Italian SMEs and public offices are facing a quieter but harder problem: protecting sensitive communications as smartphones, cloud services, and collaboration apps pull them beyond traditional boundaries.
A phishing-led intrusion pattern shows how legitimate admin software can be turned into a backup access channel that survives partial cleanup.
ReliaQuest-linked findings point to compromised hospitality gateways being used against Microsoft 365 sign-ins, showing how network control can become an identity attack surface.
A compromise at the network edge can turn a routine travel login into a credential-and-token capture event, with cloud identity as the real target.
The alleged credential theft tied to Ernst & Young is a reminder that supply-chain claims can signal risk even before the technical details are confirmed.
Researchers identified a cyber-espionage campaign targeting Thailand’s Ministry of Finance in which hackers reportedly used an autonomous AI agent, a signal that agentic systems are entering offensive tradecraft.
A counterfeit Microsoft Teams update flow is being used to push legitimate remote management tools onto victim systems, blurring the line between phishing and admin software abuse.
Compromised wireless gateways can become a quiet interception layer for travelers, turning ordinary cloud sign-ins into credential risk without ever touching the inbox itself.
A breach at DentaQuest puts a spotlight on a less visible target class: the claims and benefits systems that can concentrate identity, billing, and health-related records in one place.
A large impersonation campaign used clone domains, copied branding, and AI-written pages to make bogus Windows app sites look routine and trustworthy.
Disney+ is running a time-limited offer in Italy, and the technical fine print around renewal, identity, and cancellation is where the real risk lives.
A trust-based campaign tied to BlueNoroff shows how compromised messaging accounts and fake meetings can turn one breach into the next.
A fake video-call lure, webcam permission prompts, and Defender tampering show how modern phishing can behave like a targeted intrusion chain rather than a simple credential scam.
A victim listing names the UK Department for Education and describes two contact datasets, but the public claim still falls short of confirmed compromise.
QR-code phishing is growing fast because it moves the scam out of text filters and into the scan step, where a personal phone may become the attacker’s real launchpad.
CTM360-linked research points to a shift from delayed credential theft to real-time account hijacking, a change that shrinks the defender’s window from hours to seconds.
Stealer logs are being used to support ransomware access paths that can bypass MFA in some environments.
A phishing lure impersonating a logistics workflow and a two-step script chain show how credential theft now depends less on flashy exploits and more on ordinary Windows tools.
A phishing run dressed up as shipping notices and tax-audit mail shows how attackers can turn everyday business trust into a credential-theft pipeline.
A reported flaw in ChatGPT Workspace Agents shows how one click can become an agent-launch event, not just a browser detour.