E-mail aziendali: la sanzione privacy a Piaggio fissa nuovi limiti alla raccolta dei dati
L’Autorità Garante per la protezione dei dati, nella nota del 29 luglio 2026, ha reso noto di aver irrogato una sanzione di 460 mila euro alla Piaggio per raccolta sistematica delle e-mail dei dipendenti. Vediamo meglio, in ottica propositiva
Gestire la NIS2 come sistema: perché la documentazione deve essere coerente e integrata
La conformità alla direttiva NIS2 non può essere affrontata come una semplice produzione di documenti separati. Policy, inventari, piani, registri e procedure devono diventare parti coerenti di un modello unico di governo della sicurezza informatica
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science.
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator.
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine.
È possibile conciliare la crescita delle infrastrutture necessarie all’intelligenza artificiale con la tutela del territorio? Tutte le sfide di uno sviluppo ancora privo di regole chiare.
È possibile conciliare la crescita delle infrastrutture necessarie all’intelligenza artificiale con la tutela del territorio? Tutte le sfide di uno sviluppo ancora privo di regole chiare.
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker.
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient.
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement.
CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.
ESET tracks rise in malicious AI skills and adaptable malware
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software.
Accessi non configurati: il caso della città metropolitana di Sassari
L’errata configurazione dei privilegi di accesso, secondo il need-to-know, può trasformare un sistema documentale in una violazione sistematica della normativa in materia di dati personali ed è causa di data breach. Ecco una lezione del Garante Privacy per Sassari, enti pubblici ed organizzazioni private sull’importanza della gestione degli accessi
Phishing ai clienti Telepass: non stai pagando una contravvenzione, ti stanno solo frodando
Negli ultimi anni si è assistito alla diversificazione dei servizi erogati da istituti bancari, compagnie telefoniche, gestori pagamenti che, nati svolgendo attività in uno specifico ramo di mercato (finanza, telefonia, ecc..), si sono successivamente proposti come erogatori di servizi a tutto tond