In aumento gli attacchi russi e lo spionaggio contro Ucraina ed Europa. Il report di ESET


Nell’ultimo APT Activity Report relativo al periodo aprile-settembre 2025, ESET ha evidenziato un significativo aumento degli attacchi russi contro Ucraina ed Europa, con una campagna di spearphishing che ha usato il nome della compagnia per colpire le vittime.

I gruppi APT allineati alla Russia hanno preso di mira in particolare le entità governative in operazioni di cyberspionaggio, sia in Ucraina che in diversi Stati Membri dell’UE che hanno legami strategici e operativi con essa.

attacchi russi

ESET ha riportato che il gruppo RomCom ha sfruttato una vulnerabilità zero-day in WinRAR per distribuire DLL malevole e installare diverse backdoor, prendendo di mira bersagli nei settori settori finanziario, manifatturiero, della difesa e della logistica. Molto attivi anche i gruppi Gamaredon e Sandworm che hanno invece usato lo spearphishing come metodo principale di compromissione.

La compagnia ha segnalato inoltre che il gruppo FrostyNeighbor, allineato alla Bielorussia, ha sfruttato una vulnerabilità XSS in Roundcube per inviare email di spearphishing che imitavano comunicazioni di imprese polacche. La struttura dei messaggi suggerisce un impiego significativo dell’IA nella campagna.

Oltre agli attacchi russi, anche le campagne a opera di attaccanti cinesi sono state tra le più impattanti, soprattutto contro l’America Latina. ESET ha osservato un uso crescente della tecnica adversary-in-the-middle sia per l’accesso iniziale che per il movimento laterale. Tra i gruppi più attivi in sud America emerge FamousSparrow, il quale ha preso di mira numerose entità governative della regione.

“I gruppi allineati alla Cina restano molto attivi, con campagne che ESET ha recentemente osservato in Asia, Europa, America Latina e Stati Uniti. Questa estensione globale dimostra come gli attori APT allineati a Pechino continuino a essere mobilitati per supportare una vasta gamma di priorità geopolitiche del Paese” ha affermato Jean-Ian Boutin, Director of Threat Research di ESET.

Anche in Asia la situazione è piuttosto accesa, con diversi gruppi APT che hanno continuato a colpire entità governative e realtà dei settori tecnologico, ingegneristico e manifatturiero. I gruppi allineati alla Corea del Nord sono rimasti attivi contro la Corea del Sud, concentrandosi in particolare sulle criptovalute per finanziare le attività del regime.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/11/07/in-aumento-gli-attacchi-russi-e-lo-spionaggio-contro-ucraina-ed-europa-il-report-di-eset/?utm_source=rss&utm_medium=rss&utm_campaign=in-aumento-gli-attacchi-russi-e-lo-spionaggio-contro-ucraina-ed-europa-il-report-di-eset




Google Warns Against Relying On SEO Audit Tool Scores via @sejournal, @MattGSouthern

Google warned against relying on tool-generated scores for technical SEO audits.

Search Relations team member Martin Splitt outlined a three-step framework in a Search Central Lightning Talk that emphasizes site-specific context over standardized metrics.

The Three-Step Framework

Splitt outlined the core objective in the video:

“A technical audit, in my opinion, should make sure no technical issues prevent or interfere with crawling or indexing. It can use checklists and guidelines to do so, but it needs experience and expertise to adapt these guidelines and checklists to the site you audit.”

His recommended framework has three phases.

First, use tools and guidelines to identify potential issues. Second, create a report tailored to the specific site. Third, make recommendations based on actual site needs.

Understanding site technology comes before running diagnostic tools. Group findings by effort required and potential impact, Splitt said.

When 404s Are Normal

High 404 counts don’t always mean problems.

The red flag is unexplained rises without corresponding website changes.

Splitt explained:

“A high number of 404s, for instance, is expected if you removed a lot of content recently. That’s not a problem. It’s a normal consequence of that. But if you have an unexplained rise in 404 responses, though, that’s something you want to point out and investigate…”

Google Search Console’s Crawl Stats report shows whether 404 patterns match normal site maintenance or indicate technical issues.

Context Over Scores

Tools generate numerical scores that lack site-specific context.

Not everything tools flag carries equal weight. An international site needs hreflang auditing, while a single-language site doesn’t.

Splitt emphasized human judgment over automation:

“Please, please don’t follow your tools blindly. Make sure your findings are meaningful for the website in question and take the time to prioritize them for maximum impact.”

Talk to people who know the site and its technology. They’ll tell you if findings make sense.

Why This Matters

Generic checklists waste time on low-impact fixes while missing critical issues.

Tool scores may flag normal site behavior as problems. They assign priority to issues that don’t affect how search engines crawl your content.

Understanding when metrics reflect normal operations helps you focus audit resources where they matter. This applies whether you’re running internal audits or evaluating agency reports.

Looking Ahead

Audit platforms continue adding automated checks and scoring systems. This widens the gap between generic findings and actionable recommendations.

Google’s guidance reinforces that technical SEO requires expertise beyond tool automation.

Sites with international setups, large content archives, or frequent publishing benefit most from context-driven audits.

Hear Splitt’s full talk in the video below:

[embedded content]

https://www.searchenginejournal.com/google-warns-against-relying-on-seo-audit-tool-scores/560190/




Google Finance Gets AI Deep Search & Prediction Market Data via @sejournal, @MattGSouthern

Google Finance is rolling out Deep Search capabilities, prediction markets data, and enhanced earnings tracking features across its AI-powered platform.

The updates expand Google Finance beyond basic market data into multi-step research workflows and crowd-sourced probability forecasting. Google announced the changes today, with features rolling out over the coming weeks, starting with Labs users.

Deep Search For Financial Research

Deep Search handles complex financial queries by issuing up to hundreds of simultaneous searches and synthesizing information across multiple sources.

You can ask detailed questions and select the Deep Search option. Gemini models then generate fully cited comprehensive responses within minutes, displaying the research plan during generation.

Image Credit: Google

Robert Dunnette, Director of Product Management for Google Search, wrote:

“From there, our advanced Gemini models will get to work, issuing up to hundreds of simultaneous searches and reasoning across disparate pieces of information to produce a fully cited, comprehensive response in just a few minutes.”

Deep Search offers higher usage limits for Google AI Pro and AI Ultra subscribers. Users can access it through the Google Finance experiment in Labs.

Prediction Markets Integration

Google Finance is adding support for prediction markets data from Kalshi and Polymarket, with availability rolling out over the coming weeks, starting with Labs users.

You can query future market events directly from the search box to see current probabilities and historical trends.

An example query includes “What will GDP growth be for 2025?”

The feature rolls out this week to Labs users first.

Enhanced Earnings Tracking

Google launched earnings tracking features that provide live audio streams, real-time transcripts, and AI-generated insights during corporate earnings calls.

The Earnings tab shows scheduled calls, streams live audio during calls, and maintains transcripts for later reference. AI-powered insights under “At a glance” update before, during, and after calls with information from news reports and analyst reactions.

You can compare financial data against historical results, view performance versus expectations, and access earnings documents and SEC forms.

India Expansion

Google Finance begins rolling out in India this week with support for English and Hindi.

The India launch initially offers the core Google Finance experience. Deep Search, prediction markets, and earnings features launch first in the U.S. and will expand internationally over time.

Why This Matters

Deep Search reduces the time needed to gather financial data from multiple sources, potentially resulting in fewer webpage visits.

Prediction markets offer crowd-sourced probability estimates that complement analyst forecasts. Live earnings tracking integrates call audio, transcripts, and analyst reactions into a single interface during reporting season.

Looking Ahead

Deep Search and prediction markets roll out over the coming weeks, with Labs users getting early access. Google AI Pro and AI Ultra subscribers receive higher usage limits for Deep Search queries.

The India expansion marks Google Finance’s first international launch beyond the U.S. Access the beta at google.com/finance/beta while signed into a Google account.


Featured Image: Juan Alejandro Bernal/Shutterstock

https://www.searchenginejournal.com/google-finance-gets-ai-deep-search-prediction-market-data/560157/




Google Performance Max Adds Waze Ads And Channel Reporting via @sejournal, @MattGSouthern

Google adds Waze ads to Performance Max for store goals in the U.S. and rolls out channel performance reporting, with search partner reporting coming soon.

  • Waze ads are now available in PMax for store goals.
  • Channel performance reporting is rolling out across PMax, with search partner reporting and MCC access coming soon.
  • No extra setup is required.

https://www.searchenginejournal.com/google-performance-max-adds-waze-ads-and-channel-reporting/560167/




Appalti nel settore cyber, premi a chi sceglie le soluzioni di Paesi NATO e terzi. Tra questi anche Israele


Ci sono importanti novità nel settore degli appalti cyber: secondo le linee guida dell’ACN (Agenzia per la Cybersicurezza Nazionale), le imprese che acquisteranno tecnologie di cybersicurezza da Paesi NATO o terzi otterranno delle premialità nei bandi di gara con la pubblica amministrazione. Nel dettaglio, si tratta di otto punti in più.

“La lettera e) del soprarichiamato comma 2 stabilisce, inoltre, che siano previsti criteri di premialità per le proposte o per le offerte che contemplino l’uso “di tecnologie di cybersicurezza italiane o di Paesi appartenenti all’Unione europea o di Paesi aderenti alla NATO o di Paesi che sono parte di accordi di collaborazione con l’Unione europea o con la NATO in materia di cybersicurezza, protezione delle infrastrutture classificate, ricerca e innovazione”” si legge nel documento ufficiale.

Ciò che ha sta facendo discutere è che tra questi Paesi terzi figura anche Israele, insieme ad Australia, Corea del Sud, Giappone, Nuova Zelanda e Svizzera.

appalti cyber

Come riporta EuroNews, già l’anno scorso l’Italia, sotto pressione degli Stati Uniti, si era mossa per favorire la collaborazione con aziende facenti parte dei Paesi NATO e dell’Unione Europea; una scelta che aveva escluso Israele, da sempre un Paese leader nel settore della cybersecurity.

Il rapporto tra Italia e Israele in questo senso è piuttosto controverso: la testata ricorda infatti che a inizio anno Meta aveva segnalato ad alcuni utenti WhatsApp (giornalisti e attivisti) che i loro dati erano stati compromessi da Graphite, lo spyware dell’israeliana Paragon Solutions usato da diversi governi, compreso quello degli Stati Uniti e italiano.

La collaborazione con Paragon Solutions era stata interrotta dalle agenzie governative italiane che usavano Graphite, ma quando l’UE ha chiesto l’esclusione di Israele da Horizon Europe, programma a sostegno della ricerca scientifica, l’Italia è stata tra i Paesi che si sono opposti a questa scelta. 

Con l’aumento degli attacchi cyber contro le realtà italiane, soprattutto nel settore della pubblica amministrazione, gli occhi dell’opinione pubblica sono puntati sulle aziende e sull’esito degli appalti pubblici.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/11/06/appalti-nel-settore-cyber-premi-a-chi-sceglie-le-soluzioni-di-paesi-nato-e-terzi-tra-questi-anche-israele/?utm_source=rss&utm_medium=rss&utm_campaign=appalti-nel-settore-cyber-premi-a-chi-sceglie-le-soluzioni-di-paesi-nato-e-terzi-tra-questi-anche-israele




OpenAI’s Sam Altman Raises Possibility Of Ads On ChatGPT via @sejournal, @martinibuster

OpenAI’s CEO Sam Altman sat for an interview where he explained that his vision for the future of ChatGPT is as a trusted assistant that’s user-aligned, saying that booking hotels is not going to be the way to monetize “the world’s smartest model.” He pointed to Google as an example of what he doesn’t want ChatGPT to become: a service that accepts advertising dollars to place the worst choice above the best choice. He then followed up to express openness to advertising.

User-Aligned Monetization Model

Altman contrasted OpenAI’s revenue approach with the ad-driven incentives of Google. He explained that Google’s Search and advertising ecosystem depends on Google’s search results “doing badly for the user,” because ranking decisions are partly tied to maximizing advertising income.

The interviewer related that he and his wife took a trip to Europe and booked multiple hotels with help from ChatGPT and ate at restaurants that ChatGPT helped him find and at no point did any kind of kickback or advertising fee go back to OpenAI, leading him to tell his wife that ChatGPT “didn’t get a dime from this… this just seems wrong….” because he was getting so much value from ChatGPT and ChatGPT wasn’t getting anything back.

Altman answered that users trust ChatGPT and that’s why so many people pay for it.

He explained:

“I think if ChatGPT finds you the… To zoom out even before the answer, one of the unusual things we noticed a while ago, and this was when it was a worst problem, ChatGPT would consistently be reported as a user’s most trusted technology product from a big tech company. We don’t really think of ourselves as a big tech company, but I guess we are now. That’s very odd on the surface, because AI is the thing that hallucinates, AI is the thing with all the errors, and that was much more of a problem. And there’s a question of why.

Ads on a Google search are dependent on Google doing badly. If it was giving you the best answer, there’d be no reason ever to buy an ad above it. So you’re like, that thing’s not quite aligned with me.

ChatGPT, maybe it gives you the best answer, maybe it doesn’t, but you’re paying it, or hopefully are paying it, and it’s at least trying to give you the best answer. And that has led to people having a deep and pretty trusting relationship with ChatGPT. You ask ChatGPT for the best hotel, not Google or something else.”

Altman’s response used the interviewer’s experience as an example of a paradigm change in user trust in technology. He contrasted ChatGPT’s model, where users directly pay for answers, with Google’s ad-based model that profits from imperfect results. His point is that ChatGPT’s business model aligns more closely with users’ interests, earning a sense of trust and reliability rather than making their users feel exploited by an advertising system. This is why users perceive ChatGPT as more trustworthy, even though ChatGPT is known to hallucinate.

Altman Is Open To Transaction Fees

Altman was strongly against accepting advertising money in exchange for showing a hotel above what ChatGPT would naturally show. He said that he would be open to accepting a transaction fee should a user book that hotel through ChatGPT because that has no influence on what ChatGPT recommends, thus preserving a user’s trust.

He shared how this would work:

“If ChatGPT were accepting payment to put a worse hotel above a better hotel, that’s probably catastrophic for your relationship with ChatGPT. On the other hand, if ChatGPT shows you it’s best hotel, whatever that is, and then if you book it with one click, takes the same cut that it would take from any other hotel, and there’s nothing that influenced it, but there’s some sort of transaction fee, I think that’s probably okay. And with our recent commerce thing, that’s the spirit of what we’re trying to do. We’ll do that for travel at some point.”

I think a takeaway here is that Altman believes the advertising model that the Internet has been built on over the past thirty-plus years can subvert user trust and lead to a poor user experience. He feels that a transaction fee model is less likely to impact the quality of the service that users are paying for and that it will maintain the feeling of trust that people have in ChatGPT.

But later on in the interview, as you’ll see, Altman surprises the interviewer with his comment about the possibility of advertisements on ChatGPT.

How OpenAI Will Monetize Itself

When pressed about how OpenAI will monetize itself, Altman responded that he expects the future of commerce will have lower margins and that he doesn’t expect to fully fund OpenAI by booking hotels but by doing exceptional things like curing diseases.

Altman explained his vision:

“So one thing I believe in general related to this is that margins are going to go dramatically down on most goods and services, including things like hotel bookings. I’m happy about that. I think there’s like a lot of taxes that just suck for the economy and getting those down should be great all around. But I think that most companies like OpenAI will make more money at a lower margin.

…I think the way to monetize the world’s smartest model is certainly not hotel booking.  …I want to discover new science and figure out a way to monetize that. You can only do with the smartest model.

There is a question of, should, many people have asked, should OpenAI do ChatGPT at all? Why don’t you just go build AGI? Why don’t you go discover a cure for every disease, nuclear fusion, cheap rockets, the whole thing, and just license that technology? And it is not an unfair question because I believe that is the stuff that we will do that will be most important and make the most money eventually.

…Maybe some people will only ever book hotels and not do anything else, but a lot of people will figure out they can do more and more stuff and create new companies and ideas and art and whatever.

So maybe ChatGPT and hotel booking and whatever else is not the best way we can make money. In fact, I’m certain it’s not. I do think it’s a very important thing to do for the world, and I’m happy for OpenAI to do some things that are not the economic maxing thing.”

Advertisements May Be Coming To ChatGPT

At around the 18 minute mark the interviewer asked Altman about advertising on OpenAI and Altman acknowledged that there may be a form of advertising but was vague about what that would look like.

He explained:

“Again, there’s a kind of ad that I think would be really bad, like the one we talked about.

There are kinds of ads that I think would be very good or pretty good to do. I expect it’s something we’ll try at some point. I do not think it is our biggest revenue opportunity.”

The interviewer asked:

“What will the ad look like on the page?”

Altman responded:

“I have no idea. You asked like a question about productivity earlier. I’m really good about not doing the things I don’t want to do.”

Takeaway

Sam Altman suggests an interesting way forward on how to monetize Internet users. His way is based on trust and finding a way to monetize that doesn’t betray that trust.

Watch the interview starting at about the 16 minute mark:

[embedded content]

Featured image/Screenshot from interview

https://www.searchenginejournal.com/openais-sam-altman-raises-possibility-of-ads-on-chatgpt/560107/




Perplexity Bets $400M On Snapchat To Scale AI Search Adoption via @sejournal, @MattGSouthern

Perplexity will pay Snap $400 million to integrate its AI answer engine into Snapchat’s chat interface, with rollout starting next year.

  • Perplexity will pay Snap $400 million over one year to integrate its AI answer engine into Snapchat.
  • Snap calls this its first large-scale integration of an external AI partner directly in the app.
  • Perplexity handles 150+ million questions weekly, so the integration meaningfully expands distribution.

https://www.searchenginejournal.com/perplexity-bets-400m-on-snapchat-to-scale-ai-search-adoption/560083/




Google Deprecates Practice Problem Structured Data In Search via @sejournal, @MattGSouthern

Google will deprecate practice problem structured data in January and clarifies Dataset markup is only for Dataset Search. Book actions remain supported.

  • Practice problem markup is being deprecated from Google Search in January.
  • Dataset structured data is for Dataset Search only; it isn’t used in Google Search.
  • Book actions continue to work in Google Search.

https://www.searchenginejournal.com/google-deprecates-practice-problem-structured-data-in-search/560076/




Scoperte nuove vulnerabilità di ChatGPT che portano a leak di dati


I ricercatori di Tenable Research hanno scoperto nuove vulnerabilità in ChatGPT che consentono a un attaccante di esfiltrare dati e informazioni personali dalle chat degli utenti. I bug permetterebbero agli attaccanti di provocare leak di dati senza che le vittime se ne accorgano, tramite prompt injection indiretta.

vulnerabilità ChatGPT

In tutto, i ricercatori hanno trovato sette tra vulnerabilità e tecniche di attacco che sfruttano le debolezze di ChatGPT:

  • una vulnerabilità di prompt injection indiretta tramite Browsing Context: gli attaccanti iniettano comandi malevoli in sezioni di blog e articoli, così che quando l’utente richiede un riassunto o una ricerca su queste fonti, quelli vengono eseguiti;
  • una vulnerabilità di prompt injection indiretta zero-day in Search Context: gli attaccanti inseriscono un prompt malevolo nascosto in un sito web che viene servito solo all’agente di ricerca dell’LLM e non all’utente. Il comando malevolo viene eseguito non appena il sito viene indicizzato dalla ricerca del chatbot;
  • una 1-click prompt injection: in questo caso il prompt malevolo viene inserito in un link creato ad hoc del tipo “chatgpt[.]com/?q={Prompt}”, in modo che il chatbot elabori il contenuto del parametro “q” come una normale richiesta utente;
  • un Safety Mechanism Bypass, ovvero un tecnica che elude la validazione di sicurezza url_safe che il chatbot usa per capire se un URL è sicuro. Il bug sfrutta il fatto che domini noti come bing.com sono in una whitelist e superano sempre il controllo di sicurezza. I risultati di ricerca di Bing sono serviti tramite link di tracciamento reindirizzanti statici (bing.com/ck/a…). L’attaccante indicizza i siti web di prova su Bing per ottenere questi link di tracciamento statici, considerati “sicuri” dall’LLM, permettendo così al contenuto finale del sito di essere renderizzato, mascherando gli URL malevoli;
  • una Conversation Injection Technique, ovvero una tecnica che usa una prompt injection di primo livello inserendo i prompt malevoli nei siti web combinata a una conversation injection che prevede la generazione di un output manipolato. I comandi malevoli non sono quindi solo nei siti web, ma anche nell’output; questo diventa parte della conversazione con l’utente e del contesto e viene usato per rispondere a richieste future;
  • una tecnica per nascondere il contenuto malevolo che sfrutta un bug del modo in cui ChatGPT renderinzza il markdown: renderizzando i blocchi di codice (con “`), tutte le parole della prima riga (tranne la prima parola) non vengono mostrate nella risposta;
  • infine, una tecnica di memory injection, variazione della conversation injection che mira a rendere l’attacco persistente: l’attaccante usa SearchGPT per iniettare un comando nel contesto, ma il prompt è progettato per manipolare la memoria del chatbot, causando leak a prescindere dalla sessione e dalla chat.

“L’iniezione di prompt è un problema noto legato al funzionamento dei modelli di linguaggio grande (LLM) e, purtroppo, probabilmente non verrà risolto in modo sistematico nel prossimo futuro. I fornitori di IA dovrebbero assicurarsi che tutti i loro meccanismi di sicurezza (come url_safe) funzionino correttamente per limitare i potenziali danni causati dall’iniezione di prompt” hanno affermato i ricercatori di Tenable Research.

Il team della compagnia ha pubblicato una serie di PoC effettuate su ChatGPT 4o, ma la maggior parte delle vulnerabilità è presente anche in ChatGPT 5. I ricercatori riportano che OpenAI ha rilasciato dei fix per la prompt injection tramite parametro nell’URL, per la vulnerabilità che consente la manipolazione della memoria del chatbot e per il bypass di url_safe.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/11/05/scoperte-nuove-vulnerabilita-di-chatgpt-che-portano-a-leak-di-dati/?utm_source=rss&utm_medium=rss&utm_campaign=scoperte-nuove-vulnerabilita-di-chatgpt-che-portano-a-leak-di-dati




YouTube Separates Organic & Paid Metrics In Channel Analytics via @sejournal, @MattGSouthern

YouTube introduced separate filtering for organic and paid traffic metrics in YouTube Analytics, allowing you to distinguish between unpaid and promoted content performance.

Channels can now filter views, engaged views, likes, comments, shares, and watchtime by traffic source. The update addresses longstanding questions about how paid advertising affects organic channel growth.

YouTube’s announcement included clarification that advertising doesn’t negatively impact organic performance, stating the two systems operate independently.

What’s New

The Analytics update adds traffic source filtering across core engagement metrics.

You can view performance data split between organic sources and paid advertisements, including YouTube Promote campaigns and brand-sponsored content.

YouTube’s announcement stated:

“Organic performance is determined by how the platform’s algorithm recommends your video to viewers based on factors like watch time, engagement, and audience retention. This is your video’s word of mouth reach, determined by the quality of the content itself. Whether or not it also runs as an ad has no impact.”

The platform distinguishes paid ad performance as determined by budget and targeting settings rather than algorithmic recommendations.

This is explained in more detail in the video below:

[embedded content]

Addressing Performance Questions

YouTube addressed creator concerns about lower aggregate metrics when combining organic and paid performance.

The announcement noted that advertising often targets new audiences who may engage at lower rates than existing subscribers, which can reduce overall retention and click-through metrics when viewed in aggregate.

The new filtering allows creators to analyze each traffic source separately rather than viewing combined data.

Why This Matters

You can now measure organic content performance without paid promotion data affecting your metrics.

This separation helps identify which growth strategies work independently rather than attributing paid gains to organic strategy or vice versa.

The filtering clarifies whether audience retention issues stem from content quality or new audience targeting in ad campaigns.

Looking Ahead

The traffic filtering feature is available now in YouTube Analytics. YouTube didn’t specify whether additional metrics or filtering options will be added to the organic versus paid breakdown.

The update coincides with YouTube’s October 2025 terminology change renaming the “Views” metric to “TrueView views” in Google Ads reporting, though this naming change doesn’t affect how views are counted or billed.


Featured Image: T. Schneider/Shutterstock

https://www.searchenginejournal.com/youtube-separates-organic-paid-metrics-in-channel-analytics/560045/