Over Security

Over Security

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
·bleepingcomputer.com·
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Hackers start exploiting critical WordPress flaw for code execution
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
·bleepingcomputer.com·
Hackers start exploiting critical WordPress flaw for code execution
Attacco all’FBI, ShinyHunters rivendica il colpo: cosa sappiamo davvero
Attacco all’FBI, ShinyHunters rivendica il colpo: cosa sappiamo davvero
ShinyHunters sostiene di essere riuscito a violare l'infrastruttura dell'FBI e di aver sottratto una grande quantità di informazioni relative ad agenti, dipendenti ed ex dipendenti, oltre a persone che avrebbero presentato domanda per lavorare nell'agenzia. Il Bureau non ha ancora confermato ufficialmente, ecco cosa risulta verificato
·cybersecurity360.it·
Attacco all’FBI, ShinyHunters rivendica il colpo: cosa sappiamo davvero
InfraTrust report warns network management systems under attack
InfraTrust report warns network management systems under attack
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them.
·bleepingcomputer.com·
InfraTrust report warns network management systems under attack
Claude Opus 5.5 spinge l’AI nella cyber: più capacità, più controlli
Claude Opus 5.5 spinge l’AI nella cyber: più capacità, più controlli
Claude Opus 5.5 avvicina le capacità cyber dei modelli più avanzati a una platea molto più ampia e per questo Anthropic ha introdotto nuovi safeguard, routing delle richieste sensibili, sandbox e accessi verificati: per le aziende cambia il modo di governare gli agenti AI
·cybersecurity360.it·
Claude Opus 5.5 spinge l’AI nella cyber: più capacità, più controlli
How One Kubernetes YAML Can Hand Over a GCP Organization
How One Kubernetes YAML Can Hand Over a GCP Organization
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation.
·bleepingcomputer.com·
How One Kubernetes YAML Can Hand Over a GCP Organization
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments.
·bleepingcomputer.com·
Arista patches actively exploited VeloCloud Orchestrator zero-day
Garante privacy, 120 giorni per contestare: resta il nodo dei tempi delle sanzioni
Garante privacy, 120 giorni per contestare: resta il nodo dei tempi delle sanzioni
Il Garante privacy ha 120 giorni per notificare la contestazione, non per concludere il procedimento sanzionatorio. La Cassazione chiarisce la distinzione, ma lascia emergere un problema irrisolto: manca un termine finale certo. Una lacuna che incide sulla difesa delle imprese e che l’Autorità potrebbe colmare con il proprio regolamento
·cybersecurity360.it·
Garante privacy, 120 giorni per contestare: resta il nodo dei tempi delle sanzioni
EU Turns the Tables on Big Tech Over Children’s Safety
EU Turns the Tables on Big Tech Over Children’s Safety
EU KIDS Act proposes new age limits, parental controls and safety requirements for children using social media and online platforms in the EU.
·thecyberexpress.com·
EU Turns the Tables on Big Tech Over Children’s Safety
AI, il costo nascosto della produttività: quando generare costa meno che verificare
AI, il costo nascosto della produttività: quando generare costa meno che verificare
L’intelligenza artificiale sta abbattendo drasticamente il costo necessario per produrre codice, documenti, analisi e informazioni. Verificarli, però, continua a richiedere tempo, competenza e responsabilità. Il rischio è trasformare la produttività individuale in un debito di verifica collettivo
·cybersecurity360.it·
AI, il costo nascosto della produttività: quando generare costa meno che verificare