TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering
Surfacing Threats Before They Scale: Why Primary Source Collection Changes Intelligence
This blog explores how Primary Source Collection (PSC) enables intelligence teams to surface emerging fraud and threat activity before it reaches scale.
Sintesi riepilogativa delle campagne malevole nella settimana del 13 – 19 dicembre
Smart TV manufacturer ordered to stop collecting viewer data while court case proceeds in Texas
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections.
LLM e ransomware: la minaccia cambia marcia, ma senza cambiamenti radicali
Gli LLM hanno l'effetto di accelerare il ciclo di vita del ransomware, ma senza trasformarlo in maniera radicale. Ecco i tre cambiamenti strutturali che si stanno verificando in parallelo
Una vulnerabilità di ASUS Live Update di sette anni fa viene ancora sfruttata
Una vecchia vulnerabilità di ASUS Live Update torna a far paura: la CISA ha aggiunto il bug al catalogo delle vulnerabilità sfruttate attivamente.
Dismantling Defenses: Trump 2.0 Cyber Year in Review
The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum of technology challenges, from cybersecurity and privacy to countering disinformation, fraud and…
Over 25,000 FortiCloud SSO devices exposed to remote attacks
Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability.
NIS2, ACN aggiorna le FAQ: la notifica degli incidenti non si appalta
Le nuove FAQ di ACN sulla NIS2 affermano, senza alcuna ambiguità, chi deve notificare al CSIRT Italia quando l’incidente coinvolge una relazione cliente–fornitore tra soggetti NIS e quando entrano in gioco servizi cloud. Ecco perché “chi rileva” non coincide con “chi notifica”
AI e sregolatezza normativa
Gli scenari dell'intelligenza artificiale affrontano il dilemma della regolamentazione a riguardo, oscillando fra pericolose tentazioni di overregulation e deregulation. Ecco, dunque, che un legislatore virtuoso dovrebbe però non solo collocarsi nel mezzo, ma badare anche a come fare le regole
Senate confirms new Pentagon CIO
Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
Criminal IP (criminalip.io), the AI-powered threat intelligence and attack surface monitoring platform developed by AI SPERA, is now officially integrated into Palo Alto Networks' Cortex XSOAR.
Trump signs defense bill allocating millions for Cyber Command, mandating Pentagon phone security
UK confirms Foreign Office hacked, says ‘low risk’ of impact to individuals
Stealth in Layers: Unmasking the Loader used in Targeted Email Campaigns
CRIL has identified a commodity loader being leveraged by various threat actors in targeted email campaigns.
Denmark blames Russia for destructive cyberattack on water utility
Danish intelligence officials blamed Russia for orchestrating cyberattacks against Denmark's critical infrastructure, as part of Moscow's hybrid attacks against Western nations.
New critical WatchGuard Firebox firewall flaw exploited in attacks
WatchGuard has warned customers to patch a critical, actively exploited remote code execution (RCE) vulnerability in its Firebox firewalls.
Cloud Atlas activity in the first half of 2025: what changed
Kaspersky expert describes new malicious tools employed by the Cloud Atlas APT, including implants of their signature backdoors VBShower, VBCloud, PowerShower, and CloudAtlas.
Come anche le comunità per minori sono esposte a minacce cyber
Le informazioni psichiatriche di ragazze e ragazzi vulnerabili hanno un valore economico elevato e possono essere sfruttate, anche a fini di ricatto, nel corso di tutta la loro vita: le comunità terapeutiche che le conservano sono sotto attacco.
Quando il dato viaggia chiuso: la non responsabilità del servizio di recapito
Nel caso dei servizi di recapito, si osserva che il GDPR non attribuisce ruoli e obblighi a chi trasporta informazioni senza poter incidere sul loro contenuto, ma individua tali ruoli e obblighi in capo a chi determina finalità, modalità e destino. La responsabilità non nasce dalla prossimità fisica al dato, ma dal potere di governarlo
UE pronta alla guerra ibrida, di che si tratta: strumenti e scenari
’UE mette la “guerra ibrida” al centro del dibattito sulla sicurezza: non solo difesa militare, ma capacità industriali, cyber e cognitive. I droni parte più attiva della minaccia fisica ibrida. Il recente discorso della Commissaria Ue Ursula von der Leyen a Strasburgo richiama una responsabilità diretta europea e una lettura continua tra pace, crisi e conflitto
FTC: Instacart to refund $60M over deceptive subscription tactics
Grocery delivery service Instacart will refund $60 million to settle FTC claims that it misled customers with false advertising and unlawfully enrolled them in paid subscriptions.
I cyber attacchi non vanno in vacanza
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
India Criminalizes Tampering with Telecommunication Identifiers and Unauthorized Radio Equipment Under the Telecommunications Act
India’s Telecommunications Act criminalizes SIM tampering and unauthorized radio equipment, strengthening accountability and cybersecurity measures.
Choose Your Fighter: A New Stage in the Evolution of Android SMS Stealers in Uzbekistan
Yet another DCOM object for lateral movement
Kaspersky expert describes how DCOM interfaces can be abused to load malicious DLLs into memory using the Windows Registry and Control Panel.
How to Protect Your Site From Content Sniffing with HTTP Security Headers
Learn about the importance of HTTP security headers for preventing content sniffing vulnerabilities on your website.
Windows 10 OOB update released to fix Message Queuing (MSMQ) issues
This month's extended security update for Windows 11 broke Message Queuing (MSMQ), which is typically used by enterprises to manage background tasks.
Quantum Italia: i 4 ambiti del polo nazionale delle tecnologie quantistiche
Il sottosegretario all'Innovazione Alessio Butti e il ministro della Difesa Guido Crosetto vogliono creare un centro di ricerca Quantum dedicato ad Alessandro Volta, un polo nazionale che coinvolga università, PA e aziende, dove testare e creare applicazioni operative delle tecnologie quantistiche. Ecco l'iniziativa italiana, fra rischi e opportunità