Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify ..
Categoria : Security
AI-native OT security startup Frenos today announced raising $1.52 million in a seed funding round extension that brings the total raised by the company to $6.4 million. The new investment round was led by Momenta and Exposition Ventures, with additional support from Riptide Ventures. Frenos will use the new funding to expand its customer success ..
Recently, security engineer Rit Das asked me for advice on acquiring a small physical security company. After years selling security systems to hospitals, schools, and public safety agencies, he had discovered an opportunity to invest in well-run firms that had loyal customers and recurring revenue but lacked scale and succession options. But as our conversation ..
GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases. To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, ..
A Cl0p ransomware affiliate has been observed exploiting a critical-severity remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM. Tracked as CVE-2026-12569 (CVSS score of 9.3), the security defect is described as a deserialization of untrusted data issue that can be exploited without authentication. Patched on June 17, the ..
Hidden desktops are a legitimate Windows capability, often used by specialized software, and occasionally used by malware. MedusaHVNC is a remote access trojan (RAT) being sold as malware-as-a-service (MaaS). It is promoted through its own website and a Telegram channel. It was found and analyzed by BlackFog, with the analysis finding a hidden virtual network ..
Nvidia and a large group of technology, cybersecurity, and enterprise software companies announced on Monday the launch of the Open Secure AI Alliance, a new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents. The effort builds on existing work from the Linux Foundation’s recently launched ..
Il Cryptographic Bill of Materials (CBOM) risponde a una domanda che quasi ogni organizzazione, di fronte alla migrazione post-quantum, scopre di non saper trasformare in un elenco: dove, e con quali algoritmi, chiavi e certificati, l’azienda usa la crittografia. Sembra una domanda banale, e invece è insidiosa, perché la crittografia non vive in un posto ..
Il quishing, cioè il phishing veicolato da un QR code, ha smesso di essere una curiosità e nel 2026 è diventato, nella telemetria di Microsoft, il vettore email in più rapida crescita. Non è un dettaglio di forma, un phishing con un’immagine al posto di un link: è un attacco costruito apposta per aggirare i ..
La memory safety è uno dei problemi di sicurezza più antichi del software, e nel 2026 è tornata in cima all’agenda con la spinta delle agenzie governative. Si tratta dell’assenza di una intera famiglia di difetti, quelli che nascono quando un programma gestisce a mano la memoria e sbaglia: un buffer overflow che scrive oltre ..


