part of a criminal network involved in cyber fraud and believed to be connected to the Black Axe group responsible for illicit activities across Europe.
California Just Built a Data Deletion Tool That Actually Works (And Data Brokers Are Sweating)
California’s DROP lets consumers delete data from 1,600+ brokers in one click—but behind the scenes it raises serious security, compliance, and transparency risks.
In October 2025, a reincarnation of the hacking forum BreachForums, which had previously been shut down multiple times, was taken offline by a coalition of law enforcement agencies. In the months leading up to the takedown, the site itself suffered a data breach that exposed 324k unique email addresses, usernames, and Argon2 password hashes.
Ireland recalls almost 13,000 passports over missing 'IRL' code
Ireland's Department of Foreign Affairs has recalled nearly 13,000 passports after a software update caused a printing defect. The printing error makes the documents non-compliant with international travel standards and potentially unreadable at automated border gates.
ChatGPT tests a new feature to find jobs, improve your resume, and more
OpenAI is testing "Jobs," a new feature that could help you explore roles, improve your resume, and plan your career. This feature is being tested after ChatGPT gained support for the Health dashboard.
Raccolta dati e AI: le sfide legali del web scraping secondo la CNIL
La CNIL chiarisce che la raccolta di dati accessibili online tramite web scraping è legittima se accompagnata da misure a salvaguardia dei diritti degli interessati. Con un interessante focus sheet sul punto, la base giuridica del legittimo interesse prende forza. Vediamo meglio
Spogliati dall’AI: come difendersi dalla minaccia social
Grok su X è molto usato per “spogliare” donne e minori senza consenso, creando immagini sexualizzate. Il Garante italiano avverte: generare e diffondere questi contenuti (deepfake) può integrare reati e gravi violazioni dei diritti, con conseguenze anche privacy. Ecco cosa si rischia e come difendersi
Disimpegno USA e minacce ibride: cosa significa per la sicurezza cyber europea
Il ritiro degli Stati Uniti da iniziative cyber multilaterali ha implicazioni globali. Scopri come l'Europa reagisce a questo cambiamento strategico in un dominio critico
L’incident response è una funzione vitale dell'organizzazione, ma adottare una corretta strategia a riguardo implica il compiere scelte condivise e coordinate, per non disperdere risorse e mantenere strategie coerenti ed efficaci. Motivo per cui non è da sottovalutare l'aspetto della comunicazione interna
Disimpegno USA e minacce ibride: cosa significa per la sicurezza cyber europea
Il ritiro degli Stati Uniti da iniziative cyber multilaterali ha implicazioni globali. Scopri come l'Europa reagisce a questo cambiamento strategico in un dominio critico
Email security needs more seatbelts: Why click rate is the wrong metric
Click rate misses the real email security risk: what attackers can do after they access a mailbox. Material Security explains why containment and post-compromise impact matter more than phishing metrics.
Illinois Department of Human Services data breach affects 700K people
The Illinois Department of Human Services (IDHS), one of Illinois' largest state agencies, accidentally exposed the personal and health data of nearly 700,000 residents due to incorrect privacy settings.
L’archiviazione non cancella il passato digitale: la Cassazione fa chiarezza sul diritto all’oblio
La Cassazione boccia l'automatismo Cartabia: archiviazione penale non significa diritto all'oblio. Google mantiene la discrezionalità sul delisting. Per le piattaforme un presidio di bilanciamento, per l'interessato una pena reputazionale potenzialmente senza fine. Ecco tutti i punti critici