Sintesi riepilogativa delle campagne malevole nella settimana del 1 – 7 agosto
In questa settimana, il CERT-AGID ha riscontrato ed analizzato, nello scenario italiano di suo riferimento un totale di 135 campagne malevole, di cui 97 con obiettivi italiani e 38 generiche che hanno comunque interessato l’Italia, mettendo a disposizione dei suoi enti accreditati i relativi 1264 indicatori di compromissione (IoC) individuati.
by CERT-AgID - https://r.zerozone.it/post/uZuK4gxTn5MGxU88h
In questa settimana, il CERT-AGID ha riscontrato ed analizzato, nello scenario italiano di suo riferimento un totale di 135 campagne malevole, di cui 97 con obiettivi italiani e 38 generiche che hanno comunque interessato l’Italia, mettendo a disposizione dei suoi enti accreditati i relativi 1264 indicatori di compromissione (IoC) individuati.
by CERT-AgID - https://r.zerozone.it/post/uZuK4gxTn5MGxU88h
CERT-AGID
Sintesi riepilogativa delle campagne malevole nella settimana del 1 – 7 agosto
In questa settimana, il CERT-AGID ha riscontrato ed analizzato, nello scenario italiano di suo riferimento un totale di 135 campagne malevole, di cui 97 con obiettivi italiani e 38 generiche che hanno comunque interessato l’Italia, mettendo a disposizione…
XSS2Shell: nuova vulnerabilità nel core di WordPress può portare all’esecuzione di codice remoto
La compromissione completa non avviene attraverso la sola XSS. La catena dimostrata richiede che un amministratore WordPress già autenticato interagisca con una pagina predisposta dall'attaccante. In tale scenario, l'attaccante può sfruttare la sessione dell'amministratore fino ad ottenere una Application Password e, successivamente, utilizzarne i privilegi per arrivare al caricamento di [...]
by CERT-AgID - https://r.zerozone.it/post/1WWCm032AvYHxptP1
La compromissione completa non avviene attraverso la sola XSS. La catena dimostrata richiede che un amministratore WordPress già autenticato interagisca con una pagina predisposta dall'attaccante. In tale scenario, l'attaccante può sfruttare la sessione dell'amministratore fino ad ottenere una Application Password e, successivamente, utilizzarne i privilegi per arrivare al caricamento di [...]
by CERT-AgID - https://r.zerozone.it/post/1WWCm032AvYHxptP1
CERT-AGID
XSS2Shell: nuova vulnerabilità nel core di WordPress può portare all’esecuzione di codice remoto
La compromissione completa non avviene attraverso la sola XSS. La catena dimostrata richiede che un amministratore WordPress già autenticato interagisca con una pagina predisposta dall'attaccante. In tale scenario, l'attaccante può sfruttare la sessione …
Falsi QrCode da banca per svuotare conto corrente, primo caso in Liguria
https://www.rainews.it/tgr/liguria/articoli/2026/08/falsi-qrcode-da-banca-per-svuotare-conto-corrente-primo-caso-in-liguria-8baaf45c-7f5f-4db1-8293-73c34ce6abe1.html
https://www.rainews.it/tgr/liguria/articoli/2026/08/falsi-qrcode-da-banca-per-svuotare-conto-corrente-primo-caso-in-liguria-8baaf45c-7f5f-4db1-8293-73c34ce6abe1.html
RaiNews
Falsi QrCode da banca per svuotare conto corrente, primo caso in Liguria
Continuano le truffe 'tradizionali', a Molassana sottratti gioielli per 20mila euro
Nobema
Ransomware group called thegentlemen claims attack for Nobema. The target comes from Italy. We identify this attack with following hash code: 978864edf07d95cf9f5307fdea680b6e9f84b5da39396a3d55829836fe8679ad (ID: 34671)Target victim website: nobema.com
by RansomFeed - https://r.zerozone.it/post/frEWy7Yq6RDvNKbP5
Ransomware group called thegentlemen claims attack for Nobema. The target comes from Italy. We identify this attack with following hash code: 978864edf07d95cf9f5307fdea680b6e9f84b5da39396a3d55829836fe8679ad (ID: 34671)Target victim website: nobema.com
by RansomFeed - https://r.zerozone.it/post/frEWy7Yq6RDvNKbP5
Ransomfeed
TESI
Ransomware group called thegentlemen claims attack for TESI. The target comes from Italy. We identify this attack with following hash code: 9d3be6c9b0690f9669505f53457cc9c24e87137f7819cb76274e9a137318917a (ID: 34674)Target victim website: tesiimpianti.it
by RansomFeed - https://r.zerozone.it/post/UWYh1sPCAFQcdaANW
Ransomware group called thegentlemen claims attack for TESI. The target comes from Italy. We identify this attack with following hash code: 9d3be6c9b0690f9669505f53457cc9c24e87137f7819cb76274e9a137318917a (ID: 34674)Target victim website: tesiimpianti.it
by RansomFeed - https://r.zerozone.it/post/UWYh1sPCAFQcdaANW
Hitech Distribuzione Informatica S.r.l. (HTDI)
Ransomware group called spacebears claims attack for Hitech Distribuzione Informatica S.r.l. (HTDI). The target comes from Italy. We identify this attack with following hash code: 79beceb127d860f1b24292e72bf3d2c9c43ef80a1092dd7541e58a7f67b647ec (ID: 34727)Target victim website: www.htdi.it
by RansomFeed - https://r.zerozone.it/post/feSwA48aMXcW39Mkz
Ransomware group called spacebears claims attack for Hitech Distribuzione Informatica S.r.l. (HTDI). The target comes from Italy. We identify this attack with following hash code: 79beceb127d860f1b24292e72bf3d2c9c43ef80a1092dd7541e58a7f67b647ec (ID: 34727)Target victim website: www.htdi.it
by RansomFeed - https://r.zerozone.it/post/feSwA48aMXcW39Mkz
r.zerozone.it
TeleBotr
TeleBotr - Telegram publishing platform
studiotibaldi.it
Ransomware group called krybit claims attack for studiotibaldi.it. The target comes from Italy. We identify this attack with following hash code: e35284be35343cdfccf3aca62022643ec5dbc0eb97ab8938fa0bf1868ae46ce7 (ID: 34740)Target victim website: studiotibaldi.it
by RansomFeed - https://r.zerozone.it/post/rXUhnT2MdgmstQjBx
Ransomware group called krybit claims attack for studiotibaldi.it. The target comes from Italy. We identify this attack with following hash code: e35284be35343cdfccf3aca62022643ec5dbc0eb97ab8938fa0bf1868ae46ce7 (ID: 34740)Target victim website: studiotibaldi.it
by RansomFeed - https://r.zerozone.it/post/rXUhnT2MdgmstQjBx
Marconi Industrial Services
Ransomware group called play claims attack for Marconi Industrial Services. The target comes from Italy. We identify this attack with following hash code: 3c76e245d59e47937c4a778caae8878ef12cc6283850f6d676637e5820dbb8f8 (ID: 34757)Target victim website: www.marconi-spa.com
by RansomFeed - https://r.zerozone.it/post/xVBTVpnAmGrFWaAkV
Ransomware group called play claims attack for Marconi Industrial Services. The target comes from Italy. We identify this attack with following hash code: 3c76e245d59e47937c4a778caae8878ef12cc6283850f6d676637e5820dbb8f8 (ID: 34757)Target victim website: www.marconi-spa.com
by RansomFeed - https://r.zerozone.it/post/xVBTVpnAmGrFWaAkV
Ransomfeed
Feraboli Zootech
Ransomware group called thegentlemen claims attack for Feraboli Zootech. The target comes from Italy. We identify this attack with following hash code: 01e139eddd583204530a26cb5636886b52884e4ed7bdbb6da88d43ea302ab9a2 (ID: 34672)Target victim website: feraboli.it
by RansomFeed - https://r.zerozone.it/post/qMxnEe0dVAGUKjCRF
Ransomware group called thegentlemen claims attack for Feraboli Zootech. The target comes from Italy. We identify this attack with following hash code: 01e139eddd583204530a26cb5636886b52884e4ed7bdbb6da88d43ea302ab9a2 (ID: 34672)Target victim website: feraboli.it
by RansomFeed - https://r.zerozone.it/post/qMxnEe0dVAGUKjCRF
Vemec
Ransomware group called thegentlemen claims attack for Vemec. The target comes from Italy. We identify this attack with following hash code: 7f7997651ea15bfa65f9c489ec7bb0ee7a909b4ab37d4ad5b3fa018ec06926d2 (ID: 34670)Target victim website: vemecsrl.com
by RansomFeed - https://r.zerozone.it/post/sUhcUwS0kzJWgUg0h
Ransomware group called thegentlemen claims attack for Vemec. The target comes from Italy. We identify this attack with following hash code: 7f7997651ea15bfa65f9c489ec7bb0ee7a909b4ab37d4ad5b3fa018ec06926d2 (ID: 34670)Target victim website: vemecsrl.com
by RansomFeed - https://r.zerozone.it/post/sUhcUwS0kzJWgUg0h
r.zerozone.it
TeleBotr
TeleBotr - Telegram publishing platform
HIWIN
Ransomware group called thegentlemen claims attack for HIWIN. The target comes from Italy. We identify this attack with following hash code: 1a09ecf6ad44db315910e6ed5de2bae04684bb23974edc547078ff8c3e36d7e4 (ID: 34676)Target victim website: hiwin.it
by RansomFeed - https://r.zerozone.it/post/JkHPqjgfBbjjn2Kv0
Ransomware group called thegentlemen claims attack for HIWIN. The target comes from Italy. We identify this attack with following hash code: 1a09ecf6ad44db315910e6ed5de2bae04684bb23974edc547078ff8c3e36d7e4 (ID: 34676)Target victim website: hiwin.it
by RansomFeed - https://r.zerozone.it/post/JkHPqjgfBbjjn2Kv0
Ransomfeed
Smishing a tema INPS: implementata verifica documentale tramite intelligenza artificiale
Nelle ultime giornate il CERT-AGID ha osservato un consistente incremento delle campagne di smishing che sfruttano il nome, il logo e la grafica di INPS. Ciò che cambia, in questa nuova ondata, è l'introduzione di un ulteriore livello di controllo sui file caricati dalla vittima, basato su un modello di [...]
by CERT-AgID - https://r.zerozone.it/post/ygd74BZEyM3B8bGfS
Nelle ultime giornate il CERT-AGID ha osservato un consistente incremento delle campagne di smishing che sfruttano il nome, il logo e la grafica di INPS. Ciò che cambia, in questa nuova ondata, è l'introduzione di un ulteriore livello di controllo sui file caricati dalla vittima, basato su un modello di [...]
by CERT-AgID - https://r.zerozone.it/post/ygd74BZEyM3B8bGfS
CERT-AGID
Smishing a tema INPS: implementata verifica documentale tramite intelligenza artificiale
Nelle ultime giornate il CERT-AGID ha osservato un consistente incremento delle campagne di smishing che sfruttano il nome, il logo e la grafica di INPS. Ciò che cambia, in questa nuova ondata, è l'introduzione di un ulteriore livello di controllo sui file…
Verona 83
Ransomware group called bravox claims attack for Verona 83. The target comes from Italy. We identify this attack with following hash code: d86de1ddd72381c711af02bb781fd5ede945f53b02c47fd3a892d00c5210e640 (ID: 34789)Target victim website: www.verona83.it
by RansomFeed - https://r.zerozone.it/post/FCvu6xPh3eXzmnkeu
Ransomware group called bravox claims attack for Verona 83. The target comes from Italy. We identify this attack with following hash code: d86de1ddd72381c711af02bb781fd5ede945f53b02c47fd3a892d00c5210e640 (ID: 34789)Target victim website: www.verona83.it
by RansomFeed - https://r.zerozone.it/post/FCvu6xPh3eXzmnkeu
r.zerozone.it
TeleBotr
TeleBotr - Telegram publishing platform
Elettrica System
Ransomware group called bravox claims attack for Elettrica System. The target comes from Italy. We identify this attack with following hash code: 2369a7e333be5007e58625602625fe223858798ae6aa8403ec192b1f16aa3e26 (ID: 34791)Target victim website: www.elettricasystem.it
by RansomFeed - https://r.zerozone.it/post/FDwNXNVaQpt5r0Sj2
Ransomware group called bravox claims attack for Elettrica System. The target comes from Italy. We identify this attack with following hash code: 2369a7e333be5007e58625602625fe223858798ae6aa8403ec192b1f16aa3e26 (ID: 34791)Target victim website: www.elettricasystem.it
by RansomFeed - https://r.zerozone.it/post/FDwNXNVaQpt5r0Sj2
r.zerozone.it
TeleBotr
TeleBotr - Telegram publishing platform
Solheim — your own EU-hosted LLM instance, no reset timer
https://solheim.ai/?rdt_cid=5937873623955315411
https://solheim.ai/?rdt_cid=5937873623955315411
solheim.ai
Solheim — your own EU-hosted LLM instance, no reset timer
A virtual private LLM: one project, one VPL, sized by how many requests run at once. Flat monthly fee, no usage window, no reset timer, EU-hosted.
Vado OT. Per chi ha i figli in età scolare e deve impazzire con i libri di testo....
https://libri.italiainnumeri.it/
https://libri.italiainnumeri.it/
libri.italiainnumeri.it
Libri di Testo — i libri adottati dalla tua scuola, a.s. 2026/27
Cerca la tua scuola e la tua classe e ottieni l'elenco ufficiale dei libri di testo adottati, con ISBN, prezzo di copertina e link per comprarli online.
Retelit, operatore cloud e di telecomunicazioni, ha subito un attacco informatico. E non lo dice - IrpiMedia
https://irpimedia.irpi.eu/retelit-operatore-cloud-e-telecomunicazioni-attacco-informatico/
https://irpimedia.irpi.eu/retelit-operatore-cloud-e-telecomunicazioni-attacco-informatico/
IrpiMedia
Retelit, operatore cloud e di telecomunicazioni, ha subito un attacco informatico. E non lo dice
Tra i suoi clienti ci sono aziende strategiche, gestori di identità digitali e pubbliche amministrazioni. Migliaia i documenti già disponibili online. Dietro l’attacco Qilin, gruppo cybercriminale attivo almeno dal 2022 che ruba password e accessi