News da fonti internazionali (BleepingComputer, DARK Reading, The Hacker News)
- MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academicsby info@thehackernews.com (The Hacker News) on 3 Ottobre 2026 at 2:38 pm
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomwareby info@thehackernews.com (The Hacker News) on 3 Ottobre 2026 at 2:36 pm
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
- Danish university DTU breach exposes data of up to 200,000 peopleby Ionut Ilascu on 3 Ottobre 2026 at 2:35 pm
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
- The State of Cybersecurity in 2026: Key Segments, Insights, and Innovationsby info@thehackernews.com (The Hacker News) on 3 Ottobre 2026 at 11:00 am
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of
- RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Failby Arielle Waldman on 2 Ottobre 2026 at 8:18 pm
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.
- Frontline Education breach exposes school district employee databy Lawrence Abrams on 2 Ottobre 2026 at 7:01 pm
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
- Warlock ransomware breach SharePoint in water, telecom operator attacksby Ionut Ilascu on 2 Ottobre 2026 at 6:33 pm
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Serversby info@thehackernews.com (The Hacker News) on 2 Ottobre 2026 at 5:33 pm
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaignby info@thehackernews.com (The Hacker News) on 2 Ottobre 2026 at 5:33 pm
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodesby info@thehackernews.com (The Hacker News) on 2 Ottobre 2026 at 5:02 pm
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
- Kiteworks & Citrix Incidents Show Challenges of Zero-Day Responseby Robert Lemos on 2 Ottobre 2026 at 4:56 pm
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
- SWIFT Banking & Government Middleware Enables RCEby Nate Nelson on 2 Ottobre 2026 at 4:27 pm
Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.
- GitLab warns of critical RCE vulnerability in AI Gateway serviceby Sergiu Gatlan on 2 Ottobre 2026 at 4:20 pm
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]
- Is Your Organization Ready for 2027's AI Accountability Era?by Arielle Waldman on 2 Ottobre 2026 at 4:01 pm
Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.
- Is It Fair to Blame 'Rogue' AI for Security Failures?by Alexander Culafi on 2 Ottobre 2026 at 3:51 pm
"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.
- US sanctions Tren de Aragua gang members in ATM hacks crackdownby Sergiu Gatlan on 2 Ottobre 2026 at 3:20 pm
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]
- The EDR blind spot: 3 ways browser attacks evade endpoint telemetryby Sponsored by NordLayer Browser on 2 Ottobre 2026 at 2:00 pm
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]
- Vulnerability Backlogs Are an Ownership Problemby Nishant Sharma on 2 Ottobre 2026 at 2:00 pm
Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.
- Malicious Linux Implants Mimic Asian Mail Security Productsby Nate Nelson on 2 Ottobre 2026 at 1:00 pm
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.
- Dell asks admins to patch max severity CSM flaws as soon as possibleby Sergiu Gatlan on 2 Ottobre 2026 at 12:37 pm
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]
- OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandlingby info@thehackernews.com (The Hacker News) on 2 Ottobre 2026 at 12:23 pm
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
- Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Reportby info@thehackernews.com (The Hacker News) on 2 Ottobre 2026 at 11:30 am
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is
- Microsoft’s X account hacked in crypto pump-and-dump schemeby Sergiu Gatlan on 2 Ottobre 2026 at 9:29 am
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]
- Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Toolsby info@thehackernews.com (The Hacker News) on 2 Ottobre 2026 at 8:01 am
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writesby info@thehackernews.com (The Hacker News) on 2 Ottobre 2026 at 5:49 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacksby Lawrence Abrams on 1 Ottobre 2026 at 10:42 pm
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
- Alleged KillSec Ransomware Mastermind a 16-Year-Oldby Jai Vijayan on 1 Ottobre 2026 at 9:37 pm
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
- Autonomous AI agents tried to hack US, Canadian government websitesby Ionut Ilascu on 1 Ottobre 2026 at 8:52 pm
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
- Microsoft says threat actors are ahead in the early AI raceby Lawrence Abrams on 1 Ottobre 2026 at 7:32 pm
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Serversby info@thehackernews.com (The Hacker News) on 1 Ottobre 2026 at 4:55 pm
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected
















