Insights & Research
Analysis, insights and updates on post-quantum security, NIS2 compliance and critical infrastructure protection.
19 Million French Identities for Sale: When the Agency Issuing Your Documents Loses Your Data
On April 15, 2026, France Titres — the French government agency managing passports, ID cards, and driving licenses, formerly ANTS — detected an intrusion on the ants.gouv.fr portal. The next day a listing appeared on criminal forums: an actor known as "breach3d" (alias "ExtaseHunters", "EvilDump") was selling 18-19 million records containing names, emails, dates of birth, postal addresses, places of birth, and account identifiers. One third of the French population. The government confirmed on April 21, notifying CNIL, ANSSI, and the Paris Public Prosecutor. The identity document itself was not stolen — but what was stolen is exactly the starter kit for a national-scale identity phishing campaign. For Italian professionals handling sensitive dossiers, the case carries three immediate operational lessons.
Chat Control 2026: What Really Changes for Italian Lawyers, Journalists and Executives When Europe Discusses Your Encryption
On March 26, 2026 the European Parliament rejected Chat Control 1.0 by one vote. On April 3 the temporary derogation allowing big tech to voluntarily scan their users' messages expired. On May 4 the trilogue on Chat Control 2.0 resumes, with the goal of an agreement by July. Italy is officially among the four countries opposing the text. Mandatory client-side scanning has been removed from the Council's proposal. It sounds like good news. For those who live on confidential correspondence — a lawyer writing to a client, a journalist receiving from a source, an executive negotiating a deal — the details remaining on the table are however crucial. This article is an operational map: what was defeated, what was transformed, what remains in play, and what concretely changes for your workday in the next six months.
Iran, April 22 2026: what to expect on the cyber front as the ceasefire expires
AEGIDA Geo Briefing on the eve of the US-Iran ceasefire expiration. English translation pending — Italian version is the source of record.
FrostArmada: The APT28 DNS Hijacking Campaign That Hit 18,000 Devices Across 120 Countries
AEGIDA Threat Briefing on the FrostArmada campaign conducted by APT28 (GRU unit 26165). Between May 2025 and April 2026, the group compromised MikroTik, TP-Link, Nethesis, and Fortinet routers across 120 countries, hijacking DNS via DHCP to intercept Microsoft 365 credentials and OAuth tokens through AitM proxies. On April 7, 2026, a joint operation by the FBI, DOJ, Polish government, Microsoft, and Lumen dismantled the infrastructure.
36 Malicious npm Packages Disguised as Strapi Plugins: Red Team Reconstruction of the Guardarian Supply Chain Attack
Thirty-six npm packages published in thirteen hours from four fake accounts. Eight malware variants in rapid evolution. A single target: the Guardarian crypto platform. This is not a standard threat analysis. It is a reconstruction of the operation from the attacker's point of view, phase by phase, from the workbench of someone who builds supply chain attacks. With defensive guidance at every turn.
Bitcoin Depot, the $3.665M Heist: How a Single Credential Set Drained the Settlement Accounts of the Largest US Bitcoin ATM Operator
On March 23, 2026, Bitcoin Depot's security team — the NASDAQ-listed operator of more than 8,500 Bitcoin ATMs in the United States — detected suspicious activity on corporate IT systems. Forensic analysis reconstructed what had already happened: three days earlier, on March 20, an attacker in possession of valid credentials for digital asset settlement accounts had begun transferring bitcoin out of corporate wallets. Final loot: 50.903 BTC, approximately $3.665 million at the time of transfer, laundered through exchanges including KuCoin before internal response could stop them. The company states customer wallets and ATMs were not affected: the impacted perimeter is the operational treasury. It is a textbook case of hot wallet architecture with single credential point of failure — and a brutal reminder that "separation" between user infrastructure and corporate treasury does not compensate for a 72-hour detection gap.
The Conference, the Phantom Token, the Blind Signature: Forensic Reconstruction of the $285 Million Drift Protocol Heist
April 1, 2026, 16:05:18 UTC, on the Solana blockchain: a transaction pre-signed weeks earlier executes. One second later, at 16:05:19 UTC, a second transaction transfers administrative privileges of the Drift DeFi protocol to a wallet controlled by North Korean attackers. In the following two hours and twenty-six minutes, 18 types of tokens worth $285 million flow out of Drift vaults. Execution window: 12 minutes. Preparation: six months. This is the minute-by-minute reconstruction of how a group tied to UNC4736 — the DPRK cluster already attributed to the 2024 Radiant Capital hack — turned a crypto conference, a phantom token, and a little-known Solana feature into what is, to date, the largest DeFi hack of 2026.
Rockstar, GTA, and 78.6 Million Records: When "Pay or Leak" Hits 23:59 and the Vendor Says No
On April 11, 2026 ShinyHunters posted an ultimatum on their leak site: "Rockstar Games, your Snowflake instances were compromised thanks to Anodot.com. Pay or leak by April 14." April 14 came. Rockstar did not pay. ShinyHunters released 78.6 million internal analytics records from GTA Online and Red Dead Online. But the detail that should interest you more than GTA is another: the attackers did not breach Snowflake, did not breach Anodot in the classic sense. They extracted authentication tokens functioning as trusted credentials between the two services, and walked into Snowflake as legitimate users. No exploit. No zero-day. Just badly managed SaaS-to-SaaS identity.
Strait of Hormuz, April 2026: 1,100 Ships in the Electronic Fog — When Kinetic Blockade Meets PNT Warfare
As US Central Command launched a maritime blockade of Iranian ports on April 13, 2026 and commercial transits through the Strait of Hormuz collapsed from 130-150 to single digits per day, a second front — less visible but equally decisive — opened in the electromagnetic spectrum: the Joint Maritime Information Center recorded over 600 GNSS disruption events in 24 hours, with more than 1,100 ships hit by GPS jamming and AIS spoofing across the Persian Gulf, the Gulf of Oman, and the Strait itself. This is not collateral damage: it is warfare against the Positioning, Navigation and Timing system that underpins all global commercial shipping.
Adobe, 13 Million Tickets Exfiltrated: The "Mr. Raccoon" Breach and the Lesson Nobody Wants to Learn About Support Supply Chain
An actor using the handle "Mr. Raccoon" claims the theft of 13 million Adobe support tickets, 15,000 employee records, the entire HackerOne bug bounty archive, and internal documents. Adobe has not yet officially confirmed. But the real story is not the volume: it is the vector. The attacker did not breach Adobe — they breached an Indian BPO employee handling Adobe customer support, using infostealer + lateral phishing to the manager, and then exploited a stunning configuration flaw: a single agent account could export 13 million tickets in a single request. No alert. No limit. No approval.
After Khamenei: Iranian Cyber Escalation in the Gulf and the Shock Waves on Europe and Italy
Following the killing of Supreme Leader Ali Khamenei on February 28, 2026 and the fragile ceasefire after Iranian counterstrikes, Tehran-linked cyber operations have exploded across the Gulf: the UAE reports 600,000 attacks, three times the prior period, with a qualitative leap from disruption to complex intrusions against banks, civil aviation and law enforcement. Despite the ceasefire, Iran-aligned groups have vowed to continue — and their trajectory points at NATO allies and European infrastructure too. What this means for Italy.
CVE-2026-35616: FortiClient EMS Under Active Exploitation — The Pre-Auth Bypass Turning Endpoint Management Into an Intrusion Vector
Fortinet has released an out-of-band patch for CVE-2026-35616, a pre-authentication API access bypass (CVSS 9.1) in FortiClient EMS, Fortinet's central endpoint management platform. Unauthenticated attackers can execute arbitrary code or commands via crafted requests. First exploitation attempts were recorded on March 31, 2026 — before public disclosure. When the control plane of endpoints is compromised, the perimeter posture ceases to matter.
Smart Slider 3 Pro Compromised: Six Hours of Malicious Updates That Turned Thousands of WordPress Sites into Persistent Backdoors
On April 7, 2026, Nextend's update servers were compromised and for about six hours distributed a malicious version of the popular Smart Slider 3 Pro plugin. Every WordPress or Joomla site that updated during that window received a complete Remote Access Toolkit: unauthenticated backdoors, hidden admin accounts, must-use plugins disguised as cache components, automated credential exfiltration. A brutal lesson on WordPress plugin supply chain risk.
CVE-2026-39987: Marimo Exploited in 9 Hours and 41 Minutes — When Public Disclosure Becomes the Starting Gun for a Global Exploit Race
A pre-authentication remote code execution (RCE) vulnerability in Marimo, the Python data science notebook, was exploited in real systems exactly 9 hours and 41 minutes after public disclosure. CVE-2026-39987 (CVSS 9.3) allowed anyone to obtain a complete PTY shell via a WebSocket endpoint lacking authentication. The case sets a new weaponization speed record and raises an urgent question: how much time do we actually have after a disclosure?
Operation PRISMEX: APT28 Strikes Ukraine and NATO Allies with Steganography, Zero-Days and Logistics Sabotage
Russian group APT28 (Forest Blizzard/Fancy Bear) launched an espionage and pre-sabotage campaign against Ukraine, Poland, Romania, Slovakia and Czech Republic. Exploiting zero-day CVE-2026-21509 and the new PRISMEX malware suite — with steganography, COM hijacking and cloud C2 — the Kremlin maps military logistics, transport corridors and weather networks to prepare destructive attacks against Western support to Kyiv.
The Equalize Case: Anatomy of the Largest Government Database Theft in Italian History — 800,000 Victims, 52,811 Unauthorized SDI Accesses, and What NIS2 Would Have Changed
On April 9, 2026, the Milan Prosecutor's Office closed the second strand of the Equalize investigation, with 81 new suspects including Leonardo Maria Del Vecchio. For over five years, a Milan-based business intelligence firm pillaged SDI, Serpico, ANPR, and Bank of Italy databases, profiling 800,000 Italians — politicians, entrepreneurs, athletes, even the Prime Minister. All orchestrated from a room behind Milan's Cathedral. Complete technical analysis: how they got in, what they stole, and why NIS2 — properly applied — could have stopped them.
Iran Inside American PLCs: The IRGC Has Already Caused Real Damage to US Water and Energy Facilities
Joint advisory CISA AA26-097A of April 7, 2026, signed by FBI, NSA, EPA, DOE and Cyber Command, confirms that Iran-affiliated hackers have compromised Rockwell Automation PLCs in American critical infrastructure — water, energy, government services. This is no longer theoretical: there has been real operational disruption and financial loss.
GTIG Report 2026: 90 Zero-Days Exploited in 2025 — Enterprise Is the New Battlefield
Google Threat Intelligence Group reveals 90 zero-days were exploited in-the-wild in 2025 — and for the first time, nearly half (48%) targeted enterprise technology: firewalls, VPNs, routers, and security software. Commercial surveillance vendors surpass state groups in zero-day usage. China doubles its zero-days.
The Stryker Case: How Iran Turned Microsoft Intune Into a Weapon and Wiped 200,000 Devices Across 79 Countries
On March 11, 2026, Iranian group Handala (MOIS/Void Manticore) struck Stryker Corporation — a $25 billion medtech giant, Fortune 300, 56,000 employees — with the most devastating wiper attack ever conducted against an American company. The weapon? Microsoft Intune, the company's own device management platform, turned into a tool of mass destruction.
Salt Typhoon in Europe: China Is Already Inside the Continent's Telecom Networks
Norway confirms: Salt Typhoon compromised network devices in Norwegian organizations. The FBI counts 200+ breached companies across 80+ countries. European telecoms — from lawful intercept systems to millions of citizens' data — are in the crosshairs of China's Ministry of State Security.
Storm-1175: The Chinese Group Deploying Medusa Ransomware via Zero-Days in Under 24 Hours
Microsoft reveals that Storm-1175, a financially motivated Chinese actor, is exploiting zero-days in SmarterMail and GoAnywhere MFT to deploy Medusa ransomware at unprecedented speed — in some cases from initial compromise to ransomware in under 24 hours. Over 300 organizations hit across healthcare, education, and finance.
Medusa: The Ransomware Exploiting Zero-Days and Striking in 24 Hours — From Hospitals to the Uffizi
Microsoft reveals the Medusa group exploits zero-day vulnerabilities days before public disclosure, completing the entire attack chain — from initial access to ransomware deployment — in just 24 hours. Recent victims include hospitals, universities, and cultural institutions.
Two Zero-Days in One Week: BlueHammer Exposes Every Windows PC, Fortinet CVE-2026-35616 Hits Governments
A frustrated researcher publishes the BlueHammer exploit on GitHub: an unpatched Windows flaw enabling SYSTEM escalation. Simultaneously, CVE-2026-35616 (9.1/10) in FortiClient EMS is actively exploited against government entities worldwide. CISA orders patching by Thursday.
Iran: Missiles on Cities, Password Spraying on Municipalities — How Tehran Synchronizes Kinetic and Cyber Warfare
Check Point reveals a three-wave Iranian campaign hitting 300+ Israeli organizations and 25+ in the UAE. The most disturbing finding: cities targeted by password spraying match those hit by Iranian missiles. Iran no longer separates kinetic from cyber warfare — it synchronizes them.
Operation TrueChaos: How China Turned a Video Conferencing Platform into a Mass Espionage Weapon
Chinese hackers exploited a zero-day vulnerability in TrueConf's update mechanism — a platform used by 100,000 organizations including governments, military, and critical infrastructure — to distribute malware through the trusted update channel. A single compromised server infected dozens of government entities simultaneously. CISA ordered patching within 14 days.
BrowserGate: LinkedIn Secretly Scans 6,236 Browser Extensions and Maps Your Company
An independent investigation reveals LinkedIn uses hidden JavaScript to scan every visitor's Chrome extensions, collect device hardware data, and map which companies use which competitor products. All without explicit consent. Yet another demonstration that corporate surveillance is the web's business model.
Ransomware Attack on the Uffizi Gallery: Italian Cultural Heritage in the Crosshairs of Cybercrime
On the night of February 1-2, 2026, the Medusa ransomware group struck the administrative systems of Florence's Uffizi Gallery. Incident analysis, implications for Italian cultural institutions, and operational recommendations.
Black Week: EU Commission Hacked, Romania Under Siege, Russian Hackers Return to Old Targets
In just seven days, Europe suffered three cyber events of strategic magnitude: the compromise of the European Commission cloud exposing data from 30 EU entities, 10,000 daily attacks against Romania, and CERT-UA's warning about Russian hackers returning to previously breached networks. Analysis of a week that redefines the threat level for the continent.
Sandworm and the European Power Grid: Anatomy of a Hybrid Campaign Italy Cannot Ignore
Dutch intelligence, the Munich Security Report, and new EU sanctions converge on an alarming picture: Russia is conducting coordinated cyber-kinetic operations against European energy infrastructure. An analysis of the APT44/Sandworm group, its evolved TTPs, and the implications for the Italian energy sector.
Operation Epic Fury: Iran's Cyber Proxy War and the Risk to Europe
How the US-Israel-Iran military conflict triggered the most extensive cyber proxy offensive in recent history — and why European infrastructures are in the crosshairs of a network pre-positioned for years. Analysis of TTPs, attack chains, and strategic implications.
Perfect Storm: Zero-Days and Supply Chain Under Attack — Threat Report April 2026
April 2026 opens with a convergence of critical threats: Cisco FMC zero-day CVE-2026-20131 (CVSS 10.0), supply chain attacks on npm and PyPI, and AI-accelerated intrusions with 29-minute breakout times. Full analysis and operational recommendations.
NIS2: deadlines, obligations and penalties for European organizations
The NIS2 directive introduces stringent obligations for essential and important entities. Here is what you need to know to ensure compliance.
Store-Now-Decrypt-Later: why your communications today are already at risk
Quantum computers are not yet operational, but the threat is already real. How the "store-now-decrypt-later" attack works and how to protect yourself with post-quantum cryptography.
Supply chain attacks: the preferred vector for APT groups in 2025-2026
From SolarWinds to XZ Utils: why supply chain attacks have become the number one threat to critical infrastructure and how to defend against them.
Anatomy of the SolarWinds SUNBURST attack: the supply chain as a strategic weapon
In-depth technical analysis of the SUNBURST attack that in 2020 compromised 18,000 organizations through a legitimate software update. Timeline, evasion mechanisms, impact, and lessons for post-quantum security.
Colonial Pipeline: anatomy of the largest ransomware attack on US critical infrastructure
In-depth analysis of the DarkSide ransomware attack on Colonial Pipeline (May 2021): from a compromised VPN password to the shutdown of 5,500 miles of pipeline. Lessons learned and how a zero-trust approach would have prevented the disaster.