Finland to disconnect fiber-optic link to Russia as lease expires
Sanzione GDPR: focus sui form di registrazione non completati e sull’acquisizione occulta dei dati
Il provvedimento con cui il Garante Privacy ha sanzionato Altroconsumo Edizioni diventa una lezione sul GDPR: al centro l'utilizzo dei dati raccolti attraverso form di registrazione mai completati. Ecco perché il Garante sanziona violazioni in materia di marketing: la disponibilità tecnica di un'informazione non significa liceità di trattamento
Anthropic says its AI hacked real-world companies in three incidents
The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats
The Cyber Express weekly roundup covers the latest major cyber incidents covering AI fraud, data breaches, malware attacks, and critical infrastructure threats.
AI Act, Garante: più tutele per i dati biometrici e garanzie nello schema di DL
In ambito adeguamento della normativa italiana all’AI Act, il Garante Privacy scende in campo per disciplinare l’uso dei sistemi di intelligenza artificiale da parte delle Forze di polizia, stabilendo limiti, presupposti e garanzie per il trattamento dati biometrici e per l’uso di tecnologie di identificazione biometrica da remoto. Ecco i dettagli
Anthropic Discloses Claude AI Internet Access During Security Evaluation
Anthropic cybersecurity evaluation found Claude AI models accessed real systems during tests, revealing risks in AI security evaluations and safeguards.
Network Anomaly Detection in KATA
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
Progettazione del cablaggio strutturato: la spina dorsale fisica del data center
Perché il modo in cui vengono posati i cavi in fibra e di rame e come vengono disposti i rack incide sulla stabilità e sulla sicurezza di un data center
Agenti AI che attaccano: la lezione dai casi Anthropic e OpenAI
Anche Anthropic riporta un caso di un'agente AI che fa attacchi cyber. Si aggiunge al pericoloso precedente OpenAI-Hugging Face, che è il primo esempio di attacchi AI autonomi senza (anzi contro) la volontà umana. Ecco che succede e cosa imparare
CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco patches CVE-2026-20316, an actively exploited Cisco Secure FMC zero-day reported by Horizon3.ai. CISA urges immediate remediation.
Il ruolo del CISO tra lo scetticismo del Board e la rivoluzione dell’IA
Guida alle strategie per il CISO: come gestire la comunicazione con il board e affrontare i rischi aziendali dell'IA.
FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices
The Hims & Hers lawsuit alleges deceptive billing practices and unlawful sharing of sensitive health information with Meta, Snap, and others.
FBI Warns of PLC Cyberattacks Disrupting Water Utilities Across Seven States
FBI warns of PLC cyberattacks targeting water and wastewater utilities, disrupting operations.
Il jailbreak universale alla vigilia dell’AI Act: ecco l’impatto nella sicurezza aziendale
Il prossimo 2 agosto si applicherà l'articolo 55 dell'AI Act, che impone ai fornitori di modelli general purpose, a rischio sistemico, obblighi stringenti di red teaming, gestione degli incidenti e resilienza. Tra rivendicazioni social, ricerca accademica e obblighi normativi: cosa cambia nella postura delle aziende contro le minacce alla GenAI
Proton Drive, archiviazione cloud da 200 GB a 1 euro: come funziona l’offerta e cosa include
Come ottenere l'archiviazione cloud con l'offerta di Proton Drive che garantisce 200 GB di spazio a solo 1 euro: ecco come attivarla.
NordPass Premium con uno sconto del 50%: quanto costa il password manager per le aziende
Nordpass Premium offre il suo gestore password con uno sconto 50%: ecco le tariffe, i requisiti per attivarlo e tutte le altre info utili.
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Chi si occupava di protezione dei dati cercava nella normativa un elenco di cose da fare. Nella struttura dell’articolo 24 del Regolamento, il GDPR mostra che una normativa fondata su principi e rischio non è più debole, ma più esigente. Ecco perché il regolamento europeo non ha abolito il diritto dell’obbedienza, ma lo ha reso insufficiente
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Chi si occupava di protezione dei dati cercava nella normativa un elenco di cose da fare. Nella struttura dell’articolo 24 del Regolamento, il GDPR mostra che una normativa fondata su principi e rischio non è più debole, ma più esigente. Ecco perché il regolamento europeo non ha abolito il diritto dell’obbedienza, ma lo ha reso insufficiente
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
Claude uploaded malware to PyPI in Anthropic's botched test
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations.
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution.
Semiconductor chip titan Analog Devices reports data breach
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies — like Microsoft and now Google — are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools.
Postel avvisa (con sei settimane di ritardo) che le PEC di Poste Italiane sono finite per errori ad altri
La segnalazione arriva da un nostro lettore che ha ricevuto la segnalazione direttamente da Postel. Le richieste? Non aprire le mail, cancellarle e rispondere dicendo di averlo fatto. Peccato che siano passate sei settimane
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
You were onto something with “It’s the Climb,” Miley
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI.
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data.