ANY.RUN uncovers how PhantomEnigma abused 20+ Brazilian government websites, hid behind trusted infrastructure, and put banks and public agencies at risk.
Dalle password alle passkey: ecco come usarle per il click to pay
Secondo un'indagine di Thales, quasi 7 utenti su dieci ammettono di condividere o prendere in prestito credenziali, evidenziando quanto rapidamente la difficoltà si trasformi in rischio. Ecco perché il superamento delle password, per migrare alle passkey, è urgente, in vista del click to pay
Le 12 best practice dell’ingegneria dei sistemi di intelligenza artificiale
Le pratiche non vanno intese come una sequenza procedurale o una checklist, ma come un quadro di riferimento per le decisioni progettuali. Ecco una sintesi e un'analisi critica del documento aggiornato sull'ingegneria dei sistemi di intelligenza artificiale con le 12 raccomandazioni del Software Engineering Institute (SEI)
Analysis of ClickLock, a modular macOS stealer delivered via ClickFix that uses fake dialogs, kill loops, and a GSocket backdoor to steal passwords, browser data, and crypto wallets.
Qantas Did Everything “Right” — And Got Breached Anyway. Regulators Say That’s the Point.
The Office of the Australian Information Commissioner (OAIC) closed the book this week on its year-long preliminary inquiry into the June 2025 Qantas data breach
Dutch police bust investment fraud ring stealing over €100 million
The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims.
Zoom warns of critical account takeover vulnerability
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts.
Google Gemini CLI abused as a hacking agent, malware botnet operator
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet.
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
We built a vulnerability vending machine: AI tokens in, zero-days out
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure.
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega
Le nuove FAQ dell’ACN ribadiscono che la nomina di un CISO non esaurisce gli obblighi previsti dalla NIS2. La cyber security entra stabilmente nella governance d’impresa: le attività operative si delegano, ma responsabilità, indirizzo e supervisione restano in capo al CdA
Tre punti non negoziabili per i CISO nell’era AI agentica
L’era agentica sta già cambiando il modo in cui avvengono gli attacchi, il comportamento dei sistemi e le responsabilità dei team di sicurezza. Ecco i tre punti per i CISO per affrontare l'AI agentica
Patch Tuesday, il record che nessuno voleva: 622 CVE e un nuovo modo di fare sicurezza
Il Patch Tuesday di luglio 2026 stabilisce il record assoluto nella storia di Microsoft: 622 CVE corrette, incluse due zero-day già sfruttate in attacchi reali su SharePoint e Active Directory. Eppure, nessuna delle due supera il CVSS 6. Un segnale inequivocabile: il punteggio non è più lo strumento giusto per decidere cosa patchare per primo
OkoBot: new sophisticated malware framework targets cryptocurrency users
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
CISA warns admins to patch actively exploited SharePoint flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances.