Search/cnn
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
cnnmoney portfolio
Connections
20 relationships
How to protect yourself from webcam spying: five simple steps | Kaspersky official blog
These days, it can feel like there’s a camera watching us from every corner: a video doorbell by the front door, a laptop webcam in the home office, an IP baby monitor in the children’s room, a smart TV with a camera and microphone in the bedroom, a robot vacuum with a navigation camera roaming around the house… Even a smart cat feeder could be spying on you! And any one of these cameras can easily become a useful tool for extortionists, blackmailers, or simply curious malicious actors. You don’t have to look far for examples. South Korea, late 2025: not one device, but 120,000 IP cameras were hacked . The criminals sold intimate footage and recordings of people’s everyday lives by subscription in private chats. In this article, we look at exactly where the threat comes from, and outline five rules that can greatly reduce your chances of becoming the star of a voyeur’s show. Real-life cases of surveillance Hotel porn by subscription Unfortunately, reports of miniature cameras being discovered in hotel rooms and rental apartments have become almost routine. Technically, these belong to a separate category of devices — “spy cameras” disguised as power outlets, smoke detectors, or alarm clocks. We’ll explain a little later how to detect them. Criminals don’t just publish footage from spy cameras — they even livestream it. Access to intimate videos, naturally, isn’t free. In some regions, criminals have built an entire infrastructure around spy cameras: some people install the cameras, others process the footage, while still others sell access through the dark web or messaging apps. Victims typically discover that there was a hidden camera in their hotel room purely by accident , after coming across videos of themselves on porn sites. Hunting motorists Another popular attack vector is hacking dashcams that can connect to the internet. These devices are tempting targets for attackers: their security is often weak, while the footage clearly shows license plates, road signs, and addresses on buildings. The recordings also contain detailed metadata, including exact dates, GPS coordinates, and more. This can allow criminals to identify a victim’s regular routes, determine where their car is parked, or even eavesdrop on conversations with passengers. There can be enough information for full-scale surveillance, car theft, or even blackmail if the camera records conversations and video inside the car. Stalking Not all stolen camera footage is the result of attacks by professional cybercriminals looking to profit from it. Sometimes, stalkers hack webcams to spy on specific people — often someone they know. For example, in 2025 a case came to light in which a man had been spying on his colleagues for years through their home IP cameras. All of the victims were women, who had no idea they were being watched. In another case, a man monitored his ex-wife and daughter through an intercom system and IP cameras. He made no attempt to hide the fact that he was spying on his own family, and even sent his daughter screenshots from the webcam. As a result, she eventually had to move away. Why does this happen? Neglecting basic cybersecurity rules This is probably the main reason IP cameras get hacked. Most users never change the factory-default passwords on their routers, smart devices, or the apps connected to them. Such passwords are essentially public knowledge. They often use simple combinations such as “admin/admin” or “root/1234”, which are known worldwide and can be guessed in a matter of seconds — no sophisticated algorithm is required. This is exactly what recently allowed attackers to hack 120,000 cameras in South Korea. Irresponsible camera manufacturers Even when manufacturers give assurances that camera data is stored only locally, in practice this is often far from the truth. For example, in 2022 researchers discovered that one popular range of video cameras sent snapshots to the manufacturer’s server every time a person appeared in the frame . And that wasn’t all: remote access to all cameras’ recordings was available through URLs generated in a predictable way — making them relatively easy to generate or guess. At the same time, the company claimed that its cameras used end-to-end encryption, stored recordings exclusively on the device, and didn’t transmit data to external servers. Incidentally, the supposedly “secure encryption” was implemented using a fixed key that was identical for every user. And the key itself could easily be found in the source code published by the manufacturer. In short, if a device has a lens and Wi-Fi, be prepared for the possibility that sooner or later a serious security flaw will be discovered in it. Search engines for vulnerable devices are becoming increasingly popular To access a camera, an attacker often only needs to know its IP address and try a handful of common passwords. There are search engines that index not websites, but devices and their open ports: webcams, routers, industrial controllers, medical equipment — you name it. If an IP camera requires no username and password, or is “protected” by the default “admin/admin” credentials, it may easily be discovered and added to the database of an OSINT service. Journalists and researchers have used such services to find publicly accessible cameras in children’s rooms, offices, hospital operating rooms, banks, and shops. So what can you do? What can you do at home or in a small office without a dedicated security team? These five simple recommendations can help. 1. Research the manufacturer When choosing an IP camera model, make sure you check whether cameras from that manufacturer have been hacked before — for example, by searching for “IP camera hack manufacturer name “. Then visit the Support section of the manufacturer’s website and check the date of the most recent firmware update both for the model you are considering and older models. If you find that firmware has not been updated for more than six months, or that updates are released irregularly, you may want to choose a different model. Most cameras run specialized embedded versions of Linux, and more than 2,300 vulnerabilities were recorded in the Linux kernel in the first six months of 2026 alone. If a manufacturer fails to update its firmware regularly, sooner or later a security hole is almost certain to appear in its cameras. Consider models from major manufacturers if you don’t want to end up with a whole collection of vulnerabilities and virtually no chance of them ever being patched. Cheap cameras from obscure companies with limited functionality and weak protection can ultimately cost you dearly. 2. Disable unnecessary features The fewer third-party cloud storage services involved in your surveillance system, the better. When choosing a camera, look for a microSD card slot, or support for a home network-attached storage device (NAS), so you can store all recordings locally. Ideally, the camera should be able to operate entirely within your local network without transmitting data to the cloud or the manufacturer’s servers — with viewing available over the LAN or through a secure connection  to your home or office. When buying other smart home appliances, consider whether you really need a built-in camera in, say, a smart TV, smart speaker , robot vacuum , or automatic pet feeder . Each and every one of these devices expands the potential attack surface. After buying an IP camera, go through its settings — usually available in the manufacturer’s app or through the camera’s web interface — and disable anything you don’t need. Pay attention to features related to person recognition, artificial intelligence, system permissions, discovery of other devices on the network, and cloud storage. If you don’t use a feature, feel free to disable it. In the network settings, make sure UPnP (Universal Plug and Play) is disabled or even absent as an option. UPnP can allow the camera to make itself accessible to other devices over the internet. Check that P2P access to the webcam is disabled or unavailable, so that the camera does not connect to external servers and cannot be reached from the internet without your direct control. Make a habit of checking who’s logged into your account and who still has access to your recordings. If you gave a friend access to your webcam so they could keep an eye on your dog while you’re away, remember to remove any unnecessary sessions afterwards. And if you’ve recently ended a relationship, pay particularly close attention to whether an ex-partner still has access. For more on this, see Post-breakup digital hygiene: what to check and shut down . 3. Change the default settings Factory-default passwords have been known to attackers for years. If you haven’t changed the username and password for your router or IP camera, an attacker may be able to gain access in a matter of seconds. Replace your router’s factory-default username and password with unique, long credentials. You can do this through the router’s web interface — we explain how to access it below. To generate and store strong, unique passwords, we recommend using Kaspersky Password Manager . If your camera is linked to an account on a website or in an app, make sure you use a strong password there too, and enable two-factor authentication or passkey authentication whenever possible. By the way, both 2FA tokens and passkeys can also be stored in Kaspersky Password Manager  and synchronized across all your devices. Update the firmware on both your router and IP camera to the latest versions, even if you just bought the device, and make regular updates a habit. Large-scale IP camera hacking campaigns often exploit long-known vulnerabilities that can only be fixed by installing updates. 4. Put all cameras and smart devices on a separate Wi-Fi segment We recommend segmenting your home Wi-Fi into separate subnets. You’ve probably encountered this arrangement in cafés, which often have one Wi-Fi network for staff and another for guests. All IP cameras and other smart home gadgets should ideally be moved to a separate Wi-Fi network and completely isolated from laptops, phones, and other work devices. Better still, IP cameras should be isolated from all other devices by creating a dedicated Wi-Fi network specifically for them. Most modern routers allow you to create at least two Wi-Fi networks — a primary network and a guest network — while more advanced models can support more. That way, even if your camera is hacked, the attacker won’t be able to reach your other devices or access sensitive files. How to open your router’s web interface Enter the router’s IP address in your browser’s address bar. It is usually printed on a label on the bottom of the router. Common IP addresses for home routers include 168.0.1 , 192.168.1.1 , and 10.0.0.1. Sign in on the page that opens. Most routers have a default username and password, which are usually also printed on the same label. Some routers may ask you to create your own username and password. We recommend choosing a strong one and storing it in Kaspersky Password Manager . Factory-default passwords have long been known to attackers, and if you don’t change your router password, they may be able to get into your home network with ease. Open the settings and look for sections related to Wi-Fi segmentation or the creation of subnets or guest networks. For detailed setup instructions, consult your router’s manual or the support section of the manufacturer’s website. For more advice on protecting your smart home, see our post How to secure your smart home . 5. Learn how to detect hidden cameras — both at home and while traveling Our final set of recommendations is not about configuring the camera itself, but about good security hygiene. Make a habit of checking the client list on your router. If you see an unknown device with a strange name or MAC address, investigate what it is and why it’s connected to your home network. Our security solution  includes a dedicated Smart Home Monitor component . This feature can alert you when a new device connects to your home wired or wireless network, provide simple recommendations for improving home network security, and identify weak router passwords and insecure encryption. When traveling, we recommend checking hotel rooms and rental properties for hidden recording devices: inspect places that offer a “convenient” view of the room, such as ventilation grilles, smoke detectors, power outlets, and decorative objects; in the dark, use your smartphone as an improvised optical detector: turn on the flashlight and camera, slowly scan the room, and look for distinctive reflections from a camera lens; use the front-facing camera to look for infrared light sources that are invisible to the human eye — this can help you spot the IR illumination used for “night vision”. For more practical methods of finding spy cameras, see our article Four ways to find spy cameras . What else you should know about surveillance and cameras: Korean-style webcam breach: 120 000 IP cameras hacked IP camera security: the bad, the ugly, and the evil Airbnb security: tips for safe travel Lumos: IoT device detection system Finding hidden cameras with your smartphone’s ToF sensor
kaspersky.comAug 19, 2026extracted
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad content. Malicious links, infected attachments, spam. Secure email gateways were built for this. Scan the message, match the signature, drop the bad stuff. That era is largely handled. Phishing 2.0 is bad intent. Business email compromise, executive impersonation, fake invoices, wire fraud. There is no malicious payload to scan, only social engineering that reads as a normal request from a person you trust. Gateways are blind to it because there is nothing in the content to flag. Behavioral analysis is the only thing that catches it, which is why some of us have spent the better part of a decade building AI that learns how your people actually communicate. Phishing 3.0 is AI-powered and multi-channel. GenAI writes the lure. Deepfakes carry it into voice and video. The campaign spans email, collaboration tools, and live calls. The attacker is no longer a person typing. It is increasingly an agent that researches, drafts, sends, and adapts on its own. The third stage changed the economics of attacking you. The Attacker Now Runs an Agent Reconnaissance used to cost an attacker time. A human had to read your website, scrape job postings, map your suppliers, and study a few executives on social media before writing something believable. Agentic AI removes that cost. An agent can summarize your public footprint, pull from GitHub and cloud documentation, identify who reports to whom, and generate a target-specific pretext in seconds, then do it again for the next 10,000 organizations. The quality of the lure goes up. The clumsy, misspelled phish is retiring, replaced by interactive lures that hold a conversation. Microsoft has tracked phishing platforms that generate tens of millions of messages a month [3], and in a 2026 Dark Reading readership poll, 48% of security professionals ranked agentic AI as the top attack vector for the year, ahead of deepfakes and every other option [4]. The blast radius widens too. You no longer have to be a high-value target to get a tailored attack. When reconnaissance is free, every organization is worth personalizing, and the small teams that assumed they were too minor to bother with get swept into automated campaigns that arrive looking hand-crafted. The worst of it lands when the lure leaves the inbox altogether. In one widely reported case at engineering firm Arup, the attack opened with a phishing email impersonating the company's UK-based CFO. When the employee hesitated, a deepfake video call with what looked like several familiar colleagues closed the deal. Every other face on the call was synthetic. The employee approved 15 transfers worth about $25 million [5]. No amount of email hygiene would have caught that. The attack went after trust in what employees could see and hear, and that trust is exactly what attackers have learned to exploit. The Data Says Trust Is Already Broken One incident, however expensive, is still an anecdote. The pattern shows up when you ask the people who run security for a living. In January 2026, Osterman Research published a study, commissioned by IRONSCALES, of 128 security and IT leaders at US organizations of 1,000 to 5,000 employees [1]. The findings are blunt. 88% experienced at least one incident that undermined trust in their digital communications over the prior year. 82% said they see heightened threat actor interest in their specific industry. 60% lack confidence in their ability to counter deepfake attacks, even with the training they run today. 55% said a failed response to a trust-based attack raises the likelihood of a full breach. More than a third saw attackers masquerade as a trusted vendor or partner. The tools most organizations run assume a threat they can find inside a message. The modern attack impersonates trust across channels where there is nothing to scan, so those tools never get their shot. The gateway math reinforces it. IRONSCALES analysis of production email traffic shows Microsoft 365 EOP missing 293 phishing messages per 100 mailboxes every 30 days, and Google Workspace missing 350, in both cases well above what a well-tuned gateway catches [2]. Those numbers are the daily baseline of what reaches employees after the perimeter has had its say. Why the Old Response Model Breaks The traditional model runs block, then detect and respond. Block what you recognize, and when something gets through, investigate and clean up after. Against a human attacker sending a few hundred emails, that cadence held. Against an agent generating personalized, conversational, multi-channel attacks faster than a person can read them, detect and respond is always one step behind. The volume alone makes the point. In a 2026 study by Crogl and the Ponemon Institute, enterprise SOCs reported an average of 4,330 alerts a day and investigated just 37% of them [6]. You cannot out-hire an agent. You can only out-automate it. So the response model has to add a third posture in front of the other two. Preempt. Anticipate the attack that is being built for you, harden detection before the first message lands, and let automation handle the routine so humans spend their time on the decisions that need judgment. The Defender Needs an Agent Too Phishing 3.0 forces a symmetry. If the attacker is running agents, the defender has to run them too, or accept a permanent speed disadvantage. That shift is already underway. In the same Crogl study, security teams with the strongest postures had adopted AI in the SOC at a far higher rate than their peers, 68% against a 46% average[6]. Microsoft reports that its autonomous alert triage agent identified 6.5 times more malicious emails than manual review and saved one health network, St. Luke's University Health Network, more than 200 analyst hours a month [7][8]. The agent stops being a chatbot bolted onto a dashboard and becomes a teammate that investigates end to end and hands a human a verdict instead of a ticket. At IRONSCALES we build for this. One anticipates. One investigates. One educates. Our Red Teaming Agent runs the same open-source reconnaissance an attacker would, studying your organization across social media, code repositories, and public filings, then hardens and personalizes detection before an attack is ever sent. Our Phishing SOC Agent investigates threats at the level of an L2 analyst, compressing forensics that take hours into minutes. Our Phishing Simulation Agent trains employees against reconnaissance-based attacks modeled on the tactics actually aimed at them, rather than generic templates. Underneath all three, our Adaptive AI learns each organization's communication patterns and sharpens on real-world signal from a network of tens of thousands of security professionals. The product names matter less than the principle. Preemption requires an agent on the defensive side that thinks the way the offensive one does. A defense that only reacts to what already arrived is bringing yesterday's model to a fight that has moved on. What This Means for Practitioners Stop measuring email security only by what it blocks at the perimeter. The meaningful number is what still reaches the inbox after the gateway, because that is where the modern attack lives. Ask any vendor for their post-delivery miss rate and treat vagueness as an answer. Extend the threat model past email into voice and video. The Arup case was a video call, not a message. If your identity verification stops at the inbox, the most expensive attacks will route around it. Judge automation by autonomy, not dashboards. A tool that surfaces more alerts for a human to read is adding to the daily alert pile. A tool that investigates and resolves is subtracting from it. Ask what percentage of incidents get handled without a human touching them. Treat employee training as reconnaissance-aware. Generic simulations teach people to spot generic phish. The attacks aimed at them are personalized, so the practice should be too. Phishing 3.0 is not a forecast. Attackers are already running agents, the deepfake losses are already being counted, and the data shows trust is already being exploited faster than most defenses can respond. The organizations that come through it well will be the ones that stopped trying to win a speed race against software with human hands alone, and put an agent of their own on the field. References Osterman Research, "Rebuilding Trust in Digital Communications," commissioned by IRONSCALES, January 2026. Survey of 128 security and IT leaders at US organizations of 1,000 to 5,000 employees, fielded September to October 2025. https://ironscales.com/rebuilding-trust-in-digital-communications-report-download IRONSCALES, analysis of production email traffic across its customer base (post-delivery miss rates for Microsoft 365 EOP and Google Workspace, per 100 mailboxes per 30 days). Internal data; figures available on request. Microsoft Security, "Threat actor abuse of AI accelerates from tool to cyberattack surface," Microsoft Security Blog, April 2, 2026. https://www.microsoft.com/en-us/security/blog/2026/04/02/threat-actor-abuse-of-ai-accelerates-from-tool-to-cyberattack-surface/ Dark Reading, "2026: The Year Agentic AI Becomes the Attack-Surface Poster Child," 2026. https://www.darkreading.com/threat-intelligence/2026-agentic-ai-attack-surface-poster-child CNN Business, "Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee," May 16, 2024. https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk Crogl and Ponemon Institute, "The State of SecOps and the Deployment of AI in the SOC," 2026. Survey of 649 North American IT and security practitioners. https://www.crogl.com/newsroom/state-of-secops-ai Microsoft, "St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents," Microsoft Customer Stories, 2026. https://www.microsoft.com/en/customers/story/25330-st-lukes-university-health-network-microsoft-security-copilot Microsoft, "From alert overload to decisive action: How Security Copilot agents are transforming security and IT," Microsoft Community Hub, 2026. https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213 Note: This article has been expertly written and contributed by Steve Malone, Chief Product and Strategy Officer, IRONSCALES.
thehackernews.comAug 19, 2026extracted
L’acqua: risorsa, dominio, infrastruttura e bersaglio da colpire (e hackerare)
L’acqua non è soltanto una materia ma è anche un dominio su cui si misurano gli interessi geopolitici di molteplici attori Negli ultimi anni l’acqua ha assunto una importanza sempre maggiore nelle relazioni internazionali e oggi è diventata senza dubbio l’elemento verso cui convergono gli interessi (e i conflitti) dei principali attori statali e non-statali globali. A causa di una peculiare combinazione di fattori politici, climatici, tecnologici, commerciali e sociali, oggi l’acqua è indubbiamente il bene più conteso del mondo. Infatti, lo stesso elemento può essere visto sia come una risorsa e una materia prima (indispensabile alla vita umana, ma anche per lo sviluppo delle tecnologie legate all’intelligenza artificiale) sia come una infrastruttura (analogamente alla rete ferroviaria o elettrica). E, ovviamente, anche come campo di battaglia di cui contendersi il dominio sopra e sotto la superficie. L’acqua non è soltanto un bene primario Se considerata come una materia prima, l’acqua è sempre stata un bene primario senza la quale sarebbe impossibile la vita umana. Nei secoli è poi divenuta fondamentale anche nel settore energetico. Sia con il suo impiego direttamente nella produzione di energia (basta pensare ai mulini o alle centrali idroelettriche), sia indirettamente con il suo utilizzo in altre funzioni. In quest’ultimo caso, l’esempio più evidente sono i sistemi di raffreddamento delle centrali nucleari. Il legame tra l’acqua e l’energia nucleare ha avuto ampia eco mediatica soprattutto nelle ultime settimane: le numerose ondate di caldo che hanno colpito l’Europa hanno infatti portato allo spegnimento (o al rischio di spegnimento) di diversi impianti. A luglio la Francia ha spento tre reattori e ridotto la potenza di ulteriori sette per evitare di scaricare nei fiumi acqua eccessivamente calda in un momento in cui il Paese era colpito da temperature record. L’Ungheria rischia di dover spegnere l’unica centrale del Paese perché i livelli del Danubio sono ai minimi storici e mancherebbe l’acqua per il raffreddamento dell’impianto. La Romania ha effettuato esplosioni controllate per deviare l’acqua di raffreddamento dal Danubio all’ultimo reattore funzionante in attività. L’Europa sta attraversando settimane di crisi in termini di approvvigionamento idrico L’Europa sta attraversando settimane di crisi in termini di approvvigionamento idrico, trasporto fluviale e produzione di energia, rendendo ancora più evidente la necessità di costruire una idrostrategia (a livello nazionale e, auspicabilmente, comunitario e globale) per la gestione di questa risorsa fondamentale. La diminuzione della produzione di energia nucleare consente inoltre di analizzare un ulteriore ambito in cui l’acqua è divenuta fondamentale in questi ultimi anni: la corsa all’Intelligenza Artificiale (AI). Questa è il terreno di competizione tra le due maggiori potenze tecnologiche mondiali. Gli Usa e la Cina. E, trattandosi di un settore estremamente energivoro, gli attori pubblici e privati che operano in questo campo hanno iniziato a rimettere in funzione centrali nucleari dismesse o costruire impianti nuovi per per fare funzionare l’AI . Infatti, sebbene sia spesso immaginata come una entità astratta, l’Intelligenza Artificiale poggia in realtà su basi fisiche nel mondo reale: datacenter, infrastruttura di rete e cavi sottomarini , ad esempio. In particolare, i datacenter assorbono enormi quantità di energia e, soprattutto, di acqua per il raffreddamento. Un rapporto pubblicato dallo United Nations University Institute for Water, Environment and Health (UNU-INWEH) e intitolato “ Environmental cost of AI’s energy use ” ha stimato che nel 2025 i data center abbiano consumato una quantità di acqua sufficiente a coprire il fabbisogno idrico domestico annuo di base di oltre 600 milioni di persone nell’Africa subsahariana. Nei paragrafi precedenti si è analizzata l’acqua in quanto materia prima, ma in realtà questa è anche un dominio su cui si misurano gli interessi geopolitici di molteplici attori. Interpretazioni molteplici In questo senso, l’acqua può essere vista in due modi: come una infrastruttura di comunicazione – al pari di una rete ferroviaria o autostradale, con il suo traffico e le sue arterie più o meno congestionate – oppure come un campo di battaglia, soprattutto in prossimità di regioni al centro di conflitti. E queste due visioni non sono in contrapposizione ma si sovrappongono, rendendo sfumati i confini tra interessi militari, economici, commerciali, energetici e politici. Se la immaginiamo come una infrastruttura di comunicazione, l’importanza delle vie d’acqua diventa maggiormente evidente quando queste vengono interrotte. È il caso, ad esempio, della nave Ever Given che nel 2021 rimase incagliata nel Canale di Suez per diversi giorni bloccando uno dei chokepoint più importanti del mondo e causando ripercussioni a catena sulle catene di approvvigionamento globali. Oggi l’esempio più vistoso di queste interruzioni è lo Stretto di Hormuz, che dall’inizio della guerra tra Usa (e Israele) e Iran nel febbraio 2026 è rimasto pressoché ininterrottamente chiuso al traffico navale. Il blocco di Hormuz ha portato ad un aumento dei prezzi del petrolio e dell’energia in tutto il mondo, mostrando in modo chiaro come il controllo di alcuni tratti di mare possa garantire un potere negoziale senza precedenti. I rischi per le catene di approvvigionamento Meno noto, ma con un potenziale altrettanto pericoloso per le economie e le catene di approvvigionamento mondiale, è lo Stretto di Bab el-Mandeb, che consente l’accesso dall’Oceano Indiano al Mar Rosso e che quindi, insieme al Canale di Suez, rappresenta la via di transito privilegiata che collega l’Asia Orientale con l’Europa. Dal 2023 il gruppo yemenita degli Houthi ha iniziato ad attaccare le navi in transito da Bab el-Mandeb causando un crollo verticale del traffico marittimo nella regione e un ulteriore blocco per le esportazioni di greggio da parte dei paesi produttori (Arabia Saudita, Emirati Arabi e Stati del Golfo Persico in primis), che hanno sempre maggiori difficoltà a fare uscire il greggio via mare dalla regione. Gli Houthi, che insieme ad Hamas e Hezbollah, fanno parte dell’“Asse della Resistenza” sostenuta dall’Iran, si inseriscono quindi in una più ampia situazione di crisi del Mar Rosso . Come operano i droni marini Le vicende di Hormuz e di Bab el-Mandeb consentono di cogliere appieno le sfumature tra i due modi di concepire l’acqua come infrastruttura di comunicazione e come campo di battaglia. Questo perché il traffico commerciale marittimo mondiale è vincolato da alcune vie d’acqua imprescindibili, i cosiddetti chokepoint (come Hormuz e Bab el-Mandeb, appunto, ma anche Suez, Gibilterra, il Bosforo o il Canale di Panama, per citare solo i più famosi) che però possono divenire anche bersagli di attacchi. In particolare, il dominio marittimo è stato attraversato negli ultimi anni da una rivoluzione costituita dall’avvento dei droni marini. Si tratta di veicoli senza pilota in grado di muoversi sulla superficie dell’acqua o anche al di sotto della superficie. Il vantaggio principale di questi droni marini (in gergo UUV, Underwater Unmanned Veichles , o USV, Unmanned Surface Veichles ) è il loro costo ridotto che una produzione rapida e in grandi quantità. In questo modo è possibile impiegarli sia per colpire (o anche solo minacciare di colpire) le imbarcazioni civili e mercantili, sia in contesti bellici per attaccare le navi militari, come accaduto più volte nel Mar Nero nel contesto del conflitto tra Russia e Ucraina e in cui Kiev ha impiegato i droni marini per colpire la flotta di Mosca . L’importanza dei nuovi vettori L’importanza dei droni marini è confermata anche dalle più recenti notizie che evidenziano come questi stiano diventando fondamentali nelle strategie difensive di Paesi più piccoli e meno forti militarmente , con la necessità di dover tutelare spazi di mare di importanza strategica. È il caso di Singapore, che sta sviluppando e dispiegando veicoli sottomarini autonomi (AUV) in grado di rilevare e identificare mine navali allo scopo di garantire la sicurezza nello Stretto di Singapore (attraverso cui transita un traffico marittimo anche superiore a Hormuz). Analogamente, anche la Danimarca sta iniziando a testare e sviluppare droni sottomarini per attività di sorveglianza del fondale marino nei pressi della Groenlandia (recentemente finita nelle mire espansionistiche del Presidente Trump) e, soprattutto, per la protezione di infrastrutture critiche come i cavi sottomarini. Un bersaglio durante le guerre Infine, rimanendo in tema di conflitti, l’acqua diventa anche un bersaglio per gli attacchi durante le guerre, soprattutto in zone in cui questa rappresenta un bene disponibile in quantità ridotte. È il caso del Medio Oriente e della già citata guerra iniziata da Usa e Israele contro l’Iran a febbraio 2026. Durante il conflitto numerosi bombardamenti e attacchi hanno colpito impianti di desalinizzazione e strutture per l’approvvigionamento idrico dell’Iran e di numerosi Paesi dell’area. A marzo Teheran ha accusato Washington di aver colpito un impianto di desalinizzazione nell’isola di Qeshm . Al contempo, due strutture per lo stoccaggio di acqua sono state colpite a Kuhestak , nel distretto di Bemani, causando difficoltà di approvvigionamento per circa 20.000 persone. A luglio 2026 l’Iran ha colpito un impianto di desalinizzazione in Kuwait , un Paese che non ha pressoché alcuna fonte naturale di acqua dolce e che ricava il 90% dell’acqua potabile da questi impianti. Precedentemente, a marzo, un analogo impianto di desalinizzazione del Bahrain è stato danneggiato da un drone lanciato da Teheran . Infrastrutture idriche degli Usa nel mirino degli hacker criminali Negli ultimi giorni l’escalation della guerra potrebbe essersi ampliata anche al dominio cibernetico. Tra la fine di luglio e l’inizio di agosto 2026, infatti, sono stati segnalati attacchi informatici da parte di attori ostili in diversi impianti idrici e di trattamento delle acque reflue in sette Stati USA (i cui nomi non sono stati diffusi, sebbene i media identifichino Michigan e Minnesota tra questi sette). Nel solo Minnesota sono stati colpiti circa 30 sistemi che hanno portato a interruzioni significative dei servizi. Usa Idrici I media riportano che gli hacker hanno preso di mira i computer automatizzati che controllano i sistemi, modificandone le password per bloccare l’accesso agli operatori. Si è anche proceduto ad inviare diversi avvisi sull’acqua che fosse a temperatura di ebollizione costringendo a gestire i sistemi manualmente. Sebbene non ci sia ancora stata l’identificazione degli autori degli attacchi – e nonostante Trump abbia puntato il dito contro Tim Walz, il governatore dello Stato e appartenente al Partito Democratico –, il sospetto principale riportato dai media è che questi provengano dall’Iran. Questi attacchi a danno degli Usa dimostrano come anche l’acqua possa diventare un bersaglio della guerra informatica. Seguici anche sul nostro canale WhatsApp Vai al sito di Cybersecurity Italia. L'articolo L’acqua: risorsa, dominio, infrastruttura e bersaglio da colpire (e hackerare) sembra essere il primo su CyberSecurity Italia .
cybersecitalia.itAug 17, 2026extracted
Intelligence Usa, cominciano i tagli voluti da Bill Pulte (scelto da Donald Trump)
Grande protesta da parte dei Democratici, secondo cui “è a rischio la Sicurezza Nazionale“. L’intelligence Usa verso un ridimensionamento o almeno questa sembrerebbe la direzione del Direttore ad interim Bill Pulte (scelto da Donald Trump) che ha deliberato un grande piano di licenziamenti. Lo ha riportato la Cnn, aggiungendo che sarebbero già cominciati numerosi licenziamenti. Fortissime le proteste dei Democratici, secondo i quali “è a rischio la Sicurezza Nazionale“. I maggiori interventi riguardano l’Office of the Director of National Intelligence (ODNI), in particolare antiterrorismo e controspionaggio. Pulte si sarebbe presentato nella sede dell’ODNI già giovedì, un giorno prima dell’inizio ufficiale del suo incarico, dopo aver richiesto l’elenco completo dei dipendenti dell’ufficio per eventuali licenziamenti. Durante la visita avrebbe incontrato avvocati e funzionari. Gli ultimi cambiamenti interni L’arrivo anticipato di Pulte, sottolinea sempre la Cnn, avrebbe colto di sorpresa gran parte del personale dell’ODNI, compresa l’ormai vecchia Direttrice Tulsi Gabbard. Gabbard, che ha annunciato le proprie dimissioni il mese scorso, avrebbe ricevuto la notifica della visita di Pulte praticamente in prossimità della stessa. Già nelle scorse settimane erano emerse indiscrezioni su una possibile ristrutturazione dell’agenzia. La Reuters aveva infatti riferito di un avvertimento per il personale, da parte dei dirigenti dell’ODNI, di prepararsi a significativi tagli. Donald Trump ha infatti espresso l’intenzione di ridurre ulteriormente le dimensioni dell’organizzazione. Negli ultimi mesi, oltre ai dibattiti sui possibili cambiamenti, l’ODNI aveva già subito una profonda trasformazione. Sotto la guida di Gabbard, c’era stata una riduzione del personale del 40%. Un intervento, che aveva suscitato dibattiti sull’impatto operativo della misura, in particolare visto l’attuale scenario internazionale. Le perplessità sulla nomina La nomina di Pulte ha suscitato non poche perplessità, in quanto senza esperienze nella Sicurezza Nazionale statunitense. Dallo scorso anno, l’imprenditore ha inoltre ricoperto la carica di Direttore della Federal Housing Finance Agency (FHFA) e di vertice di FNMA, società specializzata in mutui. Diversi esperti hanno considerato questa nomina un ulteriore segnale della volontà di Donald Trump di affidare incarichi chiave a figure politicamente allineate alla sua Amministrazione. Nel nuovo ruolo, Pulte dovrà supervisionare tutto il comparto dei servizi informativi (18 agenzie), comprese la Central Intelligence Agency (CIA) e la National Security Agency (NSA). La lettera dei Democratici Visti i tagli, i rappresentanti del Partito Democratico ai vertici delle Commissioni dei Servizi alla Camera e al Senato hanno scritto, lo scorso lunedì, una lettera nei confronti del Direttore ad interim. Di qui: “Data la sua mancanza di esperienza all’interno della comunità di intelligence, è difficile immaginare che abbia già maturato, in un lasso di tempo così breve, opinioni pienamente fondate“. In particolare, “su come ridimensionare gli uffici senza compromettere la Sicurezza Nazionale“. rischierebbero di compromettere la missione di un’organizzazione creata espressamente dopo l’11 settembre per prevenire futuri attacchi terroristici di questo tipo,
cybersecitalia.itJun 23, 2026extracted
Over 900 US gas station tank gauge systems exposed to attacks
Over 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been found exposed online and are vulnerable to ongoing attacks. ATG systems are electronic monitoring devices used to remotely track fuel, chemicals, or other liquids in storage tanks, automating inventory control, environmental leak detection, and regulatory compliance. While they're commonly used at gas stations to monitor fuel tank levels, they can also be found in industrial settings to track chemical storage tanks. On Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA, the Department of Energy, and other U.S. government partners issued a joint advisory warning critical infrastructure organizations to secure internet-exposed ATG systems against ongoing attacks. The federal agencies warned that threat actors target such devices to alter system settings in command execution attacks after exploiting various security flaws, including hardcoded credentials, authentication bypasses, SQL injection vulnerabilities, OS command execution flaws, and privilege escalation weaknesses. "The recent malicious cyber activity observed by the authoring organizations—which the U.S. government has not yet attributed to a nation-state or threat actor group—involves cyber threat actors compromising internet-exposed ATG systems and subsequently modifying them through command execution," the joint advisory warned. As CISA cautioned, following successful compromises, the attackers could disable system alerts, increasing the risk of leaks or equipment failures and even causing permanent damage to the targeted tank systems. In light of CISA's advisory, Internet security watchdog Shadowserver warned today that over 1,000 ATG systems were exposed online, with the vast majority (909 devices) in the United States. "We added scanning of Automatic Tank Gauge (ATG) systems to our Accessible ICS reporting with 1061 IPs seen on 2026-06-05 (on port 10001/tcp)," Shadowserver said. "This is after weeding out vast majority which appear to be honeypots (including ports 8001/9001)." Critical infrastructure organizations are advised to restrict remote access to ATG systems from the Internet as soon as possible and implement controlled access through firewalls, VPNs, or access control lists. They should also replace default passwords on vulnerable devices with strong credentials, apply security updates, monitor systems for unauthorized changes, and implement multi-factor authentication where possible. CISA's warning comes after a May CNN report that Iranian hackers had breached ATG systems connected to the Internet at multiple gas stations across the United States. Iranian hacking groups were linked to these incidents based on their previous history of targeting fuel management systems and other industrial control technologies. After hacking the devices with weak or nonexistent passwords, the attackers reportedly manipulated the display readings but did not alter the actual fuel levels. Although these incidents didn't cause any physical damage, they raise concerns that such attacks could hinder automated fuel leak detection and similar safety-related functions. In April, another joint advisory issued by U.S. federal agencies linked Iranian state-backed hackers to attacks targeting Rockwell Automation/Allen-Bradley PLC devices since March 2026, causing financial losses and operational disruptions. Cybersecurity firm Censys reported one day later that 74.6% (3,891 hosts) of such industrial control systems found exposed online globally were from the United States. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 5, 2026extracted
CISA warns of cyberattacks targeting fuel tank monitoring systems
CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors. The cybersecurity agency says that ATG systems are commonly used in the Energy, Chemical, Food and Agriculture, and Transportation Systems sectors to remotely monitor storage tank levels, temperatures, and potential leaks. The US government says threat actors are targeting exposed devices and modifying system settings through command execution. "The recent malicious cyber activity observed by the authoring organizations—which the U.S. government has not yet attributed to a nation-state or threat actor group—involves cyber threat actors compromising internet-exposed ATG systems and subsequently modifying them through command execution," the advisory states. According to the agencies, attackers are gaining access through authentication bypass vulnerabilities, hardcoded credentials, operating system command-execution flaws, SQL injection vulnerabilities, and privilege-escalation weaknesses. If the system is successfully compromised, the attackers can alter network settings, product identifiers, tank volumes, and pump controls. They could also turn off alerts and create conditions that prevent operators from properly monitoring tank fill levels, potentially increasing the risk of leaks or equipment failures. The agencies urged organizations to block ATG systems from the internet, restrict remote access through firewalls, VPNs, or access control lists, replace default passwords, utilize strong credentials and multifactor authentication, apply security updates, and actively monitor systems for unauthorized changes. Iranian hackers previously linked to similar activity While the advisory does not attribute the activity to any specific threat actor, it follows CNN reporting in May that Iranian hackers were behind a series of breaches involving ATG systems at gas stations in multiple states. According to CNN, the attackers exploited ATG systems that were connected to the internet and protected by weak or nonexistent passwords, allowing them to access and manipulate display readings. However, the attackers did not alter the actual fuel levels. The incidents reportedly did not cause physical damage, but raised concerns that attackers could potentially interfere with leak detection and other safety-related functions. CNN reported that Iran was the primary suspect because of its history of targeting fuel management systems and other industrial control technologies. However, CNN reports that multiple sources briefed on the investigation said it may not be possible to attribute the activity to a specific attacker, as there was limited forensic evidence left behind in the attacks. CISA and its partners said organizations operating ATG systems should review their exposure and implement recommended mitigations immediately to reduce the risk of compromise. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 3, 2026extracted
Chilling Effects
Chilling Effects Younger Americans have soured on the second Donald Trump presidency, but they are not protesting it. Despite an unpopular Iran war and an even more unpopular Trump administration, college campus protests nationwide have gone silent. And at many schools, student activism is virtually nonexistent. This silence comes in the wake of a relentless Trump administration war on campus speech that has involved lawsuits, arrests, deportations and expulsions. Reports cite a range of complicated factors for the restraint, from apathy to technology-induced incapacity. But as public policy and law and social science experts, we believe students aren’t protesting for a very simple reason: They are afraid. They are self-censoring and disengaging from campaign activism to avoid punitive measures. In law and social science, we call this impact a chilling effect—the behavioral tendency for people in face of a threat to self-censor and restrain their activities for self-protection. It’s increasingly clear to us that these impacts are not incidental or ancillary to Trump administration policy. Rather, the chilling effects are the point. This is the closest thing to a consistent governing strategy in Trump’s second term. The broader chill of Trump threats Chilling effects can be subtle, but today they are everywhere. And it’s not just students who are chilled by Trump administration threats. Professors are censoring themselves in lectures and rewriting syllabuses. Researchers are stripping grant applications of words that might attract federal scrutiny, or abandoning the topics entirely. Media outlets are modifying their news coverage to avoid Trump lawsuits or sanctions. Law enforcement and regulatory agencies are refusing to investigate Trump-aligned actors inside or outside government, and major national law firms are declining cases challenging Trump administration policies. Publishers are “stepping back” from LGBTQ+ books and other progressive subjects. Many in targeted immigrant communities are afraid to leave home to go to work or school. In most cases, these people and institutions are not being specifically targeted or threatened by Trump. But they are afraid, and their fear is doing the administration’s work for it. They stay silent, avoid attention and confrontation, and look the other way. In other cases, they change their speech and behavior to accommodate or conform to the administration’s worldview. Of course, there are counterexamples, such as the winter protests in Minneapolis in response to brutality by agents with U.S. Immigration and Customs Enforcement, and the recent “No Kings” rallies. But even here, the broader but less visible trend—chilling effects—is evident. For instance, in recent reporting on the latest No Kings rallies, many media outlets observed that students were noticeably missing, despite the Trump administration’s unpopularity among younger Americans. A persistent strategy We believe none of this is by accident. In a new book, “Chilling Effects: Repression, Conformity, and Power in the Digital Age,” one of us—Jon Penney—explains how law, technology, and state and corporate power are weaponized to chill and repress, and the dangers this poses for the United States and other democratic societies. The other—Bruce Schneier—has extensively studied the security infrastructure enabling this. What we see isn’t gratuitous government cruelty, chaos or vengeance. Instead, we see a persistent strategy to maximize fear and chilling effects in ways that are corrosive to freedom and democracy. Research suggests that surveillance, personal threats, uncertainty and abuse of power are key factors in doing so. The federal government has a clear and systematic pattern of employing these very mechanisms across a number of domains far beyond campuses. They are evident in militarized raids by Immigration and Customs Enforcement and in journalists being arrested and indicted for reporting on protests. They are made clear in the long list of political enemies the Trump administration has investigated or threatened, including the Federal Reserve chairman. And they can also be seen in the weaponization of technology, including ramping up surveillance to target critics and protestors. Corrosive to freedom and democracy History offers some guidance on impacts. During the McCarthy era, overreaching laws, surveillance, and public and private sector reprisals ostensibly targeted alleged communists. But the real aim was often to suppress progressive journalists, trade unions and political opposition. In the 1960s, these same tactics were reused by Southern states to chill the Civil Rights Movement. Historians have written about how the widespread fear and conformity of these periods reshaped American society in enduring ways, including the destruction of progressive political movements and both delaying and muting the Civil Rights Movement itself. When such state threats are systematized, they can foment a broader climate of fear, self-censorship and conformity. In that climate, dissenting speech, political opposition, democratic mobilization and other checks on power become increasingly difficult, even dangerous. It is no surprise, for instance, that Trump critics regularly admit to self-censorship, fearing for their safety. Chilling effects are thus not only repressive—causing self-censorship—but productive. They produce conforming and compliant speech and behavior, which can have longer-term social impacts. They not only undermine protected rights and suppress accountability but can promote social change—even without a popular mandate to do so. This latter point is often missed. It explains Trump’s assaults on universities and cultural institutions such as the Kennedy Center for the Arts and the Smithsonian. Often dismissed as peculiar Trump obsessions, they are fully consistent with Project 2025—the sweeping policy blueprint for Trump’s second term authored by a coalition of conservative groups and its call to target the “institutions of American civil society” and “wield federal power” to “reverse” decades of progressive cultural advancements. In the near term, this means an increasingly weakened democratic society, with the government and its patrons enjoying freedom to pursue their objectives. Over the long term, this can mean a changed society as more conformist and compliant speech and culture become more widely accepted and entrenched. Not inevitable In our view, this future is not inevitable, just as the McCarthy era “Red Scare” and violent civil rights era repression were not. In both cases, fear and chilling effects were resisted in law and civil society, as they can be today. But the central mechanisms—surveillance, uncertainty, personal threats and abuse of power—would need to be addressed. For instance, new legislation could ensure justice for lawless government actors and constrain surveillance. Courts can block abuses of federal power, including illegal arrests, detentions and mass citizen databases. The media, lawyers and civil society can hold the government accountable. And students, teachers, universities and cultural institutions can resist the tendency to self-censor and conform. The citizen mobilization in Minnesota and the No Kings rallies are examples of that. But to resist chilling effects and their dangers over the long term, this would have to be the norm, not the exception. This essay was written with Jon Penney, and originally appeared in The Conversation.
schneier.comMay 29, 2026extracted
Incidente de seguridad digital en Instructure y su impacto en la plataforma Canvas
Incidente de seguridad digital en Instructure y su impacto en la plataforma Canvas 19/05/2026 Mar, 19/05/2026 - 12:39 A finales de abril y principios de mayo de 2026, el ámbito educativo global se vio afectado por un incidente de seguridad digital que puso en jaque las infraestructuras de aprendizaje en línea. La vulnerabilidad comenzó a ser detectada internamente por la compañía proveedora tecnológica Instructure el 25 de abril. Durante este periodo, coincidente con la época de exámenes finales, la agresión digital paralizó los servicios habituales de miles de campus y generó una alarma internacional ante la exposición masiva de registros confidenciales. El ciberataque fue perpetrado por el reconocido grupo de extorsión informática ShinyHunters, el cual logró vulnerar los sistemas de producción de Instructure y comprometer la plataforma Canvas. Este, afectó a unas 9.000 escuelas de educación primaria y secundaria junto con prestigiosas universidades a nivel mundial, poniendo en riesgo la información personal e identificativa de más de 200 millones de estudiantes y docentes. Entre los datos sustraídos se incluyeron nombres completos, direcciones de correo electrónico, números de identificación académica y miles de millones de mensajes privados intercambiados dentro del sistema, aunque la empresa aclaró que las contraseñas y la información financiera quedaron a salvo. Ante el secuestro visual de las pantallas de inicio de sesión de Canvas por parte de los atacantes para exigir un rescate económico, las instituciones académicas se vieron obligadas a aplicar cierres forzados de sesión, implementar alternativas de conexión de emergencia y alertar a sus comunidades frente a posibles campañas fraudulentas de suplantación de identidad (phishing).  En la actualidad, la situación crítica e inmediata de parálisis operativa se encuentra resuelta tras el restablecimiento del servicio y la intervención de agencias federales de seguridad como el FBI. Instructure emitió un comunicado oficial confirmando que lograron un acuerdo con los atacantes antes de que expirara el ultimátum fijado para el 12 de mayo, obteniendo la recuperación de los datos y pruebas digitales verificables sobre la total destrucción de los registros robados por parte de los ciberdelincuentes.    Referencias 07/05/2026 cnnespanol.cnn.com Hackers irrumpen en Canvas y afectan a universidades en plena semana de exámenes 07/05/2026 www.escudodigital.com El gigante educativo detrás de Canvas sufre un ciberataque que afecta a 8.800 escuelas y universidades 08/05/2026 www.edweek.org A Cyberattack on Canvas Could Cause Lasting Aftershocks for Schools 11/05/2026 www.arlnow.com APS urges families to be vigilant after cyberattacks against Canvas network 14/05/2026 www.reedsmith.com Canvas/Instructure cyberattack – Key developments and action items for higher education institutions Etiquetas Ciberdelito Filtración de datos Vulnerabilidad
incibe.esMay 19, 2026extracted
Usa, gruppi cyber criminali filo-iraniani colpiscono le stazioni di servizio
Gli attacchi non hanno colpito direttamente gli erogatori ma i sistemi ATG (Automatic Tank Gauge) che servono a monitorare i livelli di carburante rimasto. Nuovi sospetti degli Usa contro i gruppi cyber criminali filo-iraniani, questa volta responsabili di una serie di attacchi contro le stazioni di servizio. Gli attacchi, secondo la CNN, non hanno colpito direttamente gli erogatori, ma hanno compromesso i sistemi ATG (Automatic Tank Gauge). Si tratta di quei dispositivi utilizzati per monitorare i livelli di carburante nei serbatoi di stoccaggio delle stazioni di servizio. L’aspetto maggiormente preoccupante di tutta la vicenda, è che i gruppi avrebbero sfruttato “dispositivi industriali esposti online senza password o con configurazioni deboli“. La dinamica degli attacchi Sempre secondo la CNN, in alcuni casi i cyber criminali avrebbero potuto “alterare le letture visualizzate sui serbatoi, per quanto non i livelli effettivi di carburante al loro interno“. In ogni caso, non risulta che le intrusioni informatiche abbiano causato danni fisici o lesioni. Tuttavia, le violazioni hanno sollevato preoccupazioni in materia di sicurezza perché l’accesso a un ATG potrebbe, in teoria, consentire a un hacker di far passare inosservata una fuga di gas. Dalle prime indagini, al netto dei primi sospetti sull’Iran, è emersa anche una seconda possibilità. Quella di non esser in grado di individuare con certezza chi sia il responsabile “a causa della mancanza di prove forensi lasciate dagli hacker“. Il monito Se si arrivasse effettivamente a confermare il coinvolgimento dell’Iran, si tratterebbe dell’ultimo caso in cui Teheran minaccia infrastrutture critiche sul territorio statunitense. Un’area, che “rimane fuori dalla portata dei droni e dei missili iraniani, nel conflitto tra Usa, Israele e Iran“. In relazione al paradigma della guerra ibrida, le operazioni contro gli Usa rappresentano allora un monito. In effetti, molti gestori di infrastrutture critiche statunitensi hanno faticato a proteggere i propri sistemi. Da oltre un decennio analisti di sicurezza informatica continuano a porre l’attenzione sulle vulnerabilità dei dispositivi ATG collegati a Internet. “Reti carburante, telemetria industriale, building automation, sistemi idrici, videosorveglianza, impianti energetici e componenti OT distribuiti sono tutti potenziali obiettivi“.
cybersecitalia.itMay 18, 2026extracted
Cina, attacco cyber contro Centro nazionale di supercalcolo di Tianjin. Rubati 10 petabytes di dati sensibili
A rischio la Sicurezza Nazionale della Cina, visto che le informazioni esfiltrate riguardano aerospazio, Difesa e bioinformatica. Un hacker criminale chiamato “FlamingChina” ha rivendicato l’attacco cyber al Centro nazionale di supercalcolo di Tianjin (NSCC) “tramite VPN compromessa e botnet“, sottraendo dati sensibili per mesi. Secondo la CNN, come prova, “FlamingChina ha pubblicato un campione del presunto dei dati su un canale Telegram anonimo lo scorso 6 febbraio“. La mole del furto ammonterebbe a 10 petabytes, tutti in materia di aerospazio, Difesa e bioinformatica. Il centro, aperto nel 2009, è infatti un hub centralizzato che fornisce servizi infrastrutturali a oltre 6mila clienti nel Paese. Tra queste, agenzie scientifiche e per l’appunto della Difesa. Alcuni esperti di sicurezza informatica hanno analizzato questi campioni, riferendo che “sembrano autentici e coerenti con attività da supercomputer“. Una volta completato il furto, è cominciata la fase di vendita agli accessi, chiedendo pagamenti in criptovaluta. Se il valore dell’operazione fosse completamente confermato, si tratterebbe di un duro attacco alla Sicurezza Nazionale di Pechino. Com’è avvenuto l’accesso? Secondo la CNN, l’autore dell’attacco avrebbe affermato di aver ottenuto “l’accesso al supercomputer di Tianjin tramite un dominio VPN compromesso“. Una volta all’interno, l’hacker criminale avrebbe implementato una “botnet”, ossia una rete di programmi automatizzati in grado di penetrare nel sistema dell’NSCC. Dopodiché ha estratto, scaricato e archiviato i dati. L’estrazione dei 10 petabyte ha richiesto circa sei mesi. Distribuendo l’estrazione su molti sistemi contemporaneamente, il presunto responsabile ha ridotto il rischio di far scattare un allarme. “È meno probabile“, hanno sottolineato esperti cyber, “che qualcuno che si occupa di Difesa noti piccole quantità di dati che escono dal sistema rispetto a grandi quantità di dati che vanno in un unico luogo“. Il precedente L’operazione confermerebbe le vulnerabilità cyber sistemiche della Cina sia nel settore pubblico che in quello privato. Basti pensare a quando, cinque anni fa, un enorme database online contenente i dati personali di almeno un miliardo di cittadini cinesi è rimasto “non protetto e accessibile” al pubblico per oltre un anno. Questo, finché nel 2022 un utente anonimo su un forum di hacker non si è offerto di vendere i dati, portandoli così all’attenzione dell’opinione pubblica. Per questo, nel Libro Bianco sulla Sicurezza Nazionale del 2025, il Governo cinese ha indicato come priorità fondamentale la creazione di “solide barriere di sicurezza per alcuni settori“. In particolare “reti, dati e AI“. La Cina, si legge ancora nel Libro Bianco, “ha continuato a potenziare lo sviluppo di meccanismi, strumenti e piattaforme coordinati per la sicurezza informatica“. Il fine è quello “di garantire la sicurezza e l’affidabilità delle infrastrutture informatiche chiave“. Copertina: China Global Television Network Credits
cybersecitalia.itApr 10, 2026extracted
In Other News: FBI Hacked, US Security Pro Killed in Iran War, Hijacked Cameras Used in Khamenei Strike
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: FBI investigates potential unauthorized access to internal networks The FBI is investigating what it describes as suspicious activity indicating a possible breach of its computer systems. CNN reported that the incident is related to a network used to manage wiretaps and foreign intelligence surveillance warrants. LeakBase administrator identified A new analysis from Kela has linked the administrator of the recently seized LeakBase cybercrime forum to the alias Chucky, who also used monikers such as Beakdaz across underground platforms since at least 2013. The investigation tied these accounts through WebMoney registrations in Russia, leaked databases, and cross-referenced social media profiles. Law enforcement seized the forum’s domain and infrastructure on March 4, following arrests and actions against 37 active users, though no specific details confirm Chucky’s arrest or current status. Avira antivirus vulnerabilities Three vulnerabilities in Avira Internet Security (fixed in 1.1.114.3113) allow a low-privileged local user to achieve System-level code execution or arbitrary file deletion. All require local access for exploitation. Quarkslab reported the issues to Avira, but the disclosure process encountered difficulties due to the wording of the vendor’s vulnerability disclosure policy. Google Gemini API keys expose risks in mobile apps after policy shift Google’s Gemini API keys, once treated as non-secret credentials suitable for client-side use in mobile apps, now carry significant security implications due to a recent change in usage rules. The updated policy restricts key exposure in client applications, as Gemini models can access broader Google services and user data compared to previous APIs. Security researchers have found that keys embedded in mobile apps remain easily extractable, potentially enabling unauthorized access to cloud resources and incurring associated costs if mishandled. Gaming cheat exposes North Korean cyber operative A video game cheat led to the accidental exposure of a North Korean state actor’s personal data, Hudson Rock reported. While attempting to download a cheat for Grand Theft Auto V, the individual’s system was compromised by an information-stealing malware that exfiltrated internal credentials and location data. Forensic analysis of the stolen information allowed researchers to link the user to specific infrastructure used in state-sponsored cyber campaigns. Hacked Iranian traffic cameras enabled precise strike on Ali Khamenei The Financial Times [paywalled] has detailed a long-term intelligence operation led by Israel that culminated in the February 28 airstrikes killing Iranian Supreme Leader Ali Khamenei. A significant cyber aspect involved years-long infiltration of Tehran’s traffic camera network. Nearly all cameras were compromised, with their feeds routed to servers in Israel for persistent surveillance. This provided real-time and historical visibility into Khamenei’s movements, security details, and daily routines, enabling precise targeting adjustments. Iran is also known to have used hacked security cameras to adjust its missile strikes. TriZetto Provider Solutions data breach affects 3.4 million people TriZetto Provider Solutions, a healthcare technology company, has confirmed a data breach that impacted several of its customers. The incident involved unauthorized access to certain systems, potentially exposing protected health information and other sensitive data belonging to clients and their patients. The company recently informed the HHS that roughly 3.4 million individuals are affected by the incident. US solider killed in Kuwait was cybersecurity expert One of the six US soldiers killed in a drone strike at a command center in Kuwait was Major Jeffrey O’Brien, 45, of Iowa. O’Brien served in the Army Reserve for nearly 15 years, but for the past two years also worked as a manager of defensive cyber operations at cybersecurity company ProCircular. O’Brien was a member of the cybersecurity community for more than a decade based on his LinkedIn profile. Man who allegedly stole $46M in cryptocurrency from US Marshals arrested The FBI announced the arrest of a suspect in the Caribbean in connection with the theft of approximately $46 million in digital assets from the US Marshals Service. The joint operation between the FBI and international tactical units followed an investigation into unauthorized access to government-managed wallets holding seized cryptocurrency. Transport for London data breach affects 10 million The 2024 cyberattack against Transport for London exposed personal information belonging to a significantly larger group than originally estimated. The BBC reported that roughly 10 million individuals had their contact details and potentially other sensitive records accessed during the incident. Two suspects have been arrested in the UK, but they pleaded not guilty.
securityweek.comMar 6, 2026extracted
FBI investigates breach of surveillance and wiretap systems
The U.S. Federal Bureau of Investigation (FBI) confirmed on Thursday that it's investigating a breach that affected systems used to manage surveillance and wiretap warrants. While the federal law enforcement agency declined to share more details regarding the incident's scope and overall impact, it said that the incident has already been addressed. "The FBI identified and addressed suspicious activities on FBI networks, and we have leveraged all technical capabilities to respond," the law enforcement agency told BleepingComputer, but declined to provide additional information. On Thursday, CNN, which first reported the incident, cited an anonymous source saying the breach affected FBI systems used to manage wiretapping and foreign intelligence surveillance warrants. While it's unclear at the moment whether this incident is also connected, Chinese hackers part of a state-backed threat group tracked as Salt Typhoon have also compromised U.S. federal government systems used for court-authorized network wiretapping requests in 2024. The incident came to light after Salt Typhoon breached the networks of telecommunications providers in the U.S. (AT&T, Verizon, Lumen, Charter Communications, Consolidated Communications, Comcast, Digital Realty, and Windstream), as well as dozens of other countries. While inside the U.S. telecom firms' networks, the hackers also gained access to the "private communications" of some U.S. government officials. In November 2021, the FBI's email servers were also hacked to distribute spam emails impersonating the bureau that warned recipients about fake cyberattacks. The FBI also revealed in February 2023 that it was investigating malicious cyber activity involving an FBI New York Field Office computer system that was used to investigate child sexual exploitation. Update March 06, 07:39 EST: Added FBI statement. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 6, 2026extracted
全米が注目の行方不明事件、“消去済み”Nestカメラ映像をGoogleの技術力で復元 プライバシー懸念も
この頃、セキュリティ界隈で 全米が注目の行方不明事件、“消去済み”Nestカメラ映像をGoogleの技術力で復元 プライバシー懸念も 米テレビ司会者の母親が行方不明になった事件が全米をくぎ付けにしている。米連邦捜査局(FBI)は事件発生から10日後に、被害者の自宅に設置されたGoogle Nestの玄関カメラがとらえた映像を公開した。当初極めて困難とされていた映像が復元できたことで、同時にプライバシーを巡る懸念も浮上している。 行方不明になっているナンシー・ガスリーさん(84)は、米NBCテレビの情報番組司会者として有名なサバンナ・ガスリーさんの母親。2月1日未明、アリゾナ州トゥーソンの自宅から何者かに連れ去られたとみられる。 FBIは2月10日、ガスリーさんが行方不明になった当日にNestの玄関カメラがとらえた映像を公開した。目出し帽を着けて銃を持った人物は、カメラを壊そうとしている様子だった。 ガスリーさんは映像をGoogleのクラウドに保存できるNestの有料サービスを契約していなかったことから、捜査当局は当初、この映像の入手は不可能と説明していた。Nestの無料プランの場合、映像は3~6時間後に消去される。ガスリーさんの行方不明届けが出された時点でとうにその時間は経過していた。 しかし当局が捜索令状を取ってGoogleにNestカメラの映像を探させた結果、Googleのエンジニアがデータの復元に成功。FBIのパテル長官はXに画像を投稿し、「バックエンドシステムの残留データから映像を復元した」とポストした。 映像復元が示唆するプライバシー問題 CNNによると、Nestは無料サービスであっても約3時間分の映像履歴をGoogleのクラウドやサーバに保存しているという。たとえGoogleのシステムから削除されたとしても、新しいデータによって上書きされていない限り、復元できる可能性があった。 ただ、そうしたデータはアプリケーションやサーバやストレージのさまざまな層にまたがって存在していることから復元は技術的に極めて難しく、実現できたのはGoogleの技術力に尽きると専門家は指摘しているという。 CBSニュースによれば、ガスリーさんの玄関カメラの映像を探し出す難しさについて、元捜査員は「干し草の山の中から1本の針を見つけるようなもの」だったと形容した。 一方で今回の出来事は、プライバシー上の懸念も浮上させている。Googleによる映像復元は、たとえユーザーが無料サービスしか契約していなかったとしても、自分の知らない所でデータがいつまでも保持されていて、会社側がその気になれば、または捜査当局の要請があれば、復元が可能な現実を見せつけた。 「昔から言われている通り、『データは決して削除されない。名称が変わるのみ』。今回のケースはまさに、アップロードされたデータがたとえ削除対象としてマークされたとしても、実際には削除されない可能性があることを物語る」 米国家安全保障局(NSA)の元データ研究員パトリック・ジャクソンさんはCBSニュースにそう語り、今回の映像復元をきっかけに、Googleには捜査当局からこうした要請が殺到するかもしれないと予想している。 Copyright © ITmedia, Inc. All Rights Reserved. この頃、セキュリティ界隈で 海外のセキュリティ関連ニュースを追い続けている鈴木聖子さんによる、最近のセキュリティニュースブリーフィング。隔週でお届けします。
itmedia.co.jpFeb 19, 2026extracted
Deliberate Internet Shutdowns
Deliberate Internet Shutdowns For two days in September, Afghanistan had no internet. No satellite failed; no cable was cut. This was a deliberate outage, mandated by the Taliban government. It followed a more localized shutdown two weeks prior, reportedly instituted “to prevent immoral activities.” No additional explanation was given. The timing couldn’t have been worse: communities still reeling from a major earthquake lost emergency communications, flights were grounded, and banking was interrupted. Afghanistan’s blackout is part of a wider pattern. Just since the end of September, there were also major nationwide internet shutdowns in Tanzania and Cameroon, and significant regional shutdowns in Pakistan and Nigeria. In all cases but one, authorities offered no official justification or acknowledgment, leaving millions unable to access information, contact loved ones, or express themselves through moments of crisis, elections, and protests. The frequency of deliberate internet shutdowns has skyrocketed since the first notable example in Egypt in 2011. Together with our colleagues at the digital rights organisation Access Now and the #KeepItOn coalition, we’ve tracked 296 deliberate internet shutdowns in 54 countries in 2024, and at least 244 more in 2025 so far. This is more than an inconvenience. The internet has become an essential piece of infrastructure, affecting how we live, work, and get our information. It’s also a major enabler of human rights, and turning off the internet can worsen or conceal a spectrum of abuses. These shutdowns silence societies, and they’re getting more and more common. Shutdowns can be local or national, partial or total. In total blackouts, like Afghanistan or Tanzania, nothing works. But shutdowns are often targeted more granularly. Cellphone internet could be blocked, but not broadband. Specific news sites, social media platforms, and messaging systems could be blocked, leaving overall network access unaffected—as when Brazil shut off X (formerly Twitter) in 2024. Sometimes bandwidth is just throttled, making everything slower and unreliable. Sometimes, internet shutdowns are used in political or military operations. In recent years, Russia and Ukraine have shut off parts of each other’s internet, and Israel has repeatedly shut off Palestinians’ internet in Gaza. Shutdowns of this type happened 25 times in 2024, affecting people in 13 countries. Reasons for the shutdowns are as varied as the countries that perpetrate them. General information control is just one. Shutdowns often come in response to political unrest, as governments try to prevent people from organizing and getting information; Panama had a regional shutdown this summer in response to protests. Or during elections, as opposition parties utilize the internet to mobilize supporters and communicate strategy. Belarusian president Alyaksandr Lukashenko, who has ruled since 1994, reportedly disabled the internet during elections earlier this year, following a similar move in 2020. But they can also be more banal. Access Now documented countries disabling parts of the internet during student exam periods at least 16 times in 2024, including Algeria, Iraq, Jordan, Kenya, and India. Iran’s shutdowns in 2022 and June of this year are good examples of a highly sophisticated effort, with layers of shutdowns that end up forcing people off the global internet and onto Iran’s surveilled, censored national intranet. India, meanwhile, has been the world shutdown leader for many years, with 855 distinct incidents. Myanmar is second with 149, followed by Pakistan and then Iran. All of this information is available on Access Now’s digital dashboard, where you can see breakdowns by region, country, type, geographic extent, and time. There was a slight decline in shutdowns during the early years of the pandemic, but they have increased sharply since then. The reasons are varied, but a lot can be attributed to the rise in protest movements related to economic hardship and corruption, and general democratic backsliding and instability. In many countries today, shutdowns are a knee-jerk response to any form of unrest or protest, no matter how small. A country’s ability to shut down the internet depends a lot on its infrastructure. In the US, for example, shutdowns would be hard to enforce. As we saw when discussions about a potential TikTok ban ramped up two years ago, the complex and multifaceted nature of our internet makes it very difficult to achieve. However, as we’ve seen with total nationwide shutdowns around the world, the ripple effects in all aspects of life are immense. (Remember the effects of just a small outage—CrowdStrike in 2024—which crippled 8.5 million computers and cancelled 2,200 flights in the US alone?) The more centralized the internet infrastructure, the easier it is to implement a shutdown. If a country has just one cellphone provider, or only two fiber optic cables connecting the nation to the rest of the world, shutting them down is easy. Shutdowns are not only more common, but they’ve also become more harmful. Unlike in years past, when the internet was a nice option to have, or perhaps when internet penetration rates were significantly lower across the Global South, today the internet is an essential piece of societal infrastructure for the majority of the world’s population. Access Now has long maintained that denying people access to the internet is a human rights violation, and has collected harrowing stories from places like Tigray in Ethiopia, Uganda, Annobon in Equatorial Guinea, and Iran. The internet is an essential tool for a spectrum of rights, including freedom of expression and assembly. Shutdowns make documenting ongoing human rights abuses and atrocities more difficult or impossible. They are also impactful on people’s daily lives, business, healthcare, education, finances, security, and safety, depending on the context. Shutdowns in conflict zones are particularly damaging, as they impact the ability of humanitarian actors to deliver aid and make it harder for people to find safe evacuation routes and civilian corridors. Defenses on the ground are slim. Depending on the country and the type of shutdown, there can be workarounds. Everything, from VPNs to mesh networks to Starlink terminals to foreign SIM cards near borders, has been used with varying degrees of success. The tech-savvy sometimes have other options. But for most everyone in society, no internet means no internet—and all the effects of that loss. The international community plays an important role in shaping how internet shutdowns are understood and addressed. World bodies have recognized that reliable internet access is an essential service, and could put more pressure on governments to keep the internet on in conflict-affected areas. But while international condemnation has worked in some cases (Mauritius and South Sudan are two recent examples), countries seem to be learning from each other, resulting in both more shutdowns and new countries perpetrating them. There’s still time to reverse the trend, if that’s what we want to do. Ultimately, the question comes down to whether or not governments will enshrine both a right to access information and freedom of expression in law and in practice. Keeping the internet on is a norm, but the trajectory from a single internet shutdown in 2011 to 2,000 blackouts 15 years later demonstrates how embedded the practice has become. The implications of that shift are still unfolding, but they reach far beyond the moment the screen goes dark. This essay was written with Zach Rosson, and originally appeared in Gizmodo.
schneier.comDec 17, 2025extracted
U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UN
The U.S. Secret Service on Tuesday said it took down a network of electronic devices located across the New York tri-state area that were used to threaten U.S. government officials and posed an imminent threat to national security. "This protective intelligence investigation led to the discovery of more than 300 co-located SIM servers and 100,000 SIM cards across multiple sites," the Secret Service said. The devices were concentrated within a 35-mile (56 km) radius of the global meeting of the United Nations General Assembly in New York City. An investigation into the incident has been launched by the Secret Service's Advanced Threat Interdiction Unit. Aside from issuing anonymous telephonic threats, the sophisticated devices could be weaponized to conduct various attacks on the telecommunications infrastructure, including disabling cell phone towers, triggering a denial-of-service, and facilitating encrypted communication between potential threat actors and criminal enterprises. The Secret Service also said early evidence points to cellular communications between nation-state threat actors and individuals that are known to federal law enforcement. It did not elaborate on who these actors are. The agency also did not identify the officials who were threatened, the nature of the threat, or the nations that may have been involved. CNN and NBC News reported that the network anonymously conveyed assassination threats against senior U.S. officials and that the probe uncovered empty electronic safehouses rented around the area, including Armonk, New York; Greenwich, Connecticut; Queens, New York; and across the river in New Jersey. "The potential for disruption to our country’s telecommunications posed by this network of devices cannot be overstated," said U.S. Secret Service Director Sean Curran. "The U.S. Secret Service's protective mission is all about prevention, and this investigation makes it clear to potential bad actors that imminent threats to our protectees will be immediately investigated, tracked down, and dismantled."
thehackernews.comSep 23, 2025extracted
Ciberataque paraliza la distribución de productos de alimentación de United Natural Foods
Ciberataque paraliza la distribución de productos de alimentación de United Natural Foods 09/06/2025 Mar, 29/07/2025 - 14:35 United Natural Foods (UNFI), el mayor distribuidor de productos de alimentación de Estados Unidos y Canadá, especializado en productos naturales, orgánicos y especializados, así como en alimentos convencionales, se ha visto obligado a cerrar algunos de sus sistemas tras detectar un reciente ciberataque ocurrido el 5 de junio de 2025. El día 9, UNFI publicó una notificación diciendo que el ciberataque afectó a pedidos de sus clientes y causó interrupciones temporales en las operaciones comerciales. Esta publicación se produjo después de que, en foros y redes sociales, los usuarios alertaran que los sistemas de la empresa no funcionaban y que a los empleados les estaban cancelando turnos de trabajo. Desde que el descubrimiento de la brecha de seguridad, UNFI ha notificado a las autoridades policiales pertinentes y ha contratado a expertos externos en ciberseguridad para la investigación del incidente. UNFI también ha tomado medidas para tratar de mantener la continuidad del servicio al cliente, aplicando medidas provisionales hasta que se restablezcan los sistemas afectados. Unas semanas después, el 26 de junio, UNFI ha notificado que ya ha restablecido sus sistemas esenciales y ha puesto en línea los sistemas de pedidos y facturación en línea afectados por un ciberataque. Hasta el momento, UNFI aún no ha revelado la naturaleza del ataque ni si algún grupo de ciberdelincuencia ha reivindicado la autoría de la brecha. Aun así, la empresa no prevé enviar ningún comunicado a los consumidores, ya que la empresa ha declarado que no se ha visto afectada la seguridad de la información personal de clientes o empleados. Referencias 26/06/2025 unfi.com UNFI Systems Update 09/06/2025 bleepingcomputer.com Grocery wholesale giant United Natural Foods hit by cyberattack 27/06/2025 bleepingcomputer.com Whole Foods supplier UNFI restores core systems after cyberattack 10/06/2025 cnn.com Empty shelves plague some Whole Foods after distributor knocked offline 11/06/2025 infobae.com Un ciberataque masivo ha provocado que Whole Foods se esté quedando con los anaqueles vacíos Etiquetas Ataque Brecha de seguridad Intrusión Sector alimentación
incibe.esJul 29, 2025extracted