Arrests in Australia for TeamPCP and a massive supply-chain compromise campaign
Australian police have charged two men from Western Australia, accused of being part of the TeamPCP group, at the center of a long-running campaign of software supply chain attacks. According to authorities, the group hid malicious code in open source projects and then used it to steal credentials and data from thousands of organizations worldwide. Investigations, carried out together with…
Read the article →CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation
CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The flaw is a critical access control vulnerability…
Read the article →Suspected Iran-linked attack takes UK power plant offline
According to press sources cited by Help Net Security and Infosecurity Magazine, a British power plant remained offline for four days in July 2026 because of a cyberattack suspected to have been carried out…
Read the article →CISA adds four critical vulnerabilities to KEV catalog for active exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming their active exploitation in the wild. Among them are an authentication flaw in…
Read the article →Check Point SmartConsole: authentication bypass actively exploited
Check Point has fixed a critical vulnerability in the SmartConsole login process, tracked as CVE-2026-16232, which allows an unauthenticated attacker to obtain an application token and gain access with full administrative privileges. Reports indicate…
Read the article →Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularly dangerous because simply opening or even just viewing the email…
Read the article →Ransomware on Japan’s cold chain
A ransomware attack hit a Japanese food logistics company, causing delays and disruptions in the distribution chain for frozen products to thousands of customers. Among those affected are said to be major restaurant chains,…
Read the article →Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
Researchers at the University of California, San Diego, have discovered that at least 2.2 million cars with dealer-installed anti-theft systems are vulnerable to a Bluetooth attack. An attacker could lock or unlock the doors…
Read the article →Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code execution. Researchers at watchTowr and other analysts have observed…
Read the article →WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all the way to full site compromise. After the patch was…
Read the article →
The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
Fake alert app in Bahrain distributes Android spyware
Ubuntu snap-confine: the race condition that leads to local root
Kratos taken down, the phishing kit behind thousands of campaigns per month
HollowGraph uses Microsoft 365 calendars as a covert C2 channel
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
Italy fines WINDTRE €1.7 million after two customer data breaches
Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
Fake alert app in Bahrain distributes Android spyware
Ubuntu snap-confine: the race condition that leads to local root
Kratos taken down, the phishing kit behind thousands of campaigns per month
HollowGraph uses Microsoft 365 calendars as a covert C2 channel
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
Italy fines WINDTRE €1.7 million after two customer data breaches
Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities- OpenAI: the models escaped the sandbox and hit Hugging Face
- OT security: the ‘air gap’ is a myth and resilience must be designed
- PR3TACK wants to map threats before attackers use them
- China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty
- AGCOM says AI is reshaping access to information and pluralism
- ANPR data access via PDND changes the way the Italian public sector works
- Italy’s data centers are becoming a strategic industrial asset
- Most open-source AI projects still fail to reach production











