CISA adds four critical vulnerabilities to KEV catalog for active exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming their active exploitation in the wild. Among them are an authentication flaw in Apple macOS (CVE-2026-65400) and a weak authentication flaw in Microsoft SharePoint (CVE-2026-55040). Also included are a path traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310) and a…
Read the article →Brazilian banking trojan expanding into Portugal
A banking trojan born in Brazil is actively spreading in Portugal, taking advantage of the fact that criminals share the same language as their targets and can therefore build more credible campaigns. Linguistic proximity…
Read the article →Iranian attacks against Siemens and Schneider industrial systems
U.S. agencies have warned that Iranian cyber actors are targeting Siemens and Schneider industrial systems used in American environments. The focus on ICS components is significant because it is not only about data or…
Read the article →Check Point SmartConsole: authentication bypass actively exploited
Check Point has fixed a critical vulnerability in the SmartConsole login process, tracked as CVE-2026-16232, which allows an unauthenticated attacker to obtain an application token and gain access with full administrative privileges. Reports indicate…
Read the article →Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularly dangerous because simply opening or even just viewing the email…
Read the article →HollowGraph uses Microsoft 365 calendars as a covert C2 channel
Researchers linked the HollowGraph malware to the Cavern framework after discovering that it uses Microsoft 365 calendars and Microsoft Graph APIs as a hidden command-and-control channel. This choice allows malicious traffic to blend in…
Read the article →North Korean ClickFake campaign targets Web3 professionals
A new campaign attributed to the North Korean group Famous Chollima has targeted professionals in the Web3 sector with the ClickFix lure to deploy trojans on Windows and macOS. The mechanism relies on highly…
Read the article →Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
Google has introduced CodeMender as a managed agent for code security and has paired the initiative with Gemini 3.5 Flash Cyber, a model designed to find, validate, and fix vulnerabilities before they can be…
Read the article →Fake alert app in Bahrain distributes Android spyware
A malicious campaign exploited fake sites imitating Google Play to distribute a fake alert app in Bahrain, in the context of tensions and Iranian missile launches. According to analysts, the app installed a four-stage…
Read the article →Ransomware on Japan’s cold chain
A ransomware attack hit a Japanese food logistics company, causing delays and disruptions in the distribution chain for frozen products to thousands of customers. Among those affected are said to be major restaurant chains,…
Read the article →
WordPress wp2shell: the exploit chain fueling mass scanning
Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
ANPR data access via PDND changes the way the Italian public sector works
AGCOM says AI is reshaping access to information and pluralism
WordPress wp2shell: the exploit chain fueling mass scanning
Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
ANPR data access via PDND changes the way the Italian public sector works
AGCOM says AI is reshaping access to information and pluralism- China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty
- Italy’s data centers are becoming a strategic industrial asset
- Italy fines WINDTRE €1.7 million after two customer data breaches
- The PA can use ANPR data via PDND
- FSE 2.0: new privacy obligations for private facilities
- Most open-source AI projects still fail to reach production
- The ‘augmented customer’ is reshaping financial advice in the AI era
- European AI sovereignty is becoming a strategic issue in finance, defense and healthcare











