News da fonti internazionali (BleepingComputer, DARK Reading, The Hacker News)
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIon 12 Novembre 2026 at 4:00 pm
- [Virtual Event] Building a Secure AI Strategy for the Enterpriseon 8 Ottobre 2026 at 3:00 pm
- Surfshark VPN says hackers breached internal testing, proxy serversby Bill Toulas on 10 Settembre 2026 at 7:15 pm
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]
- Microsoft Excel KB5002914 update breaks copy and paste for some usersby Lawrence Abrams on 10 Settembre 2026 at 7:07 pm
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Storiesby info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 5:47 pm
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
- AI-powered attack exploited PaperCut flaws to hack 395 organizationsby Bill Toulas on 10 Settembre 2026 at 3:55 pm
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]
- Cisco FMC flaws exploited by ransomware gang, state-sponsored hackersby Lawrence Abrams on 10 Settembre 2026 at 3:43 pm
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
- Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploitby Elizabeth Montalbano on 10 Settembre 2026 at 3:29 pm
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
- IDScan confirms breach tied to 153 million stolen driver’s licensesby Lawrence Abrams on 10 Settembre 2026 at 2:55 pm
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]
- Google Play Early Access Abused to Push Thousands of Deceptive Android Appsby info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 2:36 pm
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
- New 'BlueMoon' kit exploited Windows and Chrome zero-day flawsby Bill Toulas on 10 Settembre 2026 at 2:11 pm
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]
- The Top 4 Threats We Found by Investigating Every Alert for a Quarterby Sponsored by Prophet Security on 10 Settembre 2026 at 2:00 pm
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCEby info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 11:45 am
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instancesby info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 11:41 am
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
- Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checksby info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 11:33 am
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That
- Microsoft says September updates fix mouse settings reset issuesby Sergiu Gatlan on 10 Settembre 2026 at 11:14 am
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlineby info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 10:36 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication
- CISA: WatchGuard RCE flaw now exploited in ransomware attacksby Sergiu Gatlan on 10 Settembre 2026 at 9:10 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]
- Microsoft fixes bug that wiped Windows desktop settingsby Sergiu Gatlan on 10 Settembre 2026 at 8:08 am
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Keyby info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 7:12 am
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every
- Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6by info@thehackernews.com (The Hacker News) on 10 Settembre 2026 at 7:04 am
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "
- EU Cyber Resilience Act to Enforce New Reporting Requirementsby Nate Nelson on 10 Settembre 2026 at 7:00 am
Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.
- Trezor warns users of email provider breach, phishing attacksby Sergiu Gatlan on 10 Settembre 2026 at 6:56 am
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]
- Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksby Lawrence Abrams on 9 Settembre 2026 at 9:40 pm
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
- AdaptHealth confirms 4.1 million people exposed in July cyberattackby Bill Toulas on 9 Settembre 2026 at 9:30 pm
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]
- Mythos Vulnerability Firehose Hits a Human Bottleneckby Jai Vijayan on 9 Settembre 2026 at 9:19 pm
An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.
- Skullcandy Dime 3 earbuds expose users to Bluetooth hijackingby Bill Toulas on 9 Settembre 2026 at 9:02 pm
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]
- US Government Accuses Chinese AI Firms of Distilling Frontier Modelsby Alexander Culafi on 9 Settembre 2026 at 7:47 pm
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
- U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Cryptoby info@thehackernews.com (The Hacker News) on 9 Settembre 2026 at 6:26 pm
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
- US says Chinese firms extracted billions of tokens from frontier AI modelsby Bill Toulas on 9 Settembre 2026 at 4:48 pm
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]
![[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI](https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltaff0d27801ea21af/6a92220704334b0b8d8445e9/DR-Cloud-AI-VE-2026.jpg?width=720&quality=80&disable=upscale)
![[Virtual Event] Building a Secure AI Strategy for the Enterprise](https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt11afeac15e7adbb9/6a921187f8aef68330d6ae57/DRIW-AI-Strategy-VE-Oct26.jpg?width=720&quality=80&disable=upscale)

_Andriy_Popov_Alamy.png?width=720&quality=80&disable=upscale)










