The heart of WordPress, run by someone who never logged in: the WP2Shell chain
WordPress runs a huge share of the public web. Two flaws in its core — a SQL injection in WP_Query (CVE-2026-60137) and a REST API batch-route confusi…
Topic · Institutions
Who defends Italy in cyberspace, with what powers, and within which European framework.
criticalFeatured dossierThe heart of WordPress, run by someone who never logged in: the WP2Shell chainRead the dossier →
WordPress runs a huge share of the public web. Two flaws in its core — a SQL injection in WP_Query (CVE-2026-60137) and a REST API batch-route confusi…
Not an attack, but the perimeter within which attacks are managed. The NIS2 directive was transposed in Italy by Legislative Decree 138/2024, in force…
APT28 turned thousands of home routers into a wiretapping network aimed at foreign ministries and law enforcement, hijacking DNS to steal already-auth…
For five years Volt Typhoon hid inside US critical infrastructure and touched nothing. In 2026 Dragos catches it manipulating engineering workstations…
Italy's cybersecurity has a defined architecture. The National Cybersecurity Agency (ACN) is the national authority for cybersecurity: it coordinates strategy, the resilience of essential services, and relations across the public and private ecosystem. Within it operates CSIRT Italia, the national computer security incident response team, which receives reports, issues alerts and bulletins, and supports incident handling.
The national level plugs into the Union's. The NIS2 Directive (Directive EU 2022/2555) raised the common European bar: it widens scope to eighteen critical sectors, mandates risk-management measures and reporting of significant incidents, and introduces direct accountability of top management. Member States had to transpose it by 17 October 2024. Each State also adopts a national cybersecurity strategy.
NIS2's logic cascades: the obligations of essential operators flow down their supply chain. A company not directly regulated may still have to demonstrate security measures because it supplies one that is. Knowing the institutional perimeter isn't a formality: it defines who to contact during an incident and which obligations apply.