Threats Affecting Italy
View all threats affecting or targeting Italy. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Italy
Click on any threat for detailed analysis and mitigation recommendations
TA4922: The Suspected Chinese Crime Group is Going Global 0 TA4922 is a highly sophisticated Chinese-speaking threat actor demonstrating rapid operational tempo and continually evolving malware capabilities. Initially targeting East Asia, particularly Japan, the group has expanded globally to Europe and Africa. The actor deploys multiple malware families including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0), alongside legitimate remote management tools like AnyDesk and SyncFuture. Campaigns use localized lures themed around HR, payroll, tax, and invoicing, targeting hundreds to thousands of recipients per campaign. TA4922 conducts credential phishing, fraud operations including credit card theft, and attempts to shift communications to out-of-band channels like LINE, WhatsApp, and Microsoft Teams. The group leverages legitimate cloud hosting services and trusted software for delivery and persistence, combining advanced tradecraft with financially motivated objectives such as data theft, fraud, access resale, and persistent remote access. Join the discussion | AlienVault OTX General | 06/03/2026, 12:55:39 UTC Added: 06/04/2026, 08:33:36 UTC |
Chinese hackers use new Atlas RAT malware in European cyberattacks 0 A Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor. [...] Join the discussion | Bleeping Computer | 06/03/2026, 21:45:27 UTC Added: 06/03/2026, 21:48:37 UTC |
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content 0 A malware-as-a-service campaign named Weedhack targets Minecraft users by distributing malicious Java JAR files via SEO poisoning and YouTube videos. The malware steals credentials, system information, and can remotely control infected systems. It is notable for its ease of access, free tier, and appeal to younger users, with infections primarily in the U. S. and several other countries. Additionally, a large CountLoader campaign spreads cryptocurrency clipper malware via cracked software, and a separate campaign distributes cryptocurrency miners through pirated content sites. These campaigns leverage sophisticated persistence and evasion techniques and have been active since early 2026. Join the discussion | Reddit Cybersecurity | 06/03/2026, 07:35:27 UTC Added: 06/03/2026, 07:48:26 UTC |
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps 0 A new variant of the TrickMo Android banking trojan was identified between January and February 2026, representing a substantial platform redesign rather than new capabilities. The malware has migrated its command-and-control infrastructure entirely onto The Open Network (TON) using .adnl endpoints, moving away from conventional internet infrastructure. Active campaigns have targeted banking and wallet users in France, Italy, and Austria. Once accessibility permissions are granted, operators gain real-time device control including credential phishing, keylogging, screen recording, SMS interception, and bidirectional remote control. New features include network reconnaissance capabilities and SSH tunnelling that transform infected devices into programmable network pivots and SOCKS5 proxy exit nodes, enabling operators to bypass IP-based fraud detection systems while accessing victim networks. Join the discussion | AlienVault OTX General | 05/11/2026, 09:07:43 UTC Added: 05/11/2026, 09:51:23 UTC |
Supply chain attack via DAEMON Tools | Kaspersky official blog 0 Kaspersky experts have detected a supply chain attack using the popular DAEMON Tools software. Join the discussion | Kaspersky Security Blog | 05/05/2026, 12:09:52 UTC Added: 05/05/2026, 12:23:38 UTC |
Risks, emerging when developing or using open-source software 0 How the popularization of AI and the simplification of development are creating new risks for corporate security. Join the discussion | Kaspersky Security Blog | 04/02/2026, 20:33:43 UTC Added: 04/02/2026, 23:17:50 UTC |
CVE-2024-44136: An attacker with physical access to a device may be able to disable Stolen Device Protection in Apple iOS and iPadOSCVE-2024-44136 0 This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection. Join the discussion | CVE Database V5 | 01/15/2025, 19:35:56 UTC Added: 04/02/2026, 18:40:42 UTC |
CVE-2024-40854: An app may be able to cause unexpected system termination in Apple iOS and iPadOSCVE-2024-40854 0 A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to cause unexpected system termination. Join the discussion | CVE Database V5 | 01/15/2025, 19:35:59 UTC Added: 04/02/2026, 18:40:42 UTC |
CVE-2024-40853: An attacker may be able to use Siri to enable Auto-Answer Calls in Apple iOS and iPadOSCVE-2024-40853 0 This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to use Siri to enable Auto-Answer Calls. Join the discussion | CVE Database V5 | 10/28/2024, 21:08:32 UTC Added: 04/02/2026, 18:40:42 UTC |
CVE-2026-25601: CWE-798: Use of Hard-coded Credentials in Metronik d.o.o. MEPIS RMCVE-2026-25601 0 A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords before storing them in the application’s database. An attacker with sufficient privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain unauthorized access to the associated ICS/OT environment. Join the discussion | CVE Database V5 | 04/01/2026, 11:28:57 UTC Added: 04/01/2026, 19:47:29 UTC |
Showing 1 to 10 of 24059 results