Categoria : Security

image_pdfimage_print

Rockwell Automation has patched four vulnerabilities in its Arena Simulation software that could let an attacker execute arbitrary code on an affected system, according to advisories published by CISA and Rockwell. Arena Simulation is a discrete-event simulation software that provides organizations with a virtual environment to model, visualize, and test complex operational workflows, allowing them ..

Leggi tutto

In April of this year, The Cybersecurity Infrastructure & Security Agency (CISA), alongside other agencies, published a warning regarding Iranian cyber activity against United States critical infrastructure. Earlier this week, that alert was updated.  The original publication offered information about ongoing cyber exploitation conducted by Iranian-linked advanced persistent threat (APT) actors, such as tactics, techniques, and ..

Leggi tutto

The risk of guardrail-free AI isn’t a future concern — it’s a current-day threat. Researchers from ThreatDown discovered the AI tools that fuel today’s cyber incidents are increasingly open, mainstream and challenging to monitor.  The first major finding from the research is that AI without guardrails has become mainstream. Some may assume that malicious AI is exclusively ..

Leggi tutto

Gli attacchi informatici si sviluppano ormai con una rapidità che lascia alle organizzazioni margini decisionali sempre più ridotti. In una crisi cyber, sapere che cosa fare, chi deve intervenire e quali attività proteggere per prime può determinare la portata dell’impatto operativo. La consapevolezza del rischio, tuttavia, non è sufficiente. Un’impresa può investire in tecnologie avanzate ..

Leggi tutto

Il codice generato dall’AI ha smesso di essere una curiosità da laboratorio ed è entrato nel flusso di lavoro quotidiano di gran parte degli sviluppatori, spesso senza che l’organizzazione se ne sia accorta davvero. La promessa è evidente e reale: scrivere più in fretta, delegare le parti ripetitive, abbassare la barriera d’ingresso a chi programma ..

Leggi tutto

Zenity Labs has found and disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents, which it names AgentForger; a tailored cross-site request forgery (CSRF). With a single successful phish, an unsuspecting employee could be tricked into launching an invisible autonomous agent that is remotely controlled by the attacker. Zenity explains in two blogs (Part 1 ..

Leggi tutto

On July 14, 2026, the White House launched Gold Eagle: a federal clearinghouse that uses frontier AI to identify, rank, and coordinate the remediation of software vulnerabilities across government and critical infrastructure before attackers reach them. Bringing together the Treasury, DHS, DoD, open-source software partners, and operators of American critical infrastructure, Gold Eagle’s engine relies ..

Leggi tutto

Palo Alto Networks (NASDAQ: PANW) on Tuesday announced its intent to acquire Embrace, a provider of user-focused observability, in a move to add Real User Monitoring (RUM) capabilities to its Observability platform. Financial terms of the deal were not disclosed. Alongside the acquisition, the company introduced Synthetics, a new capability developed in-house by its Autonomous ..

Leggi tutto