Marketing Is 4th Most Exposed To GenAI, Indeed Study Finds via @sejournal, @MattGSouthern

Marketing professionals face one of the highest levels of potential AI disruption across all occupations, with 69% of marketing job skills positioned for transformation by generative AI, according to new data from Indeed.

The analysis evaluated nearly 2,900 work skills against U.S. job postings and found that marketing is the fourth most exposed profession, trailing only software development, data and analytics, and accounting.

The Shift From Doing To Directing

Indeed’s GenAI Skill Transformation Index groups skills into four levels: minimal, assisted, hybrid, and full transformation.

For marketing professionals, the majority of affected skills fall into hybrid transformation, where AI handles routine execution while humans provide oversight, validation, and strategic direction.

Indeed writes:

“Human oversight will remain critical when applying these skills, but GenAI can already perform a significant portion of routine work.”

That covers tasks AI can complete reliably in standard cases, with people stepping in to manage exceptions, interpret ambiguous situations, and ensure quality control.

What Marketing Skills Are Most at Risk?

Administrative, documentation, and text-processing tasks show high transformation potential, where AI already performs well at information retrieval, drafting, and analysis.

Communication-related work sits in the hybrid zone for many occupations. In one example from the report, communication skills appear in 23% of nursing postings and are classified as “hybrid.” This illustrates how routine language tasks are increasingly AI-assistable while human judgment remains essential.

How the Study Scored Skills

The study used multiple large language models and based its ratings on consistent results from OpenAI’s GPT-4.1 and Anthropic’s Claude Sonnet 4, noting that model performance varies.

The team evaluated each skill on two dimensions: problem-solving requirements and physical necessity. Marketing scores high on problem-solving and low on physical necessity, making many skills strong candidates for AI transformation.

A Change From Previous Research

Earlier Hiring Lab work found zero skills “very likely” to be fully replaced by GenAI.

In this update, the report identifies 19 skills (0.7% of the ~2,900 analyzed) that cross that “very likely” threshold. The authors frame this as incremental progress toward end-to-end automation for narrow, well-structured tasks, not broad replacement.

The Broader Employment Picture

Across the labor market, 26% of jobs on Indeed could be highly transformed by GenAI, 54% are moderately transformed, and 20% show low exposure.

These are measures of potential transformation. Actual outcomes depend on adoption, workflow design, and reskilling.

The report notes:

“Any realized impacts will depend entirely on whether and how businesses adopt and integrate GenAI tools…”

Marketing vs. Other Professions

Software development tops the list with 81% of skills facing transformation, followed by data and analytics (79%) and accounting (74%).

On the other end, nursing shows 33% skill transformation, with core patient-care responsibilities remaining human-centered.

Marketing’s position reflects its reliance on cognitive, screen-based work that AI can increasingly assist.

Not All AI Models Are Equal

The report emphasizes that model choice matters. Different models varied in output quality and stability, so teams should test tools against their own use cases rather than assume uniform performance.

Looking Ahead

The report’s authors, Annina Hering and Arcenis Rojas, created the GenAI Skill Transformation Index to reflect the level of transformation rather than simple replacement.

They advise developing skills that complement AI, such as strategy, creative problem-solving, and the ability to validate and interpret AI-generated outputs.

The timeline for these changes will differ depending on the size of the company, the industry, and how digitally advanced they are.

But the overall trend is clear: roles are evolving from hands-on task execution to overseeing AI and developing strategies. Those who stay ahead by adopting hybrid workflows will likely be in the best position.


Featured Image: Roman Samborskyi/Shutterstock

https://www.searchenginejournal.com/marketing-is-4th-most-exposed-to-genai-indeed-study-finds/556911/




SISTRIX Reports Sharp Drop In ChatGPT Web Searches via @sejournal, @MattGSouthern

SISTRIX reports that ChatGPT is triggering live web searches far less often for people who use the app without logging in.

In daily spot-checks over the last two weeks, the share of answers that called the web fell from above 15% to below 2.5%. SISTRIX does not assign a cause and notes the observation applies to anonymous sessions.

What Changed

SISTRIX says it “analyses numerous ChatGPT responses to a wide variety of prompts” each day and recently “noticed that ChatGPT uses web searches significantly less frequently.”

It adds that, “at least when using the app without an account,” the measured rate of responses completed via a web search declined sharply in the period reviewed.

SISTRIX doesn’t publish a sample size, list of prompts, or detection method in the post.

SISTRIX also writes that ChatGPT has “traditionally” relied on Bing for web lookups and references rumors of Google data being used, but it doesn’t claim a direct link between any specific backend change and the measured decline.

Related Context

Microsoft Bing Search APIs Retirement

Microsoft announced that the Bing Search APIs were retired on August 11.

Some third-party tools have migrated to alternatives. This doesn’t prove a change inside ChatGPT, but it’s a relevant ecosystem shift.

Google’s SERP Access Changes

SISTRIX separately documented that Google no longer supports the “num=100” parameter and now returns 10 results per request, increasing the effort required to collect SERP data at scale.

Again, this is context rather than causation.

Recent ChatGPT Product Notes

OpenAI’s release notes list “improvements to search in ChatGPT” on September 16, without detailing backend sourcing.

That update may be unrelated to the SISTRIX measurement, but is worth noting in the same timeframe.

Why This Matters

If ChatGPT is consulting the web less frequently in anonymous sessions, you might notice fewer answers citing current sources and a greater reliance on the model’s internal knowledge for those users.

This could influence how often recent news is referenced in responses for users who aren’t logged in, although the behavior may differ for Plus or Enterprise accounts.

Looking Ahead

SISTRIX’s observation is limited to a specific time frame and anonymous usage. Currently, there’s no confirmed information from OpenAI about how frequently ChatGPT performs live lookups overall, and SISTRIX hasn’t provided a reason for the recent drop.

The most cautious conclusion is that one independent measurement showed a sharp short-term decline, which deserves further testing.


Featured Image: matakeris.creative/Shutterstock

https://www.searchenginejournal.com/sistrix-reports-sharp-drop-in-chatgpt-web-searches/556835/




Newfold Digital Sells MarkMonitor As Part Of Strategic Refocus via @sejournal, @martinibuster

London-headquartered corporate domain management company Com Laude announced the acquisition of its competitor, MarkMonitor, previously one of the holdings of Newfold Digital.

Newfold Digital Simplifies Portfolio

Newfold Digital owns many top Internet brands like Yoast, Bluehost, Register.com, and Domain.com, all businesses that focus on small and medium-sized businesses. This divestiture may be a sign that Newfold Digital may be shifting away from the enterprise market and toward focusing its portfolio of web services on the SMB end of the market.

The official Newfold Digital press release states:

“The sale is part of Newfold Digital’s strategy to simplify its portfolio and double down on the areas where it can deliver the greatest value to customers – its core brands, Bluehost and Network Solutions. ”

Stu Homan, Head of MarkMonitor, commented:

“With this acquisition, Markmonitor has found owners who value our dedicated corporate services as much as our customers do. Com Laude is deeply committed to preserving and building upon our ability to continue to deliver industry-leading customer service while growing to new levels with dedication and investment.

Our entire team is excited to bring Com Laude’s advanced tools and services to our customers, and to be part of the most exciting development in corporate domain services since Markmonitor invented the white glove service model twenty-six years ago.”

Previous to the acquisition, Com Laude was a competitor of MarkMonitor, offering services that were similar to MarkMonitor but with key differences and technologies like an AI-powered domain management dashboard.

Com Laude is headquartered in London, United Kingdom, and MarkMonitor is in Boise, Idaho, which is not commonly regarded as the center of Internet commerce or technology but is actually a growing regional technology hub.

Benjamin Crawford, CEO of Com Laude, remarked:

“Markmonitor is the best-known name in domain services for corporate customers, having virtually invented the category twenty-six years ago, and since then grown a long list of blue-chip customers with its “white glove” customer service. Com Laude offers market leading advanced tools and bespoke services in domains and online brand protection, developed for the world’s largest companies and most valuable brands. Together we will be uniquely positioned to protect and grow the digital presence of any company that needs assistance with its domain names, internet infrastructure and security, online brand protection, internet policy and compliance, and online strategy.”

Read Com Laude’s announcement:

Com Laude to Acquire Markmonitor in a Landmark Transaction

Featured Image by Shutterstock/thodonal88

https://www.searchenginejournal.com/newfold-digital-sells-markmonitor-as-part-of-strategic-refocus/556814/




Google App Adds Search Live For Real-Time Visual Search via @sejournal, @MattGSouthern

Google has rolled out Search Live in English in the United States, bringing real-time, camera-aware conversations to the Google app on Android and iOS.

You can tap the new Live icon under the search bar, or open Google Lens and choose Live to start an interactive voice conversation that can also see what your camera sees.

Rajan Patel, VP of Engineering for Search at Google, highlights the launch in a post on X:

How It Works

Search Live has two entry points. In the Google app, you can start a voice conversation and optionally enable video input.

Look for the icon shown below:

Image Credit: Google

In Lens, camera sharing is on by default so you can immediately ask questions about what is in front of you and get follow-ups with links to dig deeper on the web.

Google highlights practical scenarios such as hands-free trip planning, quick how-to guidance for hobbies, step-by-step troubleshooting for electronics without typing model numbers, support for school projects, and picking a board game by scanning several boxes at once.

See it in action in this launch video:

[embedded content]

Why This Matters

Search Live moves queries from typed text to camera and voice, with answers arriving while people are actively engaged in tasks.

You can capture these searchers by prioritizing content that answers specific, in-the-moment questions. Ensure that your visual information is accurate and easily recognizable.

Local businesses should consider keeping storefront photos, product imagery, and key details current since people can now point, ask, and get links in real time.

Looking Ahead

Search Live is only launching in English in the U.S. for now, but Google says more languages and regions are coming.

This launch continues Google’s push to move everyday search beyond the keyboard. Businesses that prepare their content and visuals for that shift will be better positioned when the rollout expands

https://www.searchenginejournal.com/google-app-adds-search-live-for-real-time-visual-search/556816/




Attaccanti sfruttano un bug di GeoServer per attaccare un’agenzia governativa U.S.A.


In un recente advisory di sicurezza, la CISA ha reso noto che un gruppo di attaccanti ha sfruttato una vulnerabilità di GeoServer per attaccare un’agenzia governativa U.S.A., riuscendo ad agire di nascosto per tre settimane prima di far scattare qualsiasi alert di sicurezza.

Il gruppo ha sfruttato la CVE-2024-36401, una vulnerabilità di GeoServer che permette l’esecuzione di codice remoto anche agli utenti non autenticati. Secondo il report, il gruppo è riuscito ad accedere separatamente a due server per poi muoversi lateralmente verso altri due.

La vulnerabilità era stata resa nota il 30 giugno 2024 e gli attaccanti sono riusciti a ottenere un primo accesso ai sistemi governativi l’11 luglio, poco più di una settimana dopo. Il secondo server è stato compromesso il 24 luglio. Su ogni server, gli attaccanti hanno caricato alcune web shell, tra le quali China Chopper, insieme a script per l’accesso remoto, il mantenimento della persistenza, l’esecuzione di comandi da remoto e l’escalation dei privilegi.

Il gruppo, dopo aver ottenuto l’accesso, ha anche eseguito una serie di tecniche brute force per ottenere le password salvate sui sistemi.

GeoServer

Oltre all’analisi tecnica dell’accaduto, CISA ha evidenziato gli errori commessi dall’agenzia che hanno portato all’incidente, al fine di sensibilizzare le organizzazioni. In primo luogo, l’agenzia non aveva applicato le patch disponibili per la vulnerabilità. “Le agenzie FCEB sono obbligate a risolvere le vulnerabilità presenti nel catalogo KEV della CISA entro i tempi prescritti dalla direttiva operativa vincolante (BOD) 22-01” spiega la CISA.

L’agenzia, inoltre, non ha testato né messo in pratica il suo Piano di Risposta agli Incidenti (IRP), né l’IRP prevedeva il coinvolgimento di terze parti che potessero accedere alle risorse necessarie, complicando l’attività della CISA.

Infine, gli alert EDR non venivano monitorati adeguatamente e alcuni sistemi esposti a internet non erano protetti.

L’Agenzia di cybersecurity statunitense non ha reso nota la provenienza del gruppo, ma l’uso di China Copper indicherebbe un coinvolgimento di cybercriminali cinesi.

CISA ha soprannominato queste tre criticità delle “lesson learned”; bisognerà valutare a stretto giro se effettivamente queste problematiche sono state recepite e comprese dalle organizzazioni.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/24/attaccanti-sfruttano-un-bug-di-geoserver-per-attaccare-unagenzia-governativa-u-s-a/?utm_source=rss&utm_medium=rss&utm_campaign=attaccanti-sfruttano-un-bug-di-geoserver-per-attaccare-unagenzia-governativa-u-s-a




Are AI Search Summaries Making Evergreen Articles Obsolete? via @sejournal, @martinibuster

Ahrefs’ Tim Soulo recently posted that AI is making publishing evergreen content obsolete and no longer worth the investment because AI summaries leave fewer clicks for publishers.  He posits that it may be more profitable to focus on trending topics, calling it Fast SEO.  Is publishing evergreen content no longer a viable content strategy?

The Reason For Evergreen Content

Evergreen content can be a basic topic that generally doesn’t change much from year to year. For example, the answer to how to change a tire will generally always be the same.

The promise of evergreen content was that it represents a steady source of traffic. Once a web page is ranking for evergreen topics, publishers basically just have to make sure that it’s updated if the topic has changed in some way.

Does AI Break The Evergreen Content Promise?

Tim Soulo is suggesting that evergreen content, which can be easy to answer with a summary, is less likely to send a click because AI summarizes the answer and satisfies the user, who may not need to visit a website.

Soulo tweeted:

“The era of “evergreen SEO content” is over. We’re entering the era of “fast SEO.”

There’s little point in writing yet another “Ultimate Guide To ___.” Most evergreen topics have already been covered to death and turned into common knowledge. Google is therefore happy to give an AI answer, and searchers are fine with that.

Instead, the real opportunity lies in spotting and covering new trends — or even setting them yourself.”

Is Fast SEO The Future Of Publishing?

Fast SEO is another way of describing trending topics. Trending topics have always been around; it’s why Google invented the freshness algorithm, to satisfy users with up-to-date content when a “query deserves freshness.”

Soulo’s idea is that trending topics are not the kind of content that AI summarizes. Perplexity is the exception; it has an entire content discovery section called Perplexity Discover that’s dedicated to showing trending news articles.

Fast SEO is about spotting and seizing short-lived content opportunities. These can be new developments, shifts in the industry or perceptions, or cultural moments.

His tweet captures the current feeling within the SEO and publishing communities that AI is the reason for diminishing traffic from Google.

The Evergreen Content Situation Is Worse Than Imagined

A technical issue that Soulo didn’t mention but is relevant here is that it’s challenging to create an “Ultimate Guide To X, Y, Z” or the “Definitive Guide To Bla, Bla, Bla” and expect it to be fresh and different from what is already published.

The barrier to entry for evergreen content is higher now than it’s ever been for several reasons:

  • There are more people publishing content.
  • People are consuming multiple forms of content (text, audio, and video).
  • Search algorithms are focused on quality, which shuts out those who focus harder on SEO than they do on people.
  • User behavior signals are more reliable than traditional link signals, and SEOs still haven’t caught on to this, making it harder to rank.
  • Query Fan-Out is causing a huge disruption in SEO.

Why Query Fan-Out Is A Disruption

Evergreen content is an uphill struggle, compounded by the seeming inevitability that AI will summarize the content and, because of Query Fan-Out, possibly send the click to another website that is cited because it offers the answer to a follow-up question to the initial search query.

Query Fan-Out displays answers to the initial query and to follow-up questions to the initial search query. If the user is happy with the summary to the initial query, they may become interested in one of the follow-up queries, and one of those will get the click, not the initial query.

This completely changes what it means to target a search query. How does an SEO target a follow-up question? Maybe, instead of targeting the main high-traffic query, it may make sense to target the follow-up queries with evergreen content.

Evergreen Content Publishing Still Has Life

There is another side to this story, and it’s about user demand. Foundational questions stick around for a long time. People will always search “how to tie a bowtie” or “how to set up WordPress.” Many users prefer the stability of an established guide that has been reviewed and updated by a trusted brand. It’s not about being a brand; it’s about being the kind of site that is trusted, well-liked, and recommended.

A strong resource can become the canonical source for a topic, ranking for years and generating the kind of user behavior signals that reinforce its authority and signal the quality of being trusted.

Trend-driven content, by contrast, often delivers only a brief spike before fading. A newsroom model is difficult to maintain because it requires constant work to be first and be the best.

The Third Way: Do It All

The choice between producing evergreen content and trending topics doesn’t have to be binary; there’s a third option where you can do it all. Evergreen and trending topics can complement each other because each side provides opportunities for driving traffic to the other. Fresh, trend-driven content can link back to the evergreen, and this can be reversed to send readers to fresh content from the evergreen.

Trend-driven content sometimes becomes evergreen itself. But in general, creating evergreen content requires deep planning, quality execution, and marketing. Somebody’s going to get the click from evergreen content, it might as well be you.

Featured Image by Shutterstock/Stokkete

https://www.searchenginejournal.com/are-ai-search-summaries-making-evergreen-articles-obsolete/556721/




Pew: Most Americans Want AI Labels, Few Trust Detection via @sejournal, @MattGSouthern

A new Pew Research Center survey reveals a gap between people’s desire to know when AI is used in content and their confidence in being able to identify it.

Seventy-six percent say it’s extremely or very important to know whether pictures, videos, or text were made by AI or by people. Only 12% feel confident they could tell the difference themselves.

Pew Research Center wrote:

“Americans feel strongly that it’s important to be able to tell if pictures, videos or text were made by AI or by humans. Yet many don’t trust their own ability to spot AI-generated content.”

This confidence gap reflects a rising unease with AI.

Half of Americans believe that the increased presence of AI in daily life raises more concerns than excitement, while just 10% are more excited than worried.

What Pew Research Found

People Want More Control

About 60% of Americans want more control over AI in their lives, an increase from 55% last year.

They’re open to AI helping with daily tasks, but still want clarity on where AI ends and human involvement begins.

When People Accept vs. Reject AI

Most support the use of AI in data-intensive tasks, such as weather prediction, financial crime detection, fraud investigation, and drug development.

About two-thirds oppose AI in personal areas such as religious guidance and matchmaking.

Younger Audiences Are More Aware

Awareness of AI is highest among adults under 30, with 62% claiming they’ve heard a lot about it, compared to only 32% of those 65 and older.

But this awareness doesn’t lead to optimism. Younger adults are more likely than seniors to believe that AI will negatively impact creative thinking and the development of meaningful relationships.

Creativity Concerns

More Americans believe AI will negatively impact essential human skills.

Fifty-three percent think it will reduce creative thinking, and 50% feel it will hinder the ability to connect with others, with only a few expecting improvements.

This suggests labeling alone isn’t sufficient. Human input must also be evident in the work.

Why This Matters

People are generally not against AI, but they do want to know when AI is involved. Being open about AI use can help build trust.

Brands that go the transparent route might find themselves at an advantage in creating connections with their audience.

For more insights, see the full report.


Featured Image: Roman Samborskyi/Shutterstock

https://www.searchenginejournal.com/pew-most-americans-want-ai-labels-few-trust-detection/556697/




Review Signals Gain Influence In Top Google Local Rankings via @sejournal, @MattGSouthern

A new analysis from Search Atlas quantifies the interaction between proximity and reviews in local rankings.

Proximity drives visibility overall, while review signals become stronger differentiators in the highest positions.

This study examines 3,269 businesses across the food, health, law, and beauty sectors.

It shows that for positions 1–21, proximity influences 55% of decisions, while review count accounts for 19%. In the top ten, proximity’s influence decreases to 36%, but review count increases to 26%, with review keyword relevance reaching 22%.

Search Atlas writes:

Proximity is the top driver of local visibility.

The study also notes:

Proximity does not always dominate in elite positions.

What It Means

You’ll have a better chance of achieving top results by focusing on earning more reviews and naturally incorporating service-specific terms into reviews, rather than relying on your pin’s location on the map.

The report suggests that Google understands review text semantically. Using service-specific language in reviews can help your rankings for high-value queries.

How To Apply This

Think of proximity as your default setting. It’s fixed, so focus your attention on the inputs you can control.

When crafting your review requests, aim for natural, service-specific language. For instance, “best dentist for whitening” tends to work better than “great service.”

Also, ensure that your GBP name and profile details are aligned. The research shows that matching your business name to the search intent, such as “Downtown Dental Clinic” for someone searching “dentist near me,” can make a positive difference.

Sector Behavior

While the overall pattern remains consistent, shoppers can exhibit different behaviors across categories.

Per the report:

  • For Law, proximity tends to be the most important factor, with reviews playing a secondary role.
  • In Beauty, reputation signals are more influential. While proximity is still key, review volume and keywords are also important.
  • When it comes to Food, review content and profile relevance become especially valuable, particularly in crowded markets.
  • Health balances proximity with strong reviews and service alignment in reviews.

Looking Ahead

This study quantifies something practitioners have long suspected: proximity earns you a look, but review content helps you secure the top spot in the close contest.

If you can’t change your location, shape the language around it.

For more data on GBP ranking factors, see the full report.

Methods & Limits

The authors applied XGBoost to grid visibility, GBP metadata, website content, and reviews, achieving a global model that explains approximately 92–93% of the variance.

They emphasize that feature importance indicates correlation, not causation. Additionally, they warn that proximity might be overstated due to fixed grid collection and note that their results represent a snapshot in time.

Use these insights as guidance, not a strict rulebook.


Featured Image: Roman Samborskyi/Shutterstock

https://www.searchenginejournal.com/review-signals-gain-influence-in-top-google-local-rankings/556664/




CERT-AGID 13-19 settembre: il phishing punta alle criptovalute


Nella settimana appena conclusa il CERT-AGID ha rilevato un totale di 73 campagne malevole. Di queste, 43 sono state mirate specificamente a obiettivi nel nostro Paese, mentre le restanti 30, pur avendo carattere generico, hanno comunque avuto ricadute sul territorio nazionale.

Per supportare le attività di difesa, il CERT-AGID ha messo a disposizione degli enti accreditati 776 indicatori di compromissione, fondamentali per riconoscere e bloccare tempestivamente eventuali attività sospette.

I temi della settimana

Questa settimana sono stati sfruttati 18 temi diversi per diffondere campagne malevole in Italia.

Il fronte più caldo resta quello bancario: sono state individuate sedici campagne, quattordici delle quali con obiettivi italiani, che hanno preso di mira istituti come ING, BPM, Intesa Sanpaolo, Unicredit, Fineco, Crédit Agricole e InteractiveBrokers.

Sono state coinvolte anche piattaforme di pagamento come SumUp e PayPal, e tutte le campagne si sono propagate via email, con l’obiettivo di carpire credenziali e dati finanziari sensibili.

Nella settimana appena conclusa il CERT-AGID ha rilevato 73 campagne malevole e messo a disposizione degli enti accreditati 776 indicatori di compromissione.

Un altro tema ricorrente è stato quello delle multe: diverse campagne, tutte italiane, hanno abusato del brand PagoPA inviando false notifiche di sanzioni o avvisi di pagamento, nel tentativo di sottrarre i dati delle carte di credito delle vittime.

Non sono mancate le campagne legate agli ordini, sfruttate in nove circostanze, di cui sei a carattere generico e tre italiane, attraverso cui sono stati distribuiti vari tipi di malware.

A queste si aggiungono le campagne basate sul tema dei pagamenti, sei in tutto, che hanno incluso anche un tentativo di phishing a nome dell’Agenzia delle Entrate.

Infine, sono state rilevate cinque campagne che giocavano sulla scadenza dei servizi: quattro mirate al pubblico italiano e una generica.

In questo caso gli aggressori hanno simulato messaggi legati a webmail in scadenza, abusando sia di marchi generici sia di piattaforme come Zimbra. Lo scopo? Sottrarre le credenziali di accesso alle caselle di posta elettronica.

Tra le attività più rilevanti osservate negli ultimi giorni spiccano alcune campagne che meritano particolare attenzione. Una di queste ha preso di mira direttamente l’Agenzia delle Entrate con una operazione di phishing che puntava a sottrarre wallet di criptovalute.

I messaggi, camuffati da notifiche ufficiali, rimandavano a domini registrati di recente che riproducevano fedelmente l’interfaccia del portale dell’Agenzia.

Qui veniva simulata una procedura di dichiarazione online in cui si chiedevano dati personali e fiscali, per poi arrivare alla fase essenziale, ossia l’inserimento del wallet o della seed phrase di recupero. In questo modo gli attaccanti ottenevano accesso diretto ai fondi digitali delle vittime.

Il CERT-AGID ha inoltre analizzato una campagna che sfruttava PDQConnect, un software legittimo per la gestione remota normalmente usato dagli amministratori IT. La tecnica di diffusione prevedeva email che simulavano la condivisione di documenti e rimandavano a una finta pagina di login di Microsoft Outlook.

Fonte: CERT-AGID

Una volta verificata la corrispondenza dell’indirizzo, veniva proposto il download di un file MSI contenente il tool di controllo remoto, consentendo agli aggressori di prendere possesso del sistema della vittima.

Non meno insidiosa la campagna che ha abusato del nome del Politecnico di Milano per diffondere il malware FormBook, uno dei trojan più diffusi e specializzati nel furto di credenziali e dati sensibili.

L’inganno consisteva in email che invitavano a consultare documentazione necessaria per partecipare a un presunto progetto. L’allegato, un archivio ZIP, nascondeva uno script malevolo che avviava l’infezione.

Infine, è stata bloccata una nuova campagna di malspam condotta attraverso caselle PEC compromesse. In questo caso gli aggressori hanno diffuso MintLoader, confermando come l’uso abusivo della posta elettronica certificata resti una delle leve più pericolose per veicolare malware in Italia.

Malware della settimana

Nel corso della settimana sono state individuate ben 19 famiglie di malware attive sul territorio italiano.

Tra le campagne di maggiore rilievo spicca ancora una volta FormBook, con una distribuzione capillare sia attraverso messaggi a tema “preventivo” rivolti all’Italia, sia tramite email generiche a tema “ordine” e “prezzi”, tutte corredate da allegati in formato ZIP o Z.

A seguire si colloca Remcos, rilevato in una campagna bancaria diretta contro utenti italiani e in quattro campagne generiche legate a falsi contratti, ordini e pagamenti. In questo caso i file allegati arrivavano nei formati RAR, GZ e 7Z.

Fonte: CERT-AGID

Anche AgentTesla è tornato a farsi vedere con due campagne italiane a tema “consegna” e “ordine”, oltre a una generica sempre mascherata da avviso di consegna: tutte veicolate da archivi compressi RAR e TAR.

Particolarmente attiva anche la famiglia DarkCloud, che ha sfruttato allegati ZIP, GZ e XLAM per diffondersi attraverso tre campagne complessive, di cui una diretta al pubblico italiano.

Non meno insidioso Guloader, osservato in tre varianti: una italiana a tema “ordine” e due generiche che simulavano fatture e consegne, con allegati nei formati 7Z, RAR e MSI.

Il CERT-AGID ha inoltre intercettato una campagna italiana che diffondeva MintLoader tramite caselle PEC compromesse e allegati ZIP, mentre EagleSpy è emerso in un’operazione bancaria che usava SMS contenenti link a file APK malevoli.

Il quadro si completa con altre famiglie ben note al panorama della cybercriminalità: dalle italiane sLoad e PDQConnect fino a un ventaglio di minacce generiche come SnakeKeylogger, VipKeylogger, XWorm, Rhadamanthys, QuasarRAT, Purecrypter, PhantomStealer, Lumma e Grandoreiro.

Phishing della settimana

Sono 13 i brand finiti nel mirino delle campagne di phishing della settimana. A dominare la scena sono state le operazioni che hanno sfruttato il nome di PagoPA, ING e SumUp, con una frequenza tale da renderle le più riconoscibili del periodo.

Fonte: CERT-AGID

Accanto a queste si sono moltiplicate le campagne che imitavano servizi di posta elettronica, spesso non legate a un marchio preciso ma ugualmente efficaci nel trarre in inganno gli utenti grazie a notifiche apparentemente legittime di caselle in scadenza o richieste di aggiornamento credenziali.

Formati e canali di diffusione

Sul fronte tecnico continua a confermarsi la supremazia degli archivi compressi come principale vettore d’attacco. Nell’arco della settimana sono state impiegate tredici tipologie diverse di file, con una netta predominanza dei formati ZIP e RAR, utilizzati complessivamente in sei campagne.

Subito dietro si collocano i formati 7Z, GZ e Z, osservati in quattro episodi, mentre JS e MSI sono comparsi due volte ciascuno.

Più sporadico invece l’impiego di estensioni come XLAM, HTML, TAR, DOCX, APK e PS1, segnale di una diversificazione costante ma meno incisiva.

Fonte: CERT-AGID

Per quanto riguarda i canali di diffusione, le email si sono confermate ancora una volta lo strumento preferito dai criminali informatici, veicolando ben 71 delle campagne censite dal CERT-AGID.

Restano più marginali gli altri canali, con una sola campagna individuata tramite PEC e un’altra diffusa via SMS.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/22/cert-agid-13-19-settembre-phishing-criptovalute/?utm_source=rss&utm_medium=rss&utm_campaign=cert-agid-13-19-settembre-phishing-criptovalute




SonicWall vittima di un breach, la compagnia chiede ai clienti di resettare le credenziali


SonicWall ha confermato di essere stata vittima di un breach che ha colpito il servizio di backup cloud dei firewall. La compagnia sta ora chiedendo ai propri clienti di resettare urgentemente le credenziali dei servizi.

Nel dettaglio, gli attaccanti son riusciti ad accedere ai file di backup delle configurazioni dei firewall memorizzati e gestiti su MySonicWall.com. Secondo l’analisi della compagnia, sono stati sottratti file relativi a meno del 5% dei propri clienti. “Nonostante le credenziali memorizzate nei file siano criptate, i file includono anche informazioni che semplificano potenziali exploit legati ai fireall” ha sottolineato SonicWall.

La compagnia ha affermato che non si è trattato di un attacco ransomware, ma di una serie di attacchi bruteforce mirati. Al momento non ci sono indicazioni sui possibili autori degli attacchi.

SonicWall

Per verificare se i propri file di configurazione sono stati compromessi, è necessario effettuare il login al proprio account MySonicWall e verificare lo stato dei backup cloud. Se non ci sono backup per i firewall, allora non si è a rischio; in caso contrario, occorre verificare se il numero seriale del firewall (indicato sempre nella sezione dei backup) è presente nella sezione “Issue List” della piattaforma.

Nel caso in cui il numero di serie non sia presente nella lista, è comunque importante seguire gli aggiornamenti della compagnia per rilasci di eventuali informazioni e guide aggiuntive

In caso positivo, è fondamentale resettare immediatamente le password seguendo la guida fornita dalla compagnia. I clienti sono caldamente invitati, tra le altre cose, a resettare e aggiornare le password e il binding TOTP per tutti gli utenti locali, aggiornare i secret condivisi e resettare le password di tutti gli account email usati per l’automazione dei log.

SonicWall invita inoltre i propri clienti a importare i nuovi file di configurazione disponibili che includono password randomiche per tutti gli utenti, reset del binding TOTP per l’autenticazione e chiavi IPSec VPN randomiche.

Attualmente non ci sono informazioni su possibili leak dei file, ma è essenziale agire il prima possibile per anticipare eventuali incidenti.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/19/sonicwall-vittima-di-un-breach-la-compagnia-chiede-ai-clienti-di-resettare-le-credenziali/?utm_source=rss&utm_medium=rss&utm_campaign=sonicwall-vittima-di-un-breach-la-compagnia-chiede-ai-clienti-di-resettare-le-credenziali