Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code execution. Researchers at watchTowr and other analysts have observed that the exploit was quickly turned into real-world attacks against exposed instances. The issue is particularly serious because attackers can use it to gain initial access…
Read the article →WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all the way to full site compromise. After the patch was…
Read the article →ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
The CVE-2026-6875 vulnerability in the ServiceNow AI Platform allows an unauthenticated attacker to execute remote code on self-hosted instances. Searchlight Cyber disclosed it on July 14, 2026, and ServiceNow released patches the same day,…
Read the article →Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
The Qilin ransomware operation is abusing CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, to gain unauthorized access to corporate networks. The flaw affects GlobalProtect portals and gateways and especially impacts unpatched systems, which…
Read the article →RoguePlanet, GigaWiper, and other destructive Windows malware show the continued rise of high-impact endpoint abuse
The feed includes several destructive or quasi-destructive Windows malware stories, from backdoors that bundle wipers and ransomware capabilities to driver-based defenses blinding endpoint security tools. These campaigns matter because they combine evasion, persistence, and…
Read the article →Government, telecom, and public-sector breaches show persistent exposure of large identity datasets
The feed includes a series of large breaches affecting telecoms, insurers, government agencies, and public services, with millions of records exposed in some cases. These incidents often start with phishing, employee compromise, or third-party…
Read the article →Healthcare, medtech, and service providers are still a favorite ransomware and breach target
Healthcare and adjacent service providers continue to be hit by both ransomware and large data breaches. The feed includes multiple incidents involving clinics, insurers, medical device manufacturers, and healthcare support organizations, often with sensitive…
Read the article →Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
Researchers at the University of California, San Diego, have discovered that at least 2.2 million cars with dealer-installed anti-theft systems are vulnerable to a Bluetooth attack. An attacker could lock or unlock the doors…
Read the article →SharkNinja cloud flaw could let attackers remotely control millions of Shark robot vacuums
A security researcher found a critical flaw in SharkNinja's cloud-connected robot vacuum ecosystem that could allow remote code execution on affected devices. The issue affects millions of Shark robot vacuums, turning a consumer appliance…
Read the article →FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
A campaign called FakeGit set up around 7,600 malicious GitHub repositories, with over 800 projects pretending to be AI Skills or MCP servers. According to researchers, the operation exploited the trust of AI agents…
Read the article →
Age verification tools raise privacy, security and civil-liberties trade-offs
Public-sector AI ethics: Italy’s governance debate meets France Travail’s algorithmic targeting
FSE 2.0: new privacy obligations for private facilities
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
AGCOM says AI is reshaping access to information and pluralism
China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty
Italy’s data centers are becoming a strategic industrial asset
Age verification tools raise privacy, security and civil-liberties trade-offs
Public-sector AI ethics: Italy’s governance debate meets France Travail’s algorithmic targeting
FSE 2.0: new privacy obligations for private facilities
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
AGCOM says AI is reshaping access to information and pluralism
China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty
Italy’s data centers are becoming a strategic industrial asset- Most open-source AI projects still fail to reach production
- The ‘augmented customer’ is reshaping financial advice in the AI era
- European AI sovereignty is becoming a strategic issue in finance, defense and healthcare
- Italian companies are moving AI oversight into finance as agentic projects struggle to reach production
- ZoneAlarm Mobile Security adds customizable content filtering for mobile protection
- Alert overload is slowing SOCs, pushing defenders toward outcome-based operations
- Microsoft releases Dusseldorf, an open-source out-of-band security testing platform
- The market for AI security products is exploding, but buyers still struggle to separate control from marketing











