How Secure Is the Italian Web? First Results from the IWSS Study on 10,020 .it Domains
IWSS, F-Hack's research across 10,022 .it domains: no security header exceeds 42% adoption, fewer than 1% of CSPs are actually restrictive, only 2.4% ...
The Italian blog on cybersecurity
Articles, guides and tutorials on cybersecurity, ethical hacking, penetration testing and web app security.
IWSS, F-Hack's research across 10,022 .it domains: no security header exceeds 42% adoption, fewer than 1% of CSPs are actually restrictive, only 2.4% ...
An infostealer on a Context.ai employee's PC triggered a chain of compromises that reached Vercel's internal systems. Here's how it happened, what was...
CSRF remains in the OWASP Top 10 and hits applications that look secure. How it really works, with exploit examples and concrete countermeasures to im...
Decrypting isn't magic: you need the right key, the correct IV or nonce, and to know which mode was used to encrypt. Here's how it works with AES and ...
What a backdoor is, how it differs from viruses and trojans, how it gets installed on a system, and the signs that help you spot one in time.
AES encrypts fast with a shared key. RSA solves the distribution problem with two keys. SHA-256 doesn't decrypt anything. Three different tools for th...
A specially crafted animated sticker file can execute remote code on Telegram for Android and Linux with no user interaction at all. ZDI-CAN-30207, CV...
Meta has announced the permanent removal of end-to-end encryption from Instagram DMs, with shutdown planned after May 8, 2026. A decision that reopens...
A bot requesting dozens of password resets per minute on a WordPress site, with a different user-agent on every request. Here's how to spot it in ngin...
Using **Nmap on Linux** to analyze networks and improve information security. In this guide you'll learn how to install Nmap, run basic and advanced s...
Follow us on social media so you don't miss the latest articles, news and cybersecurity tutorials.