Cybersecurity

"Prevention is cheaper than a breach"

4
Set

ASCII Smuggling: From AI Prompt Injection to Phishing Evasion

Microsoft researchers have identified a significant phishing campaign that repurposes ‘ASCII smuggling’—a technique originally popularized in AI prompt injection research—to bypass email security filters. Instead of hiding malicious instructions from humans to target AI models, attackers are using invisible Unicode tag characters (U+E0000 to U+E007F) to fracture high-signal keywords like…
30
Ago

TerminalFix Campaign: A Dangerous New Multi-Stage Attack Chain

Microsoft Threat Intelligence has identified a sophisticated new threat campaign dubbed ‘TerminalFix.’ This evolution of the ‘ClickFix’ social engineering technique targets organizations by leveraging compromised websites to display fake Cloudflare CAPTCHA verifications. Instead of directing users to the Windows Run dialog, TerminalFix tricks victims into pasting malicious PowerShell commands into…
23
Ago

Partecipa alla consultazione pubblica sulla certificazione dei servizi di sicurezza gestiti (EUMSS)

L’ENISA ha ufficialmente lanciato una consultazione pubblica sulla bozza dello schema di certificazione europea per i servizi di sicurezza gestiti (EUMSS). Questa iniziativa rappresenta un traguardo fondamentale, nato in seguito alla richiesta formale avanzata dalla Commissione Europea nell’aprile 2025, volta a definire un quadro di riferimento solido ai sensi del…
Scroll to top