Google to pay $8.25 million to settle lawsuit alleging children’s privacy violations
Critical flaw lets hackers track, eavesdrop via Bluetooth audio devices
A critical vulnerability in Google's Fast Pair protocol can allow attackers to hijack Bluetooth audio accessories like wireless headphones and earbuds, track users, and eavesdrop on their conversations.
Germany turns to Israel for a ‘cyber dome’ amid rising threats
How to automate just-in-time access to applications with Tines
Managing just-in-time access at scale is a growing IAM challenge as speed and auditability collide daily. Tines shows how automated workflows can grant, track, and revoke temporary app access without manual effort.
Elon Musk’s X says it will block Grok from making sexual images
Iran e Starlink: la fine del mito della connettività “a prova di censura”
Il blackout imposto da Teheran e l’interferenza sulle comunicazioni Starlink mostrano che anche le reti satellitari globali possono essere indebolite. Una lezione che riguarda la libertà di informazione, il ruolo delle infrastrutture private e la nuova geopolitica delle comunicazioni
UAT-8837 targets critical infrastructure sectors in North America
Cisco Talos is closely tracking UAT-8837, a threat actor we assess with medium confidence is a China-nexus advanced persistent threat (APT) actor.
Dark covenant in Russia: le 3 dimensioni del patto fra attori criminali e segmenti dello Stato
La trasformazione profonda dell'ecosistema cyber criminale russo vede affinarsi il Dark covenant in Russia. Ecco come si riconfigura il patto fra le autorità russe e la criminalità informatica
Referente CSIRT: chi è, cosa fa e perché la designazione NIS2 è cruciale
Referente CSIRT NIS2: ruolo, designazione e le responsabilità entro il 31 dicembre 2025. La guida operativa.
Fusion Fireside #15: Exploring PSD3 and PSR with Frederik Mennes
FTC bans GM from selling drivers' location data for five years
The FTC has finalized an order with General Motors, settling charges that it collected and sold the location and driving data of millions of drivers without consent.
ANY.RUN & Tines: Scale SOC and Meet SLAs with Powerful Automation
Learn how the ANY.RUN and Tines automate SOC triage with sandbox to reduce MTTR and improve response.
Microsoft smantella RedVDS, rete globale di cybercrime-as-a-service
Microsoft ha annunciato di aver smantellato RedVDS, una rete cybercrime-as-a-service che ha alimentato frodi multimilionarie in tutto il mondo.
Palo Alto Networks warns of DoS bug letting hackers disable firewalls
Palo Alto Networks patched a high-severity vulnerability that could allow unauthenticated attackers to disable firewall protections in denial-of-service (DoS) attacks.
Vendor Risk Management: come rendere misurabile il rischio dei fornitori
In un contesto caratterizzato dagli attacchi alla supply chain, in cui ogni fornitore rappresenta un potenziale punto di ingresso per gli attaccanti, serve un approccio strutturato e continuo di Third-Party Risk Management (TPRM) dinamico. Ecco cos'è un vendor risk management moderno e maturo
Microsoft disrupts massive RedVDS cybercrime virtual desktop service
Microsoft announced on Wednesday that it disrupted RedVDS, a massive cybercrime platform linked to at least $40 million in reported losses in the United States alone since March 2025.
DeadLock Ransomware: Smart Contracts for Malicious Purposes
Google's Personal Intelligence links Gmail, Photos and Search to Gemini
Google is rolling out 'Personal Intelligence,' a new Gemini feature that pulls your data from Gmail, Photos, Google Search, and other products.
Google plans to make Chrome for Android an agentic browser with Gemini
Google appears to be testing a new feature that integrates Gemini into Chrome for Android, allowing you to use agentic browser capabilities on your mobile device.
ChatGPT's upcoming cross-platform feature is codenamed "Agora"
OpenAI is internally testing a new feature called "Agora," and it could be related to some sort of cross-platform feature that works in real time or some other new product.
OpenAI's hidden ChatGPT Translate tool takes on Google Translate
OpenAI has quietly rolled out a new ChatGPT feature called ChatGPT Translate, and it looks very similar to Google Translate on the web.
South Korean giant Kyowon confirms data theft in ransomware attack
The Kyowon Group (Kyowon), a South Korean conglomerate, disclosed that a cyberattack has disrupted its operations and customer information may have been exposed in the incident.
Microsoft disrupts RedVDS cybercrime platform behind $40 million in scam losses
France fines Free Mobile €42 million over 2024 data breach incident
The French data protection authority (CNIL) has imposed cumulative fines of €42 million on Free Mobile and its parent company, Free, for inadequate protection of customer data against cyber threats.
Exploit code public for critical FortiSIEM command injection flaw
Technical details and a public exploit have been published for a critical vulnerability affecting Fortinet's Security Information and Event Management (SIEM) solution that could be leveraged by a remote, unauthenticated attacker to execute commands or code.
California AG to probe Musk’s Grok for nonconsensual deepfakes
Verizon Wireless outage puts phones in SOS mode without cell service
Verizon Wireless is suffering a massive outage in the US, with customers reporting their phones stuck in SOS mode with no cellular service.
“La tua tessera sanitaria è in scadenza”, ma è phishing: come difendersi
Il CERT-AgID ha identificato una nuova campagna di phishing che sfrutta indebitamente il nome e l’immagine del Ministero della Salute per indurre i cittadini a rinnovare la tessera sanitaria. Ecco come funziona la truffa e i consigli per tenere al sicuro i propri dati personali
French data regulator fines telco subsidiaries $48 million over data breach
Ugandan officials turn off internet on eve of national elections