Cyber volunteer effort for small water utilities announces new MSSP effort
Una “biblioteca” di 300TB di musica: falla tecnica o atto di protesta dietro il mirror di Spotify?
Anna's Archive ha affermato di contenere circa 86 milioni dei brani più popolari di Spotify. Il servizio per lo stremaing musicale sta indagando sulla violazione, che ha comportato la raccolta non autorizzata di metadati e l'accesso illecito ad alcuni file audio. Ecco le ipotesi che hanno causato il mega data breach
Il caso Tper e i consigli per reagire alle fughe di dati
Roger, l’app per pagare i servizi di Trasporti per l’Emilia-Romagna (Tper) è finita nel mirino dei criminal hacker. Approfittiamo di questo recente episodio per stilare l’elenco delle cose da fare quando i nostri dati vengono violati e per parlare di trasparenza delle imprese
Account obbligatori nell’e-commerce: interviene l’EDPB
L'EDPB pubblica le Recommendations 2/2025 sugli account obbligatori nell'e-commerce. La registrazione forzata spesso viola il GDPR: il guest checkout deve essere l'opzione predefinita. Sette anni dopo il GDPR, serve ancora ribadire l'ovvio
Empty Promises in MENA: How Online Quick Cash Schemes Exploit the Gig Economy
Evasive Panda APT poisons DNS requests to deliver MgBot
Kaspersky GReAT experts analyze the Evasive Panda APT’s infection chain, including shellcode encrypted with DPAPI and RC5, as well as the MgBot implant.
Медицинская лаборатория Гемотест (Gemotest) - 6,341,495 breached accounts
In April 2022, Russian pharmaceutical company Gemotest suffered a data breach that exposed 31 million patients. The data contained 6.3 million unique email addresses along with names, physical addresses, dates of birth, passport and insurance numbers. Gemotest was later fined for the breach.
US insurance giant Aflac says hackers stole personal and health data of 22.6 million people
Aflac, one of the largest insurance companies in the U.S., confirmed hackers stole reams of personal data, including Social Security numbers, identity documents, and health information.
More than 22 million Aflac customers impacted by June data breach
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities.
Hackers stole over $2.7B in crypto in 2025, data shows
2025 was another banner year for crypto hacks and heists, the third year in a row that a new crypto theft record was set.
SEC sues crypto firms for defrauding investors out of $14 million
US insurance giant Aflac says hackers stole personal and health data of 22.6 million
Aflac, one of the largest insurance companies in the U.S., confirmed hackers stole reams of personal data, including Social Security numbers, identity documents, and health information.
US disrupts multimillion-dollar bank account takeover operation targeting Americans
Vulnerabilità in GeoServer: un rischio sistemico per le infrastrutture critiche
Il software open source GeoServer, utilizzato per l’elaborazione di dati geospaziali, è nel mirino con due vulnerabilità di cui una già attivamente sfruttata. Il rischio coinvolge dati geospaziali di infrastrutture critiche: energia, sistemi militari, logistica. CISA e ACN chiedono patch urgente. I dettagli
France’s postal and banking services disrupted by suspected DDoS attack
France's postal service, La Poste, said it was hit by a disruptive cyberattack that knocked its services offline.
GhostPairing, l’attacco che sfrutta i dispositivi collegati per compromettere WhatsApp
GhostPairing è un attacco WhatsApp che abusa della funzione di collegamento dispositivi. Tramite social engineering e fake page, convince le vittime a inserire codici di verifica che autorizzano l'accesso dell'attaccante. Nessuna vulnerabilità tecnica: solo sfruttamento di funzioni legittime e fiducia degli utenti
RTO Scam Wave Continues: A Surge in Browser-Based e-Challan Phishing and Shared Fraud Infrastructure
CRIL Uncovers a New Wave of Browser-Based e-Challan Phishing Powered by Shared Fraud Infrastructure.
Scegliere il framework di sicurezza, dal NIST alla ISO 27001: guida strategica per il CISO
La scelta di un framework di sicurezza va visto come un punto di partenza, non di destinazione: un passo fondamentale per garantire robusta strategia di cyber security. Ecco quello che c’è da sapere
Malicious extensions in Chrome Web store steal user credentials
Two Chrome extensions in the Web Store named 'Phantom Shuttle' are posing as plugins for a proxy service to hijack user traffic and steal sensitive data.
Vulnerabilità critica in n8n. Rischio elevato per istanze esposte in rete
Microsoft Teams strengthens messaging security by default in January
Microsoft Teams will automatically enable messaging safety features by default in January to strengthen defenses against content tagged as malicious.
Anubis Ransomware: Inside the Mindset and Methods of a Modern Ransomware Group
It is in this context that the Anubis group operates—a presence notable less for the spectacle of its claims and more for its pragmatic, cynical, and methodical approach to compromise, persistence, and extortion.
The Week in Vulnerabilities: More Than 2,000 New Flaws Emerge
IT vulnerabilities and ICS flaws surged past 2,000 in one week, with critical bugs, PoCs, and dark web activity raising risk for enterprises.
Cyberattack knocks offline France's postal, banking services
The French national postal service's online services were knocked offline by "a major network incident" on Monday, disrupting digital banking and other services for millions.
Assessing SIEM effectiveness
We share the results of assessing the effectiveness of Kaspersky SIEM in real-world infrastructures and explore common challenges and solutions to these.
Italy fines Apple $116 million over App Store privacy policy issues
Italy's competition authority (AGCM) has fined Apple €98.6 million ($116 million) for using the App Tracking Transparency (ATT) privacy framework to abuse its dominant market position in mobile app advertising.
Finta promozione Conad: come funziona la nuova campagna di Scam che sfrutta i punti fedeltà
Una nuova campagna di scam sfrutta il brand Conad e i punti fedeltà in scadenza per indurre gli utenti a sottoscrivere inconsapevolmente abbonamenti a pagamento. In questo articolo analizziamo come funziona la frode, le differenze tra scam e phishing e perché anche Conad è una vittima dell’abuso del
Baker University says 2024 data breach impacts 53,000 people
Baker University has disclosed a data breach after attackers gained access to its network one year ago and stole the personal, health, and financial information of over 53,000 individuals.
Kaspersky: così funziona il mercato del lavoro nel dark web
Ecco come curriculum, ruoli specializzati e credenziali rubate alimentano la filiera degli attacchi informatici.