A Note on Pentesting Passkeys
Senator asks US government watchdog to review how feds use hacking tools
Senator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans.
Alabama launches investigation into OpenAI’s hack of Hugging Face
Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident.
Here’s all the times AI has gone rogue and hacked other companies
A recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet.
Il 94% del lavoro di un MDR (che funziona) è quello che non vedi
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
Fake NYPD Officers on Video Calls: How Scammers Build a Convincing Trap
Storm Claims Attack on American Contractors Insurance Group (ACIG) and Publishes Stolen Data
1.4 TB of Data and Thousands of Patients: PEAR Claims Attack on South Plains Rural Health Services (SPRHS)
UK Cybercrime Journal: ACRO Breach Report
What Happened On 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO...
Golf Canada - 568,972 breached accounts
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
NIUS - 6,090 breached accounts
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).
Carhartt - 12,933,413 breached accounts
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.
What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk
Learn what a website attack surface is, which parts of your site increase exposure, and practical ways to reduce unnecessary security risks.
Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk
Learn how analytics tags, ad pixels, chat widgets, and other third-party scripts can create website security risks, plus practical ways to manage them.
The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact
We examine how modern hacktivism has evolved into a tool of global hybrid warfare, analyzing crowdsourced attack tactics, media-driven propaganda, and real-world impacts across Ukraine, the Middle East, European Union, and NATO nations.
MFA is in Retrograde, Phishing Kit Analysis
By Jeffrey
ClickExfil: My iteration on ClickFix and FileFix
By Jeffrey
The safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.
Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
JavaScript obfuscation: From party trick to phishing kit
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
Condivisione sicura delle credenziali e monitoraggio data leak: gestire le password in azienda a 3,59 €
NordPass offre ai professionisti il suo password manager business a 3,59 €: come ottenere la prova gratis per il tuo team e quanto costa.
OpenAI – Hugging Face: perché cambia la portata dell’incidente
Il 26 agosto 2026 OpenAI ha rilasciato il rapporto sull’incidente che ha coinvolto Hugging Face, da cui emerge che i comportamenti alla base dell’incidente erano comparsi da settimane. Ecco il quadro in cui la sequenza si è sviluppata e perché l'indagine modifica sensibilmente la precedente ricostruzione
Diritto all’oblio e rimozione automatica dai broker: eliminare email e numeri dalla rete a 5,99 €
Cancellare i dati personali dai siti con Incogni è possibile ed economico grazie al 50% di sconto: ecco come funziona il servizio e i costi.
Dalla crittografia zero-knowledge agli alias per l’email: il tool per proteggere gli account online a 2,49 €
ProtonPass propone i suoi gestori per le password con Passkey e 2FA a 2,49 € al mese: ecco come attivare l'offerta e cos'è compreso.
Controller e processor: le parole del GDPR rivelano le funzioni
“Titolare” evoca un proprietario, ma senza possedere i dati. Invece, "responsabile” suggerisce un decisore autonomo, pur agendo per conto altrui e su istruzioni. Il processor sembra un esecutore meccanico, ma il GDPR gli attribuisce obblighi propri. Ecco il vero significato di controller e processor
L’illusione della terapia digitale: i rischi dell’AI applicata alla salute mentale
I rischi dei chatbot per la salute mentale: lo studio di Stanford evidenzia errori terapeutici e risposte compiacenti dell'IA.
Cyber attacco alla piattaforma Spaggiari: allarme per i minori, la questione è la trasparenza
Secondo i cyber criminali, i dati trafugati sarebbero già in vendita a 50 mila dollari, anche se si limiterebbero a al modulo Bergantini della piattaforma scolastica del gruppo Spaggiari Parma. Ecco quali rischi temere e qual è il ruolo dei DPO a scuola
TeamSystem, dati contabili esfiltrati: perché il rischio non si ferma all’Iban
Secondo la comunicazione inviata agli utenti coinvolti e circolata online, TeamSystem ha individuato l’incidente nel pomeriggio del 24 agosto 2026 e ha successivamente confermato l’esfiltrazione di dati presenti nel servizio. Ecco le informazioni coinvolte
Interferenze GNSS: come l’Europa (e l’Italia) proteggono trasporti e infrastrutture critiche
Negli ultimi anni i sistemi di navigazione satellitare sono sempre più colpiti da interferenze deliberate, note come jamming e spoofing, con effetti diretti sui trasporti e sulle infrastrutture critiche. Ecco il ruolo dell'Italia e delle istituzioni europee, agenzie spaziali e industria nella risposta contro le interferenze GNSS