Google sues alleged Chinese cybercrime operation that used AI to send scam texts
The tech giant said a group called "Outsider Enterprise" used AI to scam hundreds of thousands of victims, sending 2.5 million text messages over a span of two weeks.
Ukrainian national pleads guilty to role in Conti ransomware operation
A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation.
Over 400 Arch Linux packages compromised to push rootkit, infostealer
More than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens.
WhatsApp contro l’obbligo di apertura ai chatbot rivali: i motivi e il possibile esito dello scontro Meta-Ue
La Commissione europea vuole che Meta apra Whatsapp a chatbot rivali come ChatGPT, Gemini o Claude. L'apertura dell'app di messaggistica ai chatbot rivali è al centro della contesa Meta-UE e riguarda il futuro dell'IA. Ecco la posta in gioco
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
GitHub access sales, leaked repositories, and stolen API keys can all become supply-chain attack footholds. Flare explores how underground forums expose early signals tied to software supply-chain risk.
The Cyber Express Weekly Roundup: AI Security Controls, Major Patch Releases, Public Sector Audits, and Emerging Online Scams
The Cyber Express weekly roundup of cybersecurity stories brings new insights into security updates, Microsoft's record patches, CBSE audit and FIFA scams.
Microsoft fixes Windows update failures linked to WUSA installer
Microsoft has fixed a known issue that caused Windows updates released since May 2025 to fail when installed via the Windows Update Standalone Installer (WUSA) from a network share.
Da alert fatigue a cyber resilience: come Novomatic ha trasformato il proprio SOC con HyperSOC
Infrastruttura on-premise complessa, molteplici obblighi normativi e un SOC sommerso dagli alert: queste le sfide di Novomatic Italia. Ecco come la collaborazione con HWG Sababa e l’uso della piattaforma HyperSOC hanno ridefinito detection, risposta e resilienza
Pharma giant Novo Nordisk discloses breach of clinical trials data
Danish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
CISA orders feds to patch actively exploited Ivanti flaw by Sunday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Binding Operational Directive (BOD) 26-04.
Dentro la truffa: la falsa campagna a tema Polizia Postale che esfiltra dati in tempo reale
Campagna di phishing a tema Polizia Postale. Con l'allarme" di un Sim Swapping i truffatori cercano di rubare carte di credito e dati sensibili degli utenti
Over 73,000 French govt employees affected in Tchap messenger breach
The French government revealed that a recent breach of its Tchap encrypted messaging platform affects the accounts of over 73,000 employees in the French public sector.
Fable 5 Mythos violato in 24 ore: il caso che scuote la cybersecurity
Il caso del jailbreak a Fable 5, con esposizione delle sue istruzioni segrete, mostra quanto siano fragili i sistemi di sicurezza proprietari davanti ad attacchi distribuiti e agentici. L’incidente diventa un monito sulla nuova fase della cybersecurity legata agli HACCA
Debito organizzativo: il costo nascosto del “poi vediamo”
Attraverso l'esame dei rischi trasversali che colpiscono la data protection, la cyber security, l'intelligenza artificiale e le risorse umane nella Governance by design, ecco come le moderne normative fungono da preziosi acceleratori per intercettare le vulnerabilità in fase di progettazione e strutturare organizzazioni resilienti
Debito organizzativo: il costo nascosto del “poi vediamo”
Attraverso l'esame dei rischi trasversali che colpiscono la data protection, la cyber security, l'intelligenza artificiale e le risorse umane nella Governance by design, ecco come le moderne normative fungono da preziosi acceleratori per intercettare le vulnerabilità in fase di progettazione e strutturare organizzazioni resilienti
Maine breach portal abused to publish fake data breach disclosures
In an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies to deny the claims.
Oracle warns of security bug that hackers abused to breach 100+ companies
The tech giant warned of a security flaw that a cybercrime gang said it's exploiting as part of a mass-hacking campaign. Google said it notified more than 100 organizations that had potentially vulnerable servers.
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn't be left on an open channel.
Authorities dismantle 'AudiA6' ransomware crypto-laundering service
Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million.