WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all the way to full site compromise. After the patch was published, attackers began mass scanning and exploiting the flaw within hours, turning the fix into a roadmap for exploitation. Researchers’ reports show that many groups initially…
Read the article →Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code execution. Researchers at watchTowr and other analysts have observed…
Read the article →ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
The CVE-2026-6875 vulnerability in the ServiceNow AI Platform allows an unauthenticated attacker to execute remote code on self-hosted instances. Searchlight Cyber disclosed it on July 14, 2026, and ServiceNow released patches the same day,…
Read the article →Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
The Qilin ransomware operation is abusing CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, to gain unauthorized access to corporate networks. The flaw affects GlobalProtect portals and gateways and especially impacts unpatched systems, which…
Read the article →The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
Adobe has fixed CVE-2026-48294, a chain of vulnerabilities in its Acrobat extension for Chrome that allowed a malicious site to silently read data from an open WhatsApp Web tab. Guardio Labs described the attack…
Read the article →North Korean ClickFake campaign targets Web3 professionals
A new campaign attributed to the North Korean group Famous Chollima has targeted professionals in the Web3 sector with the ClickFix lure to deploy trojans on Windows and macOS. The mechanism relies on highly…
Read the article →Fake alert app in Bahrain distributes Android spyware
A malicious campaign exploited fake sites imitating Google Play to distribute a fake alert app in Bahrain, in the context of tensions and Iranian missile launches. According to analysts, the app installed a four-stage…
Read the article →Ransomware on Japan’s cold chain
A ransomware attack hit a Japanese food logistics company, causing delays and disruptions in the distribution chain for frozen products to thousands of customers. Among those affected are said to be major restaurant chains,…
Read the article →Kratos taken down, the phishing kit behind thousands of campaigns per month
German and US law enforcement dismantled Kratos’s infrastructure, a phishing-as-a-service platform considered among the most widely used in the world. The operation was led by the Frankfurt prosecutor’s office and the German Federal Criminal…
Read the article →HollowGraph uses Microsoft 365 calendars as a covert C2 channel
Researchers linked the HollowGraph malware to the Cavern framework after discovering that it uses Microsoft 365 calendars and Microsoft Graph APIs as a hidden command-and-control channel. This choice allows malicious traffic to blend in…
Read the article →
OpenAI: the models escaped the sandbox and hit Hugging Face
ANPR data access via PDND changes the way the Italian public sector works
Age verification tools raise privacy, security and civil-liberties trade-offs
Public-sector AI ethics: Italy’s governance debate meets France Travail’s algorithmic targeting
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty
AGCOM says AI is reshaping access to information and pluralism
OpenAI: the models escaped the sandbox and hit Hugging Face
ANPR data access via PDND changes the way the Italian public sector works
Age verification tools raise privacy, security and civil-liberties trade-offs
Public-sector AI ethics: Italy’s governance debate meets France Travail’s algorithmic targeting
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty
AGCOM says AI is reshaping access to information and pluralism- Italy’s data centers are becoming a strategic industrial asset
- Most open-source AI projects still fail to reach production
- The ‘augmented customer’ is reshaping financial advice in the AI era
- European AI sovereignty is becoming a strategic issue in finance, defense and healthcare
- ZoneAlarm Mobile Security adds customizable content filtering for mobile protection
- Microsoft releases Dusseldorf, an open-source out-of-band security testing platform
- FSE 2.0: new privacy obligations for private facilities
- Italian companies are moving AI oversight into finance as agentic projects struggle to reach production











