Japan’s Askul resumes limited online sales 6 weeks after ransomware attack
Servizi di pagamento: l’UE smantella la “zona franca” della responsabilità delle Big Tech
Il nuovo regolamento sui servizi di pagamento è la prima normativa europea che integra sicurezza finanziaria e responsabilità delle piattaforme digitali, trasformando le Big Tech in soggetti attivi della prevenzione antifrode e uscendo dalla logica della neutralità tecnologica delle piattaforme stesse. I punti cardine
Aisuru botnet behind new record-breaking 29.7 Tbps DDoS attack
In just three months, the massive Aisuru botnet launched more than 1,300 distributed denial-of-service attacks, one of them setting a new record with a peak at 29.7 terabits per second.
V3G4 Botnet Evolves: From DDoS to Covert Cryptomining
CRIL has uncovered an active V3G4 campaign using a Mirai-derived botnet alongside a fileless, runtime-configured cryptominer.
University of Phoenix discloses data breach after Oracle hack
The University of Phoenix (UoPX) has joined a growing list of U.S. universities breached in a Clop data theft campaign targeting vulnerable Oracle E-Business Suite instances in August 2025.
In atto una campagna di phishing che sfrutta le insegne del Governo per sottrarre dati bancari
Ransomware and Supply Chain Attacks Neared Records in November
Ransomware attacks rise in November 2025, targeting critical sectors and supply chains, highlighting urgent cybersecurity risks worldwide.
Guerre di Rete - Il riepilogo del mese
Continua il nostro crowdfunding. Ai donatori a breve un ebook in anteprima.
Exploits and vulnerabilities in Q3 2025
This report provides statistical data on vulnerabilities published and exploits we researched during the third quarter of 2025. It also includes summary data on the use of C2 frameworks.
French NGO Reporters Without Borders targeted by Calisto in recent campaign
Calisto phishing campaign targeting Reporters Without Borders uses ProtonMail impersonation and AiTM techniques to steal credentials in 2025.
L’eterno ritorno di Chat Control
Dopo anni di rinvii e modifiche, il Consiglio dell’Unione Europea ha votato a favore della norma contro la diffusione di materiale pedopornografico: ecco come funziona, quali sono i rischi e che cosa succederà adesso
ChatGPT is down worldwide, conversations disappeared for users
OpenAI's AI-powered ChatGPT is down worldwide with users receiving errors when attempting to access chats, with no reasons currently given.
Nuova campagna di phishing ai danni di Cassa Lombarda: dal sito fake all’installazione di malware Android
Una nuova campagna di phishing colpisce Cassa Lombarda tramite un sito fake registrato il 26 novembre e un flusso fraudolento che conduce l’utente a installare una falsa app Android. L’app, in realtà un malware della famiglia Herodotus, sfrutta i servizi di accessibilità per rubare credenziali banca
Quel cloud indispensabile che non sappiamo difendere al meglio
Le aziende investono nella sicurezza cloud più che mai, eppure faticano a proteggerla efficacemente. Ce lo rivela l'ultimo Thales Cloud Security Study, mentre l'AI generativa introduce nuove pressioni sui sistemi di protezione dati
Hook for Gold: Inside GoldFactory’s Сampaign That Turns Apps Into Goldmines
A deep dive into GoldFactory’s evolving mobile fraud campaigns across APAC, including modified banking apps, new malware variants such as Gigaflower, shared criminal infrastructure, and insights from the Group-IB Fraud Matrix, with recommendations for organizations and end users.
DOJ takes down Myanmar scam center website spoofing TickMill trading platform
Vulnerability & Patch Roundup — November 2025
Keep up-to-date with our latest WordPress vulnerability and patch updates for November 2025. Update now to protect your security!
Attacchi di password guessing: cosa sono e come proteggersi
Gli attacchi di password guessing consentono ai criminali informatici di indovinare la password della vittima. Le conseguenze includono gravi violazioni dei dati, interruzioni operative e, nei casi peggiori, la compromissione dell’intera rete. Ecco come difendersi
AI e machine learning nella cyber security: alleati strategici o nuove minacce
AI e Machine Learning nella cybersecurity: tra difesa proattiva e nuove minacce, come bilanciare innovazione, privacy e protezione aziendale.
Korea arrests suspects selling intimate videos from hacked IP cameras
The Korean National Police have arrested four individuals suspected of hacking over 120,000 IP cameras across the country and then selling stolen footage to a foreign adult site.
EU’s top court rules that online marketplaces are responsible for processing of data in ads
FTC settlement requires Illuminate to delete unnecessary student data
The Federal Trade Commission (FTC) is proposing that education technology provider Illuminate Education to delete unnecessary student data and improve its security to settle allegations related to an incident in 2021 that exposed info of 10 million students.
ChatGPT is down worldwide, conversations dissapeared for users
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories.
Iran-linked hackers target Israeli, Egyptian critical infrastructure through phishing campaign
InQL v6.1.0 Just Landed with New Features & Contribution Swag! 🚀
InQL v6.1.0 Just Landed with New Features & Contribution Swag! 🚀
Flashpoint’s Top 5 Predictions for the 2026 Threat Landscape
Flashpoint’s forward-looking threat insights for security and executive teams, provides the strategic foresight needed to prepare for the convergence of AI, identity, and physical security threats in 2026.
ShadyPanda: oltre 4 milioni di browser infetti in una campagna durata 7 anni
Una campagna durata sette anni che ha infettato 4.3 milioni di utenti Edge e Chrome: è questo il bilancio degli impatti di ShadyPanda.
India faces backlash over government cyber safety app mandate
Microsoft Defender portal outage disrupts threat hunting alerts
Microsoft is working to mitigate an ongoing incident that has been blocking access to some Defender XDR portal capabilities for the past 10 hours.