Vista elenco

Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam

13 Agosto 2026 ore 15:10

Security researchers have identified a phishing campaign that abuses Shopify’s own Shop app to deliver fake order and refund notifications directly to victims’ phones, marking a notable evolution of the classic “fake refund” scam.

According to research from cybersecurity firm Huntress, attackers are creating fraudulent Shopify seller accounts, or hijacking legitimate ones, to generate bogus orders against victims’ phone numbers or email addresses. Because Shopify’s Shop app treats these as genuine transactions, targets receive real push notifications and in-app receipts, rather than a suspicious email or text from an unfamiliar sender. Huntress said several of its own employees were targeted between May and August 2026, and that the technique has also been documented by researchers at Gen Digital and reported by users on Reddit.

In one example cited by Huntress, a fake receipt dated 7 August billed the recipient $339.96 for a “premium PC protection plan,” complete with a fabricated invoice number and transaction ID. The real sting sits in the shipping address field, which attackers repurpose to display a message urging the recipient to call a phone number if they did not place the order. Some variants dispense with the fake address altogether and instead push recipients toward the number via the order description, while others add a spoofed “out for delivery” shipment tracker to increase pressure on the target.

Victims who call the number are funnelled into a standard refund scam. Huntress said callers are typically talked into installing remote access tools such as ScreenConnect or AnyDesk, or into logging into their online banking. From there, scammers manipulate on-screen figures, sometimes editing displayed transaction details or coaching victims to misread a refund amount, to convince them they were mistakenly overpaid. Victims are then pressured to “return” the difference, usually by purchasing gift cards and handing over the redemption codes, which attackers cash out quickly.

Huntress frames the campaign as a variant of a technique it calls Living off Trusted Sites (LoTS), where attackers route victims through a legitimate, trusted platform before reaching a malicious outcome, rather than relying on a fake domain that is easier to flag. While earlier LoTS attacks used links to services such as Dropbox, Canva, or DocuSign to add credibility, this campaign instead abuses Shopify’s own notification pipeline to generate content that looks and functions exactly like a native alert. The firm noted a similar pattern in a previous campaign involving genuine PayPal invoices carrying fraudulent callback numbers.

Shopify has acknowledged the scam in its Help Center. The company and Huntress both advise users not to interact with unfamiliar phone numbers, email addresses, or links found within an order, and to contact Shop Support directly if they are concerned about the security of their account. Users who receive a suspicious order notification are advised to check their bank statements before assuming any charge went through, and can flag the order as “Not my order” within the Shop app. Huntress also recommends checking a store’s reviews and history before purchasing, noting that many of the fraudulent shopfronts used in this campaign were newly created.

The post Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam appeared first on IT Security Guru.

Is AI entering the SOC at the right stage?

13 Agosto 2026 ore 13:56

By Simon Phillips, CTO, CybaVerse

Alert fatigue is an issue that has plagued Security Operations Centres for years.

As organisations’ digital estates grow, there is more architecture to secure and more architecture for threat actors to attack, which has ultimately led to more alerts.

Today, on average a SOC will face thousands of alerts every day, each of which could indicate a potential threat. Each alert must therefore be analysed and investigated before appropriate action can be taken.

However, ask any SOC analyst and they will tell you the majority of these alerts are benign or false positives.

Yet, analysts will still spend hours investigating activity that ultimately poses little or no risk, hoping to identify the small number of genuine threats hidden amongst the noise.

Given the volume they face, and the possibility of missing something before it’s too late, it’s a noisy, high-stress environment that often leads to burnout and fatigue.

To tackle these issues, many SOCs today are turning to Artificial Intelligence (AI) to support the management of alerts.

In this scenario, the first-line analyst is replaced by an agent that reviews the incident to determine whether it’s malicious and if further action is required. The analyst must then review the conclusion reached by the agent to ensure it is accurate, but they don’t conduct the initial investigations themselves, which reduces the volume of alerts they have to investigate every day.

However, even despite these improvements, is there another way that could reduce the noise even further?

If organisations are still generating huge numbers of unnecessary alerts, have they actually solved the underlying problem, or simply moved it further downstream?

Moving AI upstream

Instead of asking AI to investigate incidents after they have been created, some organisations are using the technology much earlier in the detection process.

Rather than having AI decide whether an alert is malicious, in this scenario it’s used to help build better detection logic and more effective workflows before alerts ever reach an analyst.

For instance, in a phishing attack when an employee reports an email as suspicious, many security platforms immediately generate an incident that someone must investigate.

Traditionally, either a human analyst or an AI assistant would then collect additional context, checking whether links have been clicked, whether anyone else received the email, or whether similar activity appeared elsewhere in the environment.

If these types of checks are incorporated into the detection process, and the answers to the questions are no, then an incident would never need to be created in the first place.

The AI would determine that there was no wider threat, meaning the alert could be filtered out before it ended up in the SOC ticket queue.

The result is a faster, more efficient SOC, with far fewer unnecessary alerts reaching analysts.

From a customer perspective, this can also reduce the costs of working with an outsourced SOC partner.

Many AI-powered investigation platforms price their services according to the number of alerts they process, so reducing unnecessary alerts before they reach the investigation stage can improve efficiency while also helping organisations control operational costs.

Improving security through engineering

Another benefit of moving AI further upstream is that it limits access to sensitive customer data.

Many AI-driven investigation platforms analyse real customer logs and incident data to determine whether activity is malicious. While providers implement safeguards, some organisations are uncomfortable with sensitive operational data being processed by external AI systems, particularly where regulatory or contractual obligations apply.

Using AI during detection engineering changes this process. The AI is used to create the logic that identifies threats, not to inspect live customer data.

Once the detection rules have been verified, they can be applied consistently across customer environments without repeatedly sending operational data through AI models.

Solving the cause, not the symptom

The cyber security industry has become very good at handling alert fatigue, but not so good at preventing it. Is it time a different approach was adopted?

If security teams continue generating thousands of low-value alerts every day, replacing analysts with AI may improve efficiency, but it won’t address why the alerts exist in the first place.

As AI becomes more deeply embedded within security operations, organisations should consider where it delivers the greatest value. In many cases, the answer may not be at the point where analysts investigate incidents, but much earlier, where better detection engineering prevents unnecessary incidents from being created at all.

By reducing false positives at the source, this allows analysts to spend more time on genuine threats, while improving consistency, cutting costs and helping organisations make better use of both their technology and their people.

The post Is AI entering the SOC at the right stage? appeared first on IT Security Guru.

UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally

13 Agosto 2026 ore 12:57

UK organisations were hit by an average of 1,597 cyber attacks per week each in July 2026, a 26% increase year-on-year, according to new data from Check Point Research, the threat intelligence arm of Check Point Software Technologies. The growth rate outpaced the 16% year-on-year rise recorded globally, even though UK attack volumes remained below the worldwide average of 2,336 weekly attacks per organisation.

The figures form part of Check Point Research’s Global Threat Intelligence report for July 2026, which found that cyber risk is accumulating across multiple fronts at once: rising attack volumes, a sharp acceleration in ransomware activity, and growing exposure from the use of generative AI tools in the enterprise.

In the UK, Education, Energy & Utilities, Software, Government, and Media & Entertainment were named as the five most targeted industries in July, reflecting attackers’ continued focus on sectors that hold sensitive personal data, run critical national infrastructure, or present broad, distributed attack surfaces.

Global attacks keep climbing

Worldwide, organisations faced an average of 2,336 weekly cyber attacks in July, up 3% month-on-month and 16% year-on-year. Education remained the most targeted sector globally, averaging 4,848 weekly attacks per organisation, up 14% year-on-year. Government followed with 3,044 attacks and Telecommunications with 2,927, while Energy and Utilities rose 20% to 2,759 attacks and Hospitality, Travel and Recreation entered the global top five with 2,614 attacks, up 28%, likely reflecting increased exposure during the summer travel period.

Regionally, Latin America recorded the highest attack volume, with 3,561 weekly attacks per organisation, up 19% year-on-year, followed by APAC at 3,316. Europe stood out for its rate of growth, with attacks up 18% year-on-year to 2,051 per organisation, ahead of North America’s 9% rise to 1,613.

Ransomware breaks from its earlier pattern

The sharpest shift in July came from ransomware. Reported victims reached 964 globally, up 87% year-on-year and 49% from June, marking a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents. Business Services was the most affected sector, accounting for 32.5% of reported victims, followed by Industrial Manufacturing at 14.4% and Consumer Goods and Services at 13.4%.

North America remained the most affected region for ransomware, accounting for 45% of reported incidents, followed by Europe at 28% and APAC at 17%. At country level, the United States continued to dominate the victim count with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom and Italy.

The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks, while DeadLock climbed to third place with 10% and 97 reported victims, highlighting continued churn in the ransomware ecosystem.

GenAI exposure becomes a daily business risk

The report also highlighted the growing data exposure risk posed by generative AI tools. One in every 36 prompts sent from enterprise networks carried a high risk of sensitive data leakage, and 88% of organisations that regularly use GenAI tools were affected by high-risk prompt activity. Organisations used an average of eight GenAI tools in July, with individual users generating 95 prompts on average during the month.

Personal data was the most common sensitive category exposed, appearing in 70% of organisations, followed by financial data and network and IT infrastructure information, each present in 68% of organisations.

Email also remained a high-volume risk channel: one in every 128 emails, or 0.78%, was classified as phishing in July, with a further 20% falling into unwanted or risky categories such as graymail, spam and suspicious messages.

“Cyber risk is accumulating across multiple fronts”

“July’s data shows that cyber risk is accumulating across multiple fronts at once,” said Barnaby Nickels, regional sales manager for UKI & North EU at Check Point Software. “Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

For UK organisations, the message lands with particular urgency. With attack growth outpacing the global average and sectors ranging from education to critical infrastructure squarely in attackers’ sights, security teams are being urged to strengthen defences across network, cloud, endpoint, email and AI usage rather than relying on any single layer of protection.

The post UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally appeared first on IT Security Guru.

Un mondo più caldo sarà un mondo più violento

13 Agosto 2026 ore 00:55
di Mac Margolis e Robert Muggah

L’idea che un clima più caldo possa renderci più violenti non è nuova. Il legame tra mercurio e omicidio è familiare della narrativa pulp e dei classici. “Con queste giornate calde il sangue pazzo ribolle”, dice Benvolio prima del duello tra Capuleti e Montecchi per le strade della soffocante Verona di Shakespeare.

Gli studiosi litigano sull’argomento dal 19°  secolo, ma l’accelerazione del cambiamento climatico promette di accendere il dibattito. Se crediamo, come disse il filosofo francese Montesquieu, che  il calore eccessivo  toglie vigore al corpo e offusca la mente, un numero crescente di sociologi, psicologi e criminologi avverte che il clima estremo è miccia per crimini violenti e comportamenti delinquenti.

L’ex governatore delle carceri scozzesi David Wilson una volta ha fatto pressioni per far installare l’aria condizionata in alcune delle prigioni più violente del paese scommettendo che le temperature più fredde portassero a raffreddare gli animi. Wilson, un criminologo, ha osservato che agosto è il mese più violento, citando studi che indicano un  aumento del 10% degli omicidi  nei morti dell’estate scozzese.

Oggi esiste una ricerca considerevole che indica che alcuni shock e stress legati al clima possono innescare crimini sia violenti che non violenti. Le prove disponibili suggeriscono che il l’aumento della temperatura e l’intensificarsi dell’inquinamento possono provocare un aumento sostanziale della criminalità, a partire dalle aree più densamente abitate e vulnerabili.

Con oltre due terzi della popolazione mondiale che si prevede vivrà nelle città entro il 2030, la connessione clima-crimine non può essere ignorata. Le emissioni di gas serra e il riscaldamento stanno già intensificando le isole di calore, contribuendo alla scarsità d’acqua, all’innalzamento del livello del mare, all’aumento dei rischi legati alle inondazioni e al peggioramento della qualità dell’aria, soprattutto nelle grandi città in rapida crescita in Asia, Africa e nelle Americhe. La posta in gioco è più alta nei quartieri e nelle famiglie più vulnerabili, già gravati da profonde disuguaglianze e svantaggi.

Fino a poco tempo, la maggior parte delle città degli Stati Uniti celebrava uno storico declino di tre decenni negli omicidi. Poi le estati hanno  iniziato a scaldarsi, così come il tasso di violenza criminale. Circa il doppio delle persone sono state uccise nelle città del nord come Chicago, Milwaukee e Detroit durante i periodi più caldi rispetto ai mesi più freddi, come riportato sul New York Times, nel 2018. (Il crimine violento è aumentato anche durante l’estate nelle città del sud, anche se in modo meno drammatico.)

La pericolosa relazione tra il riscaldamento e la criminalità non è stata solo evidente negli Stati Uniti. In uno studio globale su 57 città tra il 1995 e il 2012, Dennis Mares e Kenneth Moffett hanno associato un aumento di un grado Celsius delle temperature globali con un  aumento del 6%  della prevalenza della violenza omicida.

Parte della spiegazione è intuitiva. L’aumento delle temperature generalmente manda più persone nelle strade. Certo, non è esattamente il passaggio diretto da un’ondata di caldo a un’ondata di crimine. Le giornate molto calde, ad esempio, potrebbero avere l’effetto opposto: tenere le persone in casa o nello stupore della stanchezza di Montesquieu.

Teorie più recenti sulle relazioni tra clima e criminalità provengono dalle scienze comportamentali e dalla neurologia. Attingendo alla ricerca sperimentale, l’affermazione centrale è che anche sottili alterazioni del tempo o esposizione a sostanze inquinanti possono influenzare il giudizio e il controllo individuali. Quando le persone sono esposte a cambiamenti nel loro ambiente – diciamo, aumento del calore o esposizione a specifici inquinanti – il loro comportamento può cambiare, spesso in peggio.

Nonostante tutte le perturbazioni, tuttavia, le autorità sono state lente nel rispondere alla sfida del crimine climatico. Potremmo non avere più quel lusso. Poiché il clima estremo diventa la nuova normalità, i responsabili delle città dovrebbero mappare le zone più vulnerabili e prestare maggiore attenzione alle comunità più povere, minoritarie ed emarginate che stanno affrontando i rischi e le conseguenze più gravi.

Sanzioni più severe, possono esacerbare disuguaglianze ed insicurezze e scatenare risposte repressive con conseguenze dannose per i gruppi più poveri ed emarginati.

Ci sono molteplici vantaggi negli investimenti basati sulla natura per una vita urbana più sostenibile. La riduzione delle isole di calore, l’innalzamento dei tetti verdi, l’espansione dei parchi e della copertura arborea, mentre il ridimensionamento della pavimentazione e del cemento sono tutte iniziative che possono portare dividendi nella riduzione della criminalità abbassando le temperature e abbattendo le emissioni dei numerosi gas (CO2, NO2 e PM2,5) del cielo sporco della città.

Allo stesso modo, ridurre l’inquinamento atmosferico è particolarmente efficace in termini di costi non solo per migliorare la salute della popolazione, ma anche per prevenire la criminalità. Anche l’inasprimento delle politiche ambientali possono rendere le nostre città più pulite e più sicure.

Le città più grandi e il clima molto più caldo fanno parte di un mondo che cambia, ma anche un invito all’azione. Lavorando ora per mitigare gli effetti peggiori delle condizioni meteorologiche estreme e rimediando alle ingiustizie ambientali nelle nostre città, le amministrazioni possono aiutare non solo a evitare che una crisi climatica diventi un’emergenza, ma anche a risparmiare vite e mezzi di sussistenza.

 

GLI AUTORI

Mac Margolis è un consulente dell’Istituto Igarape e un corrispondente e scrittore di lunga data con sede a Rio de Janeiro. Robert Muggah è co-fondatore dell’Istituto Igarape e direttore del SecDev Group.

L'articolo Un mondo più caldo sarà un mondo più violento proviene da Il Blog di Beppe Grillo.

❌