Check Point SmartConsole: authentication bypass actively exploited
Check Point has fixed a critical vulnerability in the SmartConsole login process, tracked as CVE-2026-16232, which allows an unauthenticated attacker to obtain an application token and gain access with full administrative privileges. Reports indicate that the bug is already being exploited in the wild, although the direct impact currently concerns only a limited number of customers. The flaw affects Security…
Read the article →Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes
Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularly dangerous because simply opening or even just viewing the email…
Read the article →Iranian attacks against Siemens and Schneider industrial systems
U.S. agencies have warned that Iranian cyber actors are targeting Siemens and Schneider industrial systems used in American environments. The focus on ICS components is significant because it is not only about data or…
Read the article →Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
Researchers at the University of California, San Diego, have discovered that at least 2.2 million cars with dealer-installed anti-theft systems are vulnerable to a Bluetooth attack. An attacker could lock or unlock the doors…
Read the article →Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code execution. Researchers at watchTowr and other analysts have observed…
Read the article →WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all the way to full site compromise. After the patch was…
Read the article →Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
The Qilin ransomware operation is abusing CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, to gain unauthorized access to corporate networks. The flaw affects GlobalProtect portals and gateways and especially impacts unpatched systems, which…
Read the article →ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
The CVE-2026-6875 vulnerability in the ServiceNow AI Platform allows an unauthenticated attacker to execute remote code on self-hosted instances. Searchlight Cyber disclosed it on July 14, 2026, and ServiceNow released patches the same day,…
Read the article →Brazilian banking trojan expanding into Portugal
A banking trojan born in Brazil is actively spreading in Portugal, taking advantage of the fact that criminals share the same language as their targets and can therefore build more credible campaigns. Linguistic proximity…
Read the article →Ransomware on Japan’s cold chain
A ransomware attack hit a Japanese food logistics company, causing delays and disruptions in the distribution chain for frozen products to thousands of customers. Among those affected are said to be major restaurant chains,…
Read the article →
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
Italy fines WINDTRE €1.7 million after two customer data breaches
Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
Public-sector AI ethics: Italy’s governance debate meets France Travail’s algorithmic targeting
OpenAI: the models escaped the sandbox and hit Hugging Face
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
Italy fines WINDTRE €1.7 million after two customer data breaches
Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
Public-sector AI ethics: Italy’s governance debate meets France Travail’s algorithmic targeting
OpenAI: the models escaped the sandbox and hit Hugging Face
OT security: the ‘air gap’ is a myth and resilience must be designed
PR3TACK wants to map threats before attackers use them
China’s Kimi K3 is testing Western AI pricing, chips, and sovereignty- AGCOM says AI is reshaping access to information and pluralism
- Italy’s data centers are becoming a strategic industrial asset
- ANPR data access via PDND changes the way the Italian public sector works
- Age verification tools raise privacy, security and civil-liberties trade-offs
- Most open-source AI projects still fail to reach production
- The ‘augmented customer’ is reshaping financial advice in the AI era
- European AI sovereignty is becoming a strategic issue in finance, defense and healthcare
- Italian companies are moving AI oversight into finance as agentic projects struggle to reach production











