Latest from Italy, updates in the state-sponsored landscape, ransomware and leaks
Italy: several malicious activities observed In the past week, several offensives have targeted Italian entities. Specifically, Microsoft reported an advanced phishing campaign exploiting the legitimate “device code flow” authentication mechanism...
Read moreWar in Iran and cyber operations, offensive activity in Italy, iOS threats, and phishing campaigns
Iran: cyber offensives linked to the conflict In the context of the escalation between the United States, Israel, and Iran, the cyber domain continues to represent a relevant operational space,...
Read moreCyber operations in the Iranian conflict, attacks in Italy, developments in the APT landscape
Iran: cyberattacks in the context of the conflict Within the context of the escalation between the United States, Israel, and Iran, the cyber domain continues to represent a significant operational...
Read moreIranian conflict and cyber warfare, attacks in Italy, LeakBase and Tycoon 2FA disrupted
Iran: cyber offensives linked to the conflict The conflict between the United States, Israel, and Iran has unfolded alongside extensive cyber operations, with reports of widespread internet disruptions, hacking of...
Read moreRansomware and phishing in Italy, new Asia-based state-sponsored activity, Cisco and Fortinet 0-days
Italy: new cybercrime attacks New operations linked to a phishing campaign themed around the renewal of the health insurance card have been identified in Italy, initially reported on January 8, 2026. The theme has proven...
Read moreNew attacks in Italy, data breaches reported, offensives from China
Italy: new phishing and ransomware offensives Over the past two weeks, multiple phishing campaigns have targeted Italian users. One operation abused the name and logo of Fineco Bank. In particular, a fraudulent email with the subject “Confirmation of...
Read moreUpdates on React2Shell exploitation, the latest from Beijing and Tehran, new attacks in Italy
React2Shell: EtherRAT and other malware delivered in state-sponsored and cybercrime activity During a recent attack based on the exploitation of the critical vulnerability CVE-2025-55182 (known as React2Shell), security researchers identified...
Read more