Sicurezza
Cybersecurity, ransomware, privacy
- inSicurezzaDigitale.com — Cybersecurity in italiano IT
- SecureBulletin — Cybersecurity news in English EN
- Ransomfeed Daily News — Daily cybersecurity news EN
2.415 voci in archivio · mostrate 751–775 .
Polonia, arrestato cittadino russo per attacchi informatici a reti locali
In un’operazione che conferma la crescente sofisticazione della minaccia cyber proveniente da attori legati a stati nazionali, le autorità polacche hanno arrestato un cittadino russo sospettato di ave…
ShadowV2: la botnet che ha sfruttato il caos AWS per colonizzare l’IoT globale
Mentre il mondo assisteva al collasso dei servizi Amazon Web Services lo scorso ottobre, un’altra storia, più silenziosa e insidiosa, si stava scrivendo nelle reti globali. Nel vuoto lasciato dall’inf…
Battlefield 6’s Rise Is Fueling a Surge of Malware: How Attackers are Capitalizing on the Hype
Since its release this October, “Battlefield 6” has ignited gaming communities, with millions eagerly jumping into the action-packed experience. However, alongside the excitement comes a darker side –…
OpenAI API Users: Mixpanel Data Leak Exposes Personal Information
OpenAI, the renowned developer of AI models like ChatGPT, has recently acknowledged a data breach involving its third-party analytics provider, Mixpanel. This incident exposed sensitive user informati…
HashJack: quando un cancelletto nell’URL inganna l’IA nel browser
C’è una nuova, sottile minaccia che sfrutta uno dei simboli più innocui del web – il cancelletto (hashtag) “#” – per aggirare le difese di sicurezza e manipolare gli assistenti IA integrati nei browse…
The FBI’s Latest Warning: Phishing Scams Target the IC3
The internet is a constant battleground, and today’s cybercriminal tactics are more intricate and insidious than ever before. Recently, the Federal Bureau of Investigation (FBI) issued urgent warnings…
HashJack: weaponizing trust in AI browser assistants
A vulnerability in the way AI browser assistants handle URL fragments opens doors for malicious attacks. For years, we’ve seen AI take center stage across various industries, revolutionizing everythin…
A Critical Security Flaws in HashiCorp’s Provider
HashiCorp’s Vault Terraform provider, a cornerstone of secure secrets management for organizations worldwide, has been found with a critical security flaw. This vulnerability, tracked as CVE-2025-1335…
ClickFix: Fake Windows Updates and PNG Steganography Make a Darker Play for User Machines
For those deeply involved with cybersecurity, the past few years have seen a dramatic rise in sophisticated phishing campaigns leveraging social engineering to deliver malware onto unsuspecting victim…
How Hackers are using Open-Source repositories to steal crypto
A new wave of malware targeting cryptocurrency users is hitting developers hard, showcasing the growing sophistication and accessibility of attacks in 2023. The root cause? A well-executed supply chai…
ToddyCat’s new tricks: email hacking evolves with the cloud
The age-old adage “if it ain’t broke, don’t fix it” doesn’t always hold true in cybersecurity. As attackers are increasingly leveraging cloud services to protect sensitive data, their methods are evol…
Wireshark 4.6.1: critical security update addresses major vulnerabilities
A recent update from the Wireshark Foundation addresses critical vulnerabilities impacting the widely used network protocol analyzer, potentially exposing users to denial-of-service conditions. The vu…
Com groups: come un moderatore è finito dietro le sbarre
Nel sottobosco digitale di Telegram, dove l’anonimato e la crittografia offrono un rifugio apparentemente sicuro, si annidano comunità criminali sempre più strutturate e spietate. Una di queste, un “C…
TamperedChef: la fabbrica degli avvelenatori di certificati digitali
C’è una certa quiete, quasi rassicurante, quando apriamo un installer, nel vedere quella piccola finestra di dialogo di Windows che certifica la validità di una firma digitale. È un sigillo di fiducia…
APT24: three years of obscure espionage with the “BadAudio” download
For years, APT24, a sophisticated cyber espionage group linked to China’s People’s Republic, has been quietly crafting targeted attacks against key players across global industries. Their latest offen…
Oracle hit: Clop’s Zero-Day exploit leaves tech giant exposed
Yesterday, the cybersecurity world was rocked by news of a potentially massive breach targeting Oracle. The notorious Clop ransomware gang has publicly claimed responsibility for compromising the tech…
Databreach: 2.3TB data from Italian rail group, Almaviva
A colossal digital archive, estimated at approximately 2.3 terabytes, has appeared in the darkest corners of the web. A malicious actor claims to possess it, pointing the finger at Almaviva and a wide…
Eternidade Stealer: WhatsApp-Enabled banking trojan sophistication
The Trustwave SpiderLabs team has unearthed a particularly unsettling piece of malware – Eternidade Stealer – that’s raising serious questions about the security practices surrounding WhatsApp and the…
Whatsapp: rilevata vulnerabilità crittografica globale
Un silenzio digitale ha avvolto per mesi i server di WhatsApp (che non si sono opposti allo sfruttamento), un vuoto di sicurezza che ha permesso a un gruppo di ricerca dell’Università di Vienna di con…
Akira: a CAPTCHA breach unravels enterprise security
The recent escalation of attacks attributed to the Howling Scorpius ransomware group has highlighted a chillingly simple, yet devastatingly effective, entry vector. While often touted as the vanguard…
Nova Stealer: macOS cryptocurrency theft
The cybersecurity landscape is consistently shaped by increasingly sophisticated threats, and the latest to garner significant attention is Nova Stealer – a meticulously crafted malware campaign speci…
The Cloudflare cascade: operational failure
The recent, prolonged disruption experienced by Cloudflare, affecting global internet traffic for several hours, wasn’t a conventional cyberattack. Instead, it’s a stark and unsettling illustration of…
DoorDash data breach: a social engineering compromise
The recent disclosure by DoorDash regarding a cybersecurity incident, initially attributed to a social engineering attack, warrants a detailed examination beyond the standard press release narrative…
WhatsApp’s silent threat: the screen-sharing scams
The current wave of WhatsApp scams, fueled by the platform’s recently introduced screen-sharing feature, is a prime example. It’s a chilling demonstration of how a seemingly innocuous feature can beco…
Il buio di Cloudflare: Internet down il 18 novembre
Stamattina, intorno alle 11:30 GMT, un brusio ha iniziato a propagarsi nelle stanze digitali di sysadmin, sviluppatori e semplici utenti. Un brusio che si è rapidamente trasformato in un coro di coste…