Over Security

Over Security

33710 bookmarks
Custom sorting
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
·bleepingcomputer.com·
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
Attacco ad Hugging Face: gli Agent AI diventano parte attiva della catena offensiva, come proteggersi
Attacco ad Hugging Face: gli Agent AI diventano parte attiva della catena offensiva, come proteggersi
La scorsa settimana un agente di AI autonomo ha violato parte dell'infrastruttura di produzione di Hugging Face. L’azienda di AI open source ha rilevato l’intrusione, contenendola e riscontrando accessi non autorizzati ad alcuni set di dati interni e credenziali di servizio. Ecco perché gli Agent AI amplificano la superficie di attacco
·cybersecurity360.it·
Attacco ad Hugging Face: gli Agent AI diventano parte attiva della catena offensiva, come proteggersi
Il phishing cambia le regole? Il NIST ridisegna la governance delle identità digitali
Il phishing cambia le regole? Il NIST ridisegna la governance delle identità digitali
La revisione delle linee guida NIST SP 800-63-4 segna un cambio di paradigma nella gestione delle identità digitali. Autenticazione resistente al phishing, verifica continua del rischio e Zero Trust ridisegnano un modello destinato a influenzare anche la NIS2 e il mercato europeo
·cybersecurity360.it·
Il phishing cambia le regole? Il NIST ridisegna la governance delle identità digitali
An AI SOC Evaluation Guide for Security Leaders
An AI SOC Evaluation Guide for Security Leaders
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness.
·bleepingcomputer.com·
An AI SOC Evaluation Guide for Security Leaders
Hugging Face discloses breach linked to autonomous AI agent
Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
·bleepingcomputer.com·
Hugging Face discloses breach linked to autonomous AI agent
Microsoft confirms Windows Server Update Services sync delays
Microsoft confirms Windows Server Update Services sync delays
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week.
·bleepingcomputer.com·
Microsoft confirms Windows Server Update Services sync delays
Videosorveglianza e diritto di accesso: il caso Lidl ridefinisce la gestione delle richieste GDPR
Videosorveglianza e diritto di accesso: il caso Lidl ridefinisce la gestione delle richieste GDPR
Il provvedimento con cui il Garante Privacy ha sanzionato Lidl mostra come moduli, canali interni e procedure non possano ostacolare l'esercizio dei diritti previsti dal GDPR. Un caso che offre indicazioni operative su organizzazione, videosorveglianza e gestione delle richieste di accesso
·cybersecurity360.it·
Videosorveglianza e diritto di accesso: il caso Lidl ridefinisce la gestione delle richieste GDPR
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates.
·bleepingcomputer.com·
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
Critical ServiceNow code execution flaw now exploited in attacks
Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
·bleepingcomputer.com·
Critical ServiceNow code execution flaw now exploited in attacks
Viaggi e prenotazioni online nel mirino: l’estate è alta stagione anche per il phishing
Viaggi e prenotazioni online nel mirino: l’estate è alta stagione anche per il phishing
Con l’aumento delle prenotazioni online crescono anche le campagne di phishing che sfruttano marchi, offerte e comunicazioni legate ai viaggi. Il report di Check Point mostra come il turismo sia diventato uno dei settori più esposti agli attacchi di social engineering
·cybersecurity360.it·
Viaggi e prenotazioni online nel mirino: l’estate è alta stagione anche per il phishing
Standard universali privacy nei dispositivi IoT, per evitare il costo della comodità
Standard universali privacy nei dispositivi IoT, per evitare il costo della comodità
Dalle smart home a alla Internet of Medical Things, la promessa dell’IoT è rendere invisibile la complessità. Ma ciò che diventa invisibile all’utente rischia di diventare opaco anche per il controllo, la responsabilità e la protezione dei dati personali. Ecco perché nasce l'urgenza per standard universali per la privacy nei dispositivi IoT
·cybersecurity360.it·
Standard universali privacy nei dispositivi IoT, per evitare il costo della comodità
Phishing Interactive Brokers in italiano: oltre 6.000 email tentano di rubare le credenziali
Phishing Interactive Brokers in italiano: oltre 6.000 email tentano di rubare le credenziali
Il team antifrode di D3Lab ha rilevato il 17 luglio una campagna di phishing particolarmente massiva che sfrutta il nome e l’identità visiva di Interactive Brokers. Oltre 6.000 email, numerosi oggetti differenti e un’infrastruttura composta da più domini conducono le vittime verso una falsa procedur
·d3lab.net·
Phishing Interactive Brokers in italiano: oltre 6.000 email tentano di rubare le credenziali
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Group-IB uncovers HOLLOWGRAPH, a Windows malware that abuses Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.
·group-ib.com·
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
CVE-2026-42533 is a critical Pre-Auth nginx RCE flaw affecting multiple versions. Upgrade now to patched releases to mitigate the risk.
·thecyberexpress.com·
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
Paidwork - 23,272,765 breached accounts
Paidwork - 23,272,765 breached accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.
·haveibeenpwned.com·
Paidwork - 23,272,765 breached accounts
Hackers abuse ViPNet software to target Russian govt agencies
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.
·bleepingcomputer.com·
Hackers abuse ViPNet software to target Russian govt agencies
L’industria della colonizzazione lunare
L’industria della colonizzazione lunare
Mappe, porti, regolamenti e soprattutto rapporti di potere: come funziona la logistica della space economy.
·guerredirete.substack.com·
L’industria della colonizzazione lunare