nicfab
119 subscribers
15 photos
16 files
2.58K links
Canale di aggiornamento su Privacy, Data Protection, IA e Cybersecurity
Channel for updates on Privacy, Data Protection, AI, and Cybersecurity
Download Telegram
Daily Digest | 11 August 2026

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/

A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
TechCrunch
https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
The Hacker News
https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
SecurityWeek RSS Feed
https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
The Hacker News
https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html

#Privacy #AI #Cybersecurity #DailyDigest
📧 NicFab Newsletter #33 — 11 August 2026

The Italian Garante reprimands R.T.I. over AI-manipulated deepfakes of Enrico Mentana: satire is no free pass, and a disclaimer counts only if the average viewer perceives it.

The EDPB asks the Commission to reassess the Data Privacy Framework after Trump v. Slaughter.

Also in this issue: the Ninth Circuit on AI agents and the CFAA, the EES switched off when queues grow, the SAFE guidelines on agentic incident reporting, and AI Act in a Nutshell on Article 37.

👉 https://www.nicfab.eu/en/newsletter-issues/2026-08-11-issue-33/
📧 NicFab Newsletter #33 — 11 agosto 2026

Il Garante ammonisce R.T.I. per i deepfake di Enrico Mentana generati con l'IA: la satira non è un lasciapassare, e il disclaimer conta solo se il telespettatore medio lo percepisce.

L'EDPB chiede alla Commissione di riesaminare il Data Privacy Framework dopo Trump v. Slaughter.

Nel numero anche: il Nono Circuito su agenti AI e CFAA, il sistema EES spento quando le code crescono, le linee guida SAFE sugli incidenti dei sistemi agentici, e l'AI Act in Pillole sull'articolo 37.

👉 https://www.nicfab.eu/it/newsletter-issues/2026-08-11-issue-33/
Daily Digest | 12 August 2026

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
The Hacker News
https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/

US and South Korea warn of Gunra ransomware targeting govt agencies
BleepingComputer
https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
The Hacker News
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html

Zoom Patches Zero-Click Code Execution Vulnerability
SecurityWeek RSS Feed
https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 13 August 2026

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition

Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer
https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa

SharePoint Vulnerability Exploited Shortly After PoC Release
SecurityWeek RSS Feed
https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
The Hacker News
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 14 August 2026

Privacy watchdog warns of ‘serious risks’ over EU police agency surveillance
POLITICO
https://www.politico.eu/article/europol-data-processing-reform-privacy-risks-edps-warning/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

Hackers breach govt webmail while running parallel crypto fraud
BleepingComputer
https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/

Trezor discloses data breach affecting nearly 14,000 customers
BleepingComputer
https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The Hacker News
https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
SecurityWeek RSS Feed
https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 17 August 2026

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
Dark Reading
https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office

Hackers arrested over €30M bank fraud exploiting service provider flaw
BleepingComputer
https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/

RingCentral data breach exposed info of 1.6 million accounts
BleepingComputer
https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/

Hackers Exploiting Unpatched GeoServer Zero-Day
SecurityWeek RSS Feed
https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
SecurityWeek RSS Feed
https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/

#Privacy #AI #Cybersecurity #DailyDigest
📬 NicFab Newsletter #34 | 18 agosto 2026

Privacy, Data Protection, AI e Cybersecurity — la rassegna settimanale.

In questo numero:

🏛️ D-TECT: la Commissione europea apre il forum industriale su droni e contro-droni, tra sovranità tecnologica e minacce ibride

🟢 La CNIL pubblica una guida operativa su DPO e conflitti di interesse: le funzioni incompatibili e il caso DPO-RSSI

📊 Australia, le restrizioni social per i minori fanno scuola, ma eSafety rileva che i divieti restano largamente inefficaci

🔍 Apple Intelligence in Cina con Alibaba e registrazione presso la CAC, mentre nell'UE resta aperto lo scontro sul DMA

🏛️ New Jersey: firmato l'Age-Appropriate Design Code, con la soglia di processing più bassa fra i design code USA

⚠️ Prompt injection nascosto in un atto giudiziario, Ghostjacking via log di sicurezza e il problema strutturale della delega vaga agli agenti IA

🔴 Operation Klonen: 30 milioni sottratti a Commerzbank sfruttando un fornitore, RingCentral con 1,6 milioni di account esposti e CVE-2026-65400 su macOS sfruttata attivamente

📖 AI Act in Pillole – Parte 34: l'articolo 38 e il coordinamento degli organismi notificati

👉 Leggi il numero completo: https://www.nicfab.eu/it/newsletter-issues/2026-08-18-issue-34/?utm_campaign=telegram-issue-34

📩 Iscriviti alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora

#Privacy #GDPR #AIAct #Cybersecurity
📬 NicFab Newsletter #34 | August 18, 2026

Privacy, Data Protection, AI & Cybersecurity — weekly review.

In this issue:

🏛️ The European Commission launches D-TECT, the EU industrial forum on drone and counter-drone technology: expressions of interest open, inaugural meeting on 11 November 2026

🟢 CNIL publishes operational guidance on DPO conflicts of interest: senior management and HR roles incompatible as a rule, and the DPO-CISO combination put under scrutiny

📊 Australia's under-16 social media ban becomes an exported regulatory model, but eSafety finds most 10-15 year-olds still online due to inadequate age verification

📈 Apple Intelligence registered by China's CAC with an Alibaba-built model, while the DMA standoff in Europe delays Siri AI — same company, two very different strategies

⚠️ Prompt injection hidden in a court filing, Ghostjacking via security logs, and OpenAI's GPT-5.6-Cyber lowering safeguards on exploit development: agentic AI risks are becoming concrete

🔴 Operation Klonen siphons €30 million from Commerzbank through a supplier, while ShinyHunters expose 1.6 million RingCentral accounts and SafePal data goes up for sale

🔍 Coordinated attacks on U.S. water utilities with Iranian attribution suspicions, and a Polish combined heat and power plant breached through a private APN

📖 AI Act Explained – Part 34: Article 38 and the coordination of notified bodies, the sectoral group, and the exchange of knowledge between notifying authorities

👉 Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-08-18-issue-34/?utm_campaign=telegram-issue-34

📩 Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
Daily Digest | 18 August 2026

680,000 Impacted by French Tax Authority Data Breach
SecurityWeek RSS Feed
https://www.securityweek.com/680000-impacted-by-french-tax-authority-data-breach/

Philips and GE investigating Clop ransomware data theft claims
BleepingComputer
https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/

Microsoft working on Defender patch for ShieldBreak zero-day
BleepingComputer
https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
SecurityWeek RSS Feed
https://www.securityweek.com/critical-sap-commerce-cloud-vulnerability-exploited-3-days-after-disclosure/

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
The Hacker News
https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 19 August 2026

Statement by the High Representative on behalf of the EU on the alignment of certain countries concerning restrictiv...
Council of the EU Press Releases
https://www.consilium.europa.eu/en/press/press-releases/2026/08/18/statement-by-the-high-representative-on-behalf-of-the-eu-on-the-alignment-of-certain-countries-concerning-restrictive-measures-against-serious-human-rights-violations-and-abuses/

French tax authority data breach affects 678,000 individuals
BleepingComputer
https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/

CISA: Windows Task Host flaw now exploited by ransomware gangs
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
SecurityWeek RSS Feed
https://www.securityweek.com/heights-finance-data-breach-impacts-at-least-1-2-million-individuals/

France probes disinfo campaigns targeting 2027 election candidates
POLITICO
https://www.politico.eu/article/france-probe-russia-disinformation-campaigns-2027-election/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 20 August 2026

OpenAI confirms ChatGPT is down as logins and signups fail
BleepingComputer
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-as-logins-and-signups-fail/

OpenAI seeks to one-up Anthropic with new customer privacy protections
TechCrunch
https://techcrunch.com/2026/08/19/openai-seeks-to-one-up-anthropic-with-new-customer-privacy-protections/

Rogue ransomware affiliate poses as data recovery firm to steal payments
BleepingComputer
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/

Rogue ransomware affiliate poses as recovery firm to steal payments
BleepingComputer
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/

Healthtech firm CareCloud data breach impacts 3.7 million patients
BleepingComputer
https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 21 August 2026

CISA: Medusa ransomware hit over 500 critical infrastructure orgs
BleepingComputer
https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Hacker News
https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
SecurityWeek RSS Feed
https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/

MLflow Vulnerability Exploited for Cloud Credential Theft
SecurityWeek RSS Feed
https://www.securityweek.com/mlflow-vulnerability-exploited-for-cloud-credential-theft/

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The Hacker News
https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html

#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 24 August 2026

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The Hacker News
https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html

Microsoft Patches Exploited Entra ID Vulnerability
SecurityWeek RSS Feed
https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/

Brussels changes gear on Big Tech enforcement
Politico EU Technology
https://www.politico.eu/article/brussels-changes-gear-on-big-tech-enforcement-as-first-wave-of-cases-wraps-up/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication

SickKids data breach exposes employee and job applicant info
BleepingComputer
https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
SecurityWeek RSS Feed
https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/

#Privacy #AI #Cybersecurity #DailyDigest
📬 NicFab Newsletter #35 | 25 agosto 2026

Privacy, Data Protection, AI e Cybersecurity — la rassegna settimanale.

In questo numero:

🏛️ La Commissione europea mette a gara uno studio empirico da 400.000 euro sul design dei marketplace e sull'effettività dei meccanismi DSA (artt. 16, 30.7 e 31)

📖 Parere EDPS 17/2026 sulla revisione del Regolamento 2018/1725 trasmesso alle delegazioni del Consiglio, con riunione del Working Party on Data Protection il 4 settembre

🟢 La CNIL pubblica una guida per i cittadini sul rifiuto del credito: scoring, FICP, trasparenza degli algoritmi e diritto a conoscere le ragioni del diniego

🔴 DMA: 890 milioni di euro a Google per self-preferencing su Search e restrizioni allo steering su Play, mentre Bruxelles cambia marcia sull'enforcement Big Tech

📈 Apple e Commissione trovano l'intesa sui termini App Store UE: commissione IAP dal 30 al 26 percento dal 1° ottobre 2026

⚠️ Grok esfiltra dati utente tramite istruzioni cifrate, "mind virus" tra agenti AI via file di prompt persistenti e Copilot rivela da sé il parametro segreto per attaccarlo

🔍 Cybersecurity: GitLab CVE-2026-19478 sfruttata in poche ore, Zimbra RCE non autenticato già in KEV e 14 pacchetti npm trojanizzati distribuiscono RedC2 4.0

📊 TikTok paga 400 milioni per violazioni COPPA, la FTC prepara limiti al surveillance pricing e Aylo chiude con 120 milioni le class action su CSAM

📖 AI Act in Pillole - Parte 35: l'articolo 39 e gli organismi di valutazione della conformità di paesi terzi

👉 Leggi il numero completo: https://www.nicfab.eu/it/newsletter-issues/2026-08-25-issue-35/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-35

📩 Iscriviti alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora

#Privacy #GDPR #AIAct #Cybersecurity
📬 NicFab Newsletter #35 | August 25, 2026

Privacy, Data Protection, AI & Cybersecurity — weekly review.

In this issue:

🏛️ The European Commission tenders a EUR 400,000 empirical study on how marketplace design shapes user behaviour under DSA Articles 16, 30(7) and 31

📖 EDPS Opinion 17/2026 on the revision of Regulation 2018/1725 sent to Council delegations, ahead of the Working Party meeting on 4 September

🟢 CNIL publishes a citizens' guide on credit refusals: no "right to credit", but transparency, bias mitigation and explainability duties apply to AI scoring models

🔴 Brussels changes gear on Big Tech: EUR 890 million in DMA fines against Google for self-preferencing and Play Store restrictions, bringing total DMA penalties to EUR 1.6 billion

📈 Apple reshapes App Store terms for EU developers from 1 October 2026: commission down to 26%, Core Technology Fee replaced by a 5% Core Technology Commission

⚠️ Cybersecurity week: GitLab CVE-2026-19478 exploited within hours, unauthenticated RCE in Zimbra already in KEV, and 14 trojanized npm packages delivering RedC2 4.0

🔍 AI security under pressure: Grok exfiltrating user data via encrypted instructions, Copilot disclosing the secret parameter used to attack it, and OpenAI pausing frontier RL training

📊 TikTok pays USD 400 million for COPPA violations while the FTC prepares limits on surveillance pricing

👉 Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-08-25-issue-35/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-35

📩 Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity