LIVE · cybersecurity feed
Live wire
security

Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review

Italy's Ministry of Foreign Affairs confirmed on October 8, 2026, that its website was under cyberattack. The ministry stated that its protection systems successfully mitigated the incident, preventing any disruption to its services.

ZeroDay News ·

Source: Security Affairs

Italy's Ministry of Foreign Affairs confirmed on October 8, 2026, that its website was under cyberattack. The ministry stated that its protection systems successfully mitigated the incident, preventing any disruption to its services.

Foreign Minister Antonio Tajani indicated that the ministry is actively monitoring the situation in collaboration with the Polo Strategico Nazionale, Italy's national cloud hub, and other relevant authorities. Tajani emphasized that cybersecurity has been a central focus of the Farnesina's reform efforts over the past year, leading to strengthened capabilities in prevention, monitoring, and response, including technological countermeasures.

Following the attack, Italian authorities are also inspecting the websites of Italian embassies and consulates abroad for similar malicious activity.

The ministry's statement also outlined Italy's intention to collaborate with Romania and other European Union member states to propose measures in upcoming EU meetings aimed at officially designating the entities responsible for cyberattacks, particularly those targeting Italian institutions.

While the ministry did not identify the perpetrators or the specific nature of the attack, analysts note that the pattern of targeting Italian government and critical infrastructure aligns with previous campaigns by pro-Russian hacktivist groups. One such group, NoName057(16), which emerged in March 2022, has a history of using DDoS attacks against governments supporting Ukraine.

NoName057(16), often associated with the crowdsourced DDoSia Project, has previously targeted Italian entities. In January 2025, during a visit by Ukrainian President Volodymyr Zelensky to Rome, the group reportedly attacked various ministries, government sites, banks including Intesa and Monte dei Paschi di Siena, and the ports of Taranto and Trieste. Prior to that, in December 2024, Malpensa and Linate airports were reportedly targeted. Another wave of attacks in February 2025 was linked to a speech by President Mattarella.

The Ministry of Foreign Affairs itself experienced a similar incident in late December 2024, when its website was reportedly taken offline by Russian hackers, though it was restored the following day. DDoS attacks primarily impact availability rather than data integrity.

Reports indicate that the DDoSia project's target list for the current campaign includes the Farnesina (Ministry of Foreign Affairs), five Italian embassy sites, several services belonging to the Interior and Defence Ministries, and other Italian organizations. Specific targets identified include ambbruxelles.esteri.it, ambbucarest.esteri.it, ambcopenaghen.esteri.it, ambdublino.esteri.it, and ambhelsinki.esteri.it, along with various government and defense-related domains.

This incident is not the first time the Italian Foreign Ministry has faced cyber intrusions. In 2017, a months-long intrusion into the ministry's systems was reported, with attackers reportedly targeting staff email accounts at the ministry and Italian embassies, though not the encrypted systems used for sensitive communications. At that time, a senior ministry security official noted that attacks often coincide with significant events for Italy.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.

ai

Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal

More than 100 members of Congress have urged Google and Spirit Airlines to halt a proposed $10 million deal that would transfer Spirit's internal data to Google for the purpose of training artificial intelligence models. The lawmakers expressed significant concerns that even with de-identification safeguards, the data could still expose sensitive employee information.

ransomware

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

IDC Frontier, a prominent Japanese cloud and digital infrastructure provider, has confirmed that its IDCF Cloud service was targeted in a ransomware attack. The incident, which began on October 7 at 3:40 AM local time, led to an outage at a data center cluster serving Japan's eastern region.

security

DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub

The U.S. Justice Department and FBI have announced the seizure of two hacking tools, Microscan and FishHub, which are linked to the Chinese government-affiliated group Flax Typhoon and the China-based firm Integrity Technology Group. The seizures, authorized by a court in the Western District of Pennsylvania, aim to disrupt access to these tools by denying hackers their domain names.

ransomware

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Zohar Pinhasi, the owner and operator of the ransomware recovery firm MonsterCloud, has been indicted on charges of wire fraud and wire fraud conspiracy. Authorities allege that Pinhasi defrauded hundreds of clients by claiming to decrypt their data using proprietary tools without paying ransoms, while in reality, he secretly paid cybercriminals and then charged his clients significantly…

malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.