Over Security

Over Security

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).
·bleepingcomputer.com·
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach.
·bleepingcomputer.com·
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
IDScan sued over alleged data breach affecting 153 million drivers
IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses.
·bleepingcomputer.com·
IDScan sued over alleged data breach affecting 153 million drivers
Critical Citrix NetScaler auth bypass now leveraged in attacks
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
·bleepingcomputer.com·
Critical Citrix NetScaler auth bypass now leveraged in attacks
Il budget? Non basta mai
Il budget? Non basta mai
Che la sicurezza cyber debba coinvolgere anche l'IA è vero, ma non è possibile delegarla a questi sistemi o, peggio ancora, considerarli come un focus principale sia d'attacco che di difesa. Perché altrimenti il rischio è quello di perdere quella visione d'insieme necessaria per mantenere una corretta postura di sicurezza cyber
·cybersecurity360.it·
Il budget? Non basta mai
Il phishing sfrutta le difficoltà economiche: come prevenire l’attacco che induce a telefonare all’attaccante
Il phishing sfrutta le difficoltà economiche: come prevenire l’attacco che induce a telefonare all’attaccante
L’ultima campagna phishing, che scommette sulle difficoltà economiche delle vittime, trasforma l’ansia economico-finanziaria in vettore di ingegneria sociale, incoraggiando le vittime a chiamare un numero di telefono sotto il controllo dei cyber criminali. Ecco come mitigare i rischi nelle interazioni telefoniche
·cybersecurity360.it·
Il phishing sfrutta le difficoltà economiche: come prevenire l’attacco che induce a telefonare all’attaccante
Microsoft says some users can’t open the Teams desktop client
Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems.
·bleepingcomputer.com·
Microsoft says some users can’t open the Teams desktop client
39 New Methods That Compromise Passkey Authentication
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography.
·bleepingcomputer.com·
39 New Methods That Compromise Passkey Authentication
Cyber Resilience Act, l’11 settembre scattano gli obblighi di segnalazione: cosa cambia per le aziende
Cyber Resilience Act, l’11 settembre scattano gli obblighi di segnalazione: cosa cambia per le aziende
Dall’11 settembre 2026 il Cyber Resilience Act entra nella sua prima fase operativa con gli obblighi di segnalazione previsti dall’articolo 14. Una scadenza che impone a produttori e sviluppatori di preparare processi di incident response, vulnerability management e CVD senza aspettare la piena applicazione del 2027
·cybersecurity360.it·
Cyber Resilience Act, l’11 settembre scattano gli obblighi di segnalazione: cosa cambia per le aziende
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems.
·bleepingcomputer.com·
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
Control Gap dell’AI: la corsa all’adozione lascia i dati vulnerabili
Control Gap dell’AI: la corsa all’adozione lascia i dati vulnerabili
Con il debutto di Claude Mythos, il tempo che intercorre tra la scoperta di una vulnerabilità e la compromissione attiva (con accessi non autorizzati) si sta azzerando. Ecco cosa implica il fatto che la velocità delle minacce ha subito un’accelerazione senza precedenti e come cambia il ritmo del cybercrime
·cybersecurity360.it·
Control Gap dell’AI: la corsa all’adozione lascia i dati vulnerabili
Google warns of new Chrome zero-day flaw exploited in attacks
Google warns of new Chrome zero-day flaw exploited in attacks
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
·bleepingcomputer.com·
Google warns of new Chrome zero-day flaw exploited in attacks
Angry Birds: Toy Ghouls’ new toys
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
·securelist.com·
Angry Birds: Toy Ghouls’ new toys
Server Exchange, cinque scudi per la posta elettronica
Server Exchange, cinque scudi per la posta elettronica
La sicurezza dei server Exchange dipende dalla capacità di ridurne l’esposizione, correggere rapidamente le vulnerabilità e riconoscere un’intrusione già avvenuta. Di cosa tenere conto e quali strumenti sono d’aiuto
·cybersecurity360.it·
Server Exchange, cinque scudi per la posta elettronica
Organizzazioni “buone” o “brave” negli adempimenti GDPR: il futuro si progetta
Organizzazioni “buone” o “brave” negli adempimenti GDPR: il futuro si progetta
La distinzione tra organizzazioni “buone” - che rispettano le regole già definite da altri - e quelle “brave” - che comprendono i trattamenti, valutano i rischi, trasformando gli adempimenti in strumenti di governo - è messa alla prova sugli strumenti quotidiani. Ecco come le lingue costruiscono il futuro dal dovere (shall) e dalla volontà (will)
·cybersecurity360.it·
Organizzazioni “buone” o “brave” negli adempimenti GDPR: il futuro si progetta
One Adversary: The 90-Day Fusion Playbook
One Adversary: The 90-Day Fusion Playbook
Fusion is a capability you mature into, not a team you hire. Here is the honest maturity path, the metrics that fund it, and the on-ramp that costs no headcount, startable this quarter.
·group-ib.com·
One Adversary: The 90-Day Fusion Playbook