Anthropic AI agent faked identities, phished real developers in UK government hacking test
NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain
La gestione dei fornitori non può essere ridotta a un elenco anagrafico o contrattuale. In ottica NIS2, la criticità di un fornitore dipende dagli asset che gestisce, dai servizi IT che supporta, dagli accessi di cui dispone e dall’impatto che una sua indisponibilità o compromissione può produrre sull’organizzazione
How Enterprises Can Scale AI Securely with the Right Cloud Foundation
Learn why enterprises need a secure cloud foundation for AI, zero trust, visibility, and resilience to scale AI securely while reducing cyber risk.
Express VPN, fino all’80% di sconto sui piani da 28 mesi: cosa include l’offerta
Express VPN lancia l'offerta per avere il servizio per 28 mesi, disponibile su 10 dispositivi, con uno sconto dell'80%: ecco come funziona.
Claude evade (di nuovo) e compromette tre aziende reali
Sembra proprio che tenere a bada i modelli IA sia complicatissimo e Anthropic sta accumulando una certa esperienza nel settore. L’azienda ha infatti rivelato che alcuni modelli della famiglia Claude sono riusciti ad accedere ai sistemi di tre organizzazioni reali durante esercitazioni di sicurezza, trasformando test che avrebbero dovuto svolgersi in ambienti controllati in vere …
Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN
See how ChongLuaDao protects 200 million users against phishing threats with the help of ANY.RUN's Interactive Sandbox.
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
What Happened Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out ...
La sfida della sovranità digitale fra cyber security e geopolitica
Perché l'Europa non può più permettersi una sovranità di facciata. Il libro "Guerra profonda" e un avvocato ci aiutano a comprendere gli attori e gli obiettivi di questa nuova trasformazione digitale
One Adversary: The Moment Nobody Sees
Map any fraud campaign against your org chart and one stage of the attack has no owner. The adversary knows exactly which one — and the most expensive fraud cases live there.
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries.
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE).
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.
OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud
New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed.
Hackers steal over $130 million by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms.
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
Polish convenience store chain Żabka hacked through third-party account
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
Russian businesses erase Durov-linked products after 'terrorist' designation
Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries.
Apple launches new legal challenge against UK over iCloud access
Cybersecurity360 Awards 2026: le sfide della leadership antifragile
Analisi della leadership antifragile: come trasformare crisi, attacchi informatici e incertezza in valore per le aziende.
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
Top Hack e violazioni di dati: ecco la classifica del 2018
L'anno 2018 è ormai un lontano ricordo, eppure ha stabilito un record per quanto riguarda le attività di hacking e di violazioni di dati, le più importanti degli ultimi anni.
Revenge Porn, quando i ricatti si fanno in rete
Il Revenge Porn è la pubblicazione sul web di immagini o video che ritraggono le parti intime di una persona, senza il suo consenso, per vendetta.
How legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
Retelit, operatore cloud e di telecomunicazioni, ha subito un attacco informatico. E non lo dice
Tra i suoi clienti ci sono aziende strategiche, gestori di identità digitali e pubbliche amministrazioni. Migliaia i documenti già disponibili online. Dietro l’attacco Qilin, gruppo cybercriminale attivo almeno dal 2022 che ruba password e accessi
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono
Nessun sistema è immune dai guasti. Il principio del fail secure insegna a progettare applicazioni e infrastrutture che, in caso di errore, proteggano dati e asset critici senza amplificare il rischio. Un approccio che cambia il modo di concepire sicurezza, resilienza e continuità operativa
Phishing a tema “multe” sfrutta il nome della Polizia di Stato e di pagoPA