Over Security

Over Security

77 Open VSX extensions found harvesting developer info
77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed.
·bleepingcomputer.com·
77 Open VSX extensions found harvesting developer info
Hackers steal over $130 million by exploiting bug in offline hardware wallets
Hackers steal over $130 million by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms.
·techcrunch.com·
Hackers steal over $130 million by exploiting bug in offline hardware wallets
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
·bleepingcomputer.com·
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Varonis Agent IBAC keeps AI agents within their intended boundaries
Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries.
·bleepingcomputer.com·
Varonis Agent IBAC keeps AI agents within their intended boundaries
Top Hack e violazioni di dati: ecco la classifica del 2018
Top Hack e violazioni di dati: ecco la classifica del 2018
L'anno 2018 è ormai un lontano ricordo, eppure ha stabilito un record per quanto riguarda le attività di hacking e di violazioni di dati, le più importanti degli ultimi anni.
·hackerstribe.com·
Top Hack e violazioni di dati: ecco la classifica del 2018
Revenge Porn, quando i ricatti si fanno in rete
Revenge Porn, quando i ricatti si fanno in rete
Il Revenge Porn è la pubblicazione sul web di immagini o video che ritraggono le parti intime di una persona, senza il suo consenso, per vendetta.
·hackerstribe.com·
Revenge Porn, quando i ricatti si fanno in rete
How legitimate cloud platforms enable phishers to bypass MFA
How legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
·securelist.com·
How legitimate cloud platforms enable phishers to bypass MFA
Retelit, operatore cloud e di telecomunicazioni, ha subito un attacco informatico. E non lo dice
Retelit, operatore cloud e di telecomunicazioni, ha subito un attacco informatico. E non lo dice
Tra i suoi clienti ci sono aziende strategiche, gestori di identità digitali e pubbliche amministrazioni. Migliaia i documenti già disponibili online. Dietro l’attacco Qilin, gruppo cybercriminale attivo almeno dal 2022 che ruba password e accessi
·irpimedia.irpi.eu·
Retelit, operatore cloud e di telecomunicazioni, ha subito un attacco informatico. E non lo dice
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono
Nessun sistema è immune dai guasti. Il principio del fail secure insegna a progettare applicazioni e infrastrutture che, in caso di errore, proteggano dati e asset critici senza amplificare il rischio. Un approccio che cambia il modo di concepire sicurezza, resilienza e continuità operativa
·cybersecurity360.it·
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono
NIS2, asset e servizi IT: come costruire un inventario realmente utile alla gestione del rischio
NIS2, asset e servizi IT: come costruire un inventario realmente utile alla gestione del rischio
L’inventario degli asset non dovrebbe essere una semplice lista tecnica di server, applicazioni, dispositivi e servizi cloud. In ottica NIS2, deve diventare una mappa ragionata di ciò che sostiene le attività dell’organizzazione, evidenziando criticità, dipendenze, owner, fornitori e impatti sul business
·cybersecurity360.it·
NIS2, asset e servizi IT: come costruire un inventario realmente utile alla gestione del rischio
Categorizzazione NIS 2: da adempimento a strumento di governo della sicurezza
Categorizzazione NIS 2: da adempimento a strumento di governo della sicurezza
La categorizzazione NIS2, che non è finita il 30 giugno, entra in una nuova fase: infatti apre il percorso, ma non lo conclude. Ecco perché il valore del lavoro svolto non dipenderà dalla qualità formale di ciò che è stato trasmesso, bensì dall’uso che ogni organizzazione deciderà di farne
·cybersecurity360.it·
Categorizzazione NIS 2: da adempimento a strumento di governo della sicurezza
New Pass-ta-key attacks let malware hijack Google-synced passkeys
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.
·bleepingcomputer.com·
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize in computer hacking laws to find out.
·techcrunch.com·
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated