Proton Pass is discounting its Family plan, and the offer is a reminder that the strongest security tools still depend on how people use them.
A discount may be the headline hook, but the technical story is the shift from malware blocking to detecting phishing, fake websites, and synthetic media before users act.
A targeted email lure tied to aerospace branding reportedly used a password-protected archive, a multi-stage dropper, and legitimate remote-access software to create a stealthy access path.
A fake business document and a trusted support app can be enough to create durable access, especially when defenders do not tightly govern remote software.
A World Cup-themed phishing run is turning event excitement into a payment-data trap, using counterfeit reward pages and email lures that can look legitimate enough to get past routine checks.
A NordPass discount may be the headline hook, but the deeper story is the shift from reusable passwords to phishing-resistant authentication that can shrink the value of stolen credentials.
The browser’s new Paste Protect feature targets a social-engineering pattern that turns copied text into risky command execution.
Opera has added a default-on browser defense aimed at clipboard hijacking and command injection, a reminder that the paste action can carry more risk than it appears.
Paste Protect is built into the browser, enabled by default on Windows, macOS, and Linux, and aimed at cutting off clipboard hijacking and ClickFix-style code injection before a user can paste trouble into place.
With Paste Protect, Opera is trying to blunt ClickFix-style lures that turn social engineering into a command execution problem.
Awareness campaigns are meant to harden people against phishing, but the data they generate can pull security teams into GDPR territory if they are not tightly scoped and retained.
An alert about messages using the Commissariato di P.S. Online brand shows how criminals can borrow institutional trust to make a fraud narrative feel urgent and believable.
A phishing wave aimed at commercial messaging apps shows how account recovery, not encryption, can become the weakest point in secure communication.
A long-running support-impersonation scheme shows how one convincing conversation can matter more than any exploit against the app itself.
Italy’s national CSIRT is warning about an ongoing ClickFix phishing pattern that pushes victims to run malicious commands themselves, a reminder that social engineering can be as dangerous as any exploit.
A new payment-lure campaign turns the language of sanctions and official notices into a social-engineering weapon, betting that urgency will outrun verification.
A government awareness campaign, a parental vademecum, and a short spot place digital dependence in the spotlight, with child screen use framed as a behavior issue that starts at home.
A malicious email campaign dressed as electronic invoicing shows how trusted business channels can be turned into low-friction phishing paths.
A Polizia di Stato awareness project in Como puts scam prevention in the spotlight, showing how cyber defense often begins with recognition, not reaction.
A phishing wave themed around SEND and pagoPA shows how attackers can turn trusted civic branding into a believable trap.