Google fixes two Android zero days exploited in attacks, 107 flaws
Google has released the December 2025 Android security bulletin, addressing 107 vulnerabilities, including two flaws actively exploited in targeted attacks.
Fake Calendly invites spoof top brands to hijack ad manager accounts
An ongoing phishing campaign impersonates popular brands, such as Unilever, Disney, MasterCard, LVMH, and Uber, in Calendly-themed lures to steal Google Workspace and Facebook business account credentials.
Microsoft: KB5070311 triggers File Explorer white flash in dark mode
Microsoft has confirmed that the KB5070311 preview update is triggering bright white flashes when launching the File Explorer in dark mode on Windows 11 systems.
University of Pennsylvania confirms new data breach after Oracle hack
The University of Pennsylvania (Penn) has confirmed a new data breach after attackers stole documents containing personal information from its Oracle E-Business Suite servers in August.
Cultura aziendale e cyber security: la lezione di Nokia per i CISO del futuro
La cultura aziendale influenza la percezione del programma di sicurezza a tutti i livelli e spesso riflette la personalità del CISO stesso. La sfida è integrare abitudini e convinzioni di sicurezza attraverso flessibilità culturale, documentazione formale e comunicazione efficace. Ecco come
Windows 11 KB5070311 update fixes File Explorer freezes, search issues
Microsoft has released the KB5070311 preview cumulative update for Windows 11 systems, which includes 49 changes, including fixes for File Explorer freezes and search issues.
Kaspersky Security Bulletin contains statistics on various cyberthreats for the period from November 2024 to October 2025, which are based on anonymized data voluntarily provided by Kaspersky users via Kaspersky Security Network (KSN).
Gestire gli incidenti significativi: la matrice operativa per la conformità NIS 2
La sicurezza non vive nei documenti ma nei sistemi che li mettono in relazione. Ecco come passare dalla Business Impact Analysis alla notifica di un incidente significativo mediante una matrice operativa che correla impatti, tempi di continuità e livelli di servizio
Glassworm malware returns in third wave of malicious VS Code packages
The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now in its third wave, with 24 new packages added on the two platforms.
SmartTube YouTube app for Android TV breached to push malicious update
The popular open-source SmartTube YouTube client for Android TV was compromised after an attacker gained access to the developer's signing keys, leading to a malicious update being pushed to users.
Luci e ombre nel whistleblowing per le violazioni dell’AI Act: le 4 questioni aperte
Il debutto del sistema di whistleblowing per l’AI Act prevede un canale sicuro e crittografato gestito dall’European AI Office per la segnalazione delle violazioni della normativa sull’intelligenza artificiale. Ecco opportunità e problematiche legate alla protezione legale, attiva dal 2 agosto dell'anno prossimo
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats
Hackers impersonate IT pros with deepfakes, fake resumes, and stolen identities, turning hiring pipelines into insider threats. Huntres sLabs explains how stronger vetting and access controls help stop these threats.
ShadyPanda browser extensions amass 4.3M installs in malicious campaign
A long-running malware operation known as "ShadyPanda" has amassed over 4.3 million installations of seemingly legitimate Chrome and Edge browser extensions that evolved into malware.
South Africa Aligns Local Realities with Global Cybersecurity Standards
South Africa is reshaping cybersecurity with a culturally aware, locally informed, and globally aligned strategy to counter rising ransomware and digital threats.
Il tempo per documentare la gestione della sicurezza non dev'essere visto come un costo ma come un investimento, motivo per cui va affrontato tenendo conto della raccolta delle evidenze documentali necessarie all'attuazione degli obiettivi strategici dell'organizzazione. Altrimenti, il rischio è che si abbiano punti ciechi