Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more
How to Align and Measure Threat Intelligence Operations: Flashpoint Priority Intelligence Requirements
Flashpoint Intelligence Requirements helps organizations operationalize Priority Intelligence Requirements (PIRs) and align intelligence activity to business priorities, operational risk, and measurable outcomes.
Google Chrome adds session cookie theft protection for all users
Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers.
The Cyber Express Weekly Roundup: Supply Chain Attacks, Mobile Banking Malware, and Expanding Cloud Phishing Campaigns
The Cyber Express weekly roundup highlights the latest supply chain attacks, mobile malware, and cloud phishing.
Man sent to prison for selling data of 7 millions elderly Americans
A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers.
Iranian Hackers Linked to Cyberattack on Los Angeles Transit Network
Israeli researchers linked Iranian hackers to the LA public transport cyberattack targeting LACMTA and disrupting services.
US charges Google security engineer with Polymarket insider trading
A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market.
WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover
WP Maps Pro vulnerability let attackers create admin accounts via a flawed AJAX action, risking full WordPress site takeover.
Norton software antivirus: sconti fino al 68% sui piani 360 con VPN e protezione anti-truffa IA
Norton offre il suo software antivirus in sconto fino al 68%: ecco cosa sapere sull'offerta per proteggere il nostro computer.
Charter Communications data breach affects 4.9 million accounts
The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned.
Proteggere la Privacy online: come funziona l’offerta Incogni per rimuovere i dati dal web e risparmiare fino al 50%
Con Incogni puoi proteggere in tutta sicurezza la tua privacy online e puoi anche arrivare a risparmiare il 50%: questa è l'offerta dedicata.
La gestione del rischio architetturale nello sviluppo Agile
Le implicazioni del framework AARM nel dominio della cyber security per tradurre i requisiti normativi in pratiche Agile concrete
Notepad++ Patches High-Severity RCE Flaws in Version 8.9.6.1
Notepad++ patches CVE-2026-48778, CVE-2026-48770, and CVE-2026-48800 flaws that could enable RCE and command injection attacks.
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.
Anthropic confirms Claude Mythos-class models will roll out to the public
Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private software.
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
A likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools.
BTMOB Android malware service generates custom phishing payloads
An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures.
Charter - 4,851,517 breached accounts
In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
The Mini Shai-Hulud Worm and the New Era of CI/CD Exploitation
We break down the technical mechanics of TeamPCP’s recent campaign and the impact on the developer ecosystem.
Hackers are trying to steal Signal users’ backups in new wave of phishing attacks
A new hacking campaign is trying to trick Signal users to give up their secret recovery key, which can be used to access online backups containing past messages.
FBI warns of fake FIFA websites running World Cup fraud schemes
The FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and hospitality packages, and push other fraud related to the event.
Less panic patching, more precision
In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
Oltre le direttive CERT-In: come gestire la connettività sicura in India con le VPN
Come operare in India nel rispetto della normativa CERT-In: analisi tecnica delle migliori VPN per aziende.
Interview #11 NoName057(16)
The following interview, which we publish in full, was conducted in May 2026 by me, fastfire. The pro-Russia hacktivist collective NoName057(16) (often referred to as NoName) emerged in March 2022 following the Russian invasion of Ukraine. The group primarily conducts disruptive Distributed Denial-of-Service (DDoS) campaigns against government and private sector entities in NATO member states
Il 78% delle aziende ha già subito o sospetta incidenti legati all’IA
A leggere il nuovo “2026 Cloud Security Report” realizzato da Check Point insieme a Cybersecurity Insiders, sembra proprio che l’adozione dell’intelligenza artificiale nelle aziende stia crescendo più rapidamente della capacità delle organizzazioni di proteggerla. Il report, basato sulle risposte di 1.042 professionisti IT e cybersecurity provenienti da organizzazioni di tutto il mondo, mostra un quadro …
Cruise giant Carnival confirms data breach affecting nearly 6 million people
New Gogs zero-day flaw lets hackers get remote code execution
An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.
How SIEM helps MSPs reduce noise and stop threats faster
MSPs don't lack security data. They struggle to separate real threats from alert noise. Kaseya explains how SIEM helps MSPs improve visibility, reduce fatigue, and respond faster.
NIS2, adottati i modelli comuni per la notifica di incidenti cyber: cosa cambia per le aziende
Il Gruppo di Cooperazione NIS ha approvato template standardizzati per la segnalazione degli incidenti informatici. Un passo concreto verso la semplificazione degli obblighi NIS2, con importanti implicazioni pratiche per i soggetti essenziali e importanti che stanno completando il percorso di conformità