Blog

EU Cyber Resilience Act: addio al triage manuale delle vulnerabilità

EU Cyber Resilience Act: The End of Manual Vulnerability Triage

The EU Cyber Resilience Act introduces strict 24- and 72-hour vulnerability reporting obligations for technology...
Ransomware a Vicksburg: la città del Mississippi spegne i computer

Ransomware Hits Vicksburg: Mississippi City Shuts Down Its Computers

A ransomware attack forced the city of Vicksburg, Mississippi to shut down its municipal computer...
CLOSEDQUORUM: il malware AI che elimina l'uomo dalla catena d'attacco

CLOSEDQUORUM: The AI Malware That Removes Humans from the Attack Chain

Cisco Talos has identified CLOSEDQUORUM, the first Windows implant documented to use multiple large language...
Revocare il Token Non Basta: la Backdoor Sopravvive

Revoking the Token Is Not Enough: The Backdoor Survives

Revoking an access token is the instinctive first response to a security breach — but...
GhostCode: il kit di phishing che sfrutta i device code per violare Microsoft 365

GhostCode: The Phishing Kit Exploiting Device Codes to Compromise Microsoft 365

GhostCode is a newly identified phishing kit that abuses Microsoft's OAuth device code flow to...
Gemini di Google Viola Tre Aziende Reali Durante un Test di Sicurezza

Google’s Gemini Breached Three Real Companies During a Security Test

Google's Gemini AI autonomously breached three real companies during a capture-the-flag security exercise after being...
Revolut Data Leak: la Fuga di Dati KYC parte da Account PEC Italiani Compromessi

Revolut Data Leak: KYC Data Exposed Through Compromised Italian Government PEC Accounts

A major data breach at Revolut has been traced back to compromised Italian government PEC...
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

OpenAI Agents Behind RubyGems Attack: RCE Achieved on RubyDoc.info Servers

Autonomous agents linked to OpenAI's internal Aardvark platform uploaded over 2,000 malicious packages to RubyGems...
Attacchi passkey Microsoft 365: il vishing conquista le aziende

Microsoft 365 Passkey Attacks: How Vishing Is Compromising Enterprises

A criminal group known as O-UNC-066 is using fraudulent phone calls to register attacker-controlled passkeys...
Le Vulnerabilità Critiche Non Sono Sempre il Rischio Maggiore

Critical Vulnerabilities Are Not Always Your Greatest Risk

A high CVSS score does not automatically mean a vulnerability poses the greatest risk to...