Over Security

Over Security

Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services.
·bleepingcomputer.com·
Microsoft blames massive Microsoft 365 outage on maintenance bug
Acn: nel primo semestre 2026 resta elevata la pressione da parte delle minacce cyber
Acn: nel primo semestre 2026 resta elevata la pressione da parte delle minacce cyber
Secondo l'operational summary dell'Acn, nel primo semestre 2026 si sta consolidando il sistema nazionale di cyber security, mentre l'entrata a regime degli obblighi di notifica previsti dalla direttiva NIS2 rafforza la resilienza del Paese. Ecco cosa emerge nei dettagli e cosa brilla per la sua assenza
·cybersecurity360.it·
Acn: nel primo semestre 2026 resta elevata la pressione da parte delle minacce cyber
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline.
·bleepingcomputer.com·
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19.
·bleepingcomputer.com·
Chick-fil-A data breach affects more than 13,000 customers
AIncident Responsible
AIncident Responsible
Il recente caso exploitgym, con i server di Huggingface compromessi dall'azione degli agenti di OpenAI offre non pochi spunti per ragionare circa il gap cognitivo fra rischio incalcolabile e non calcolato nella gestione della sicurezza cyber
·cybersecurity360.it·
AIncident Responsible
Backup su larga scala: dagli indicatori di stato “verde” alla reale capacità di ripristino
Backup su larga scala: dagli indicatori di stato “verde” alla reale capacità di ripristino
In caso di incidenti, dovuti ad attacchi ransomware, interruzioni di servizio o cancellazioni accidentali, ciò che conta è se esistono punti di ripristino, quanto questi siano recenti e se i backup siano rapidamente e ripetutamente eseguibili, anche in situazioni di stress. Ecco come effettuare il backup su larga scala
·cybersecurity360.it·
Backup su larga scala: dagli indicatori di stato “verde” alla reale capacità di ripristino
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups.
·bleepingcomputer.com·
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Man gets six years for hacking 750 women's Snapchat accounts
Man gets six years for hacking 750 women's Snapchat accounts
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos.
·bleepingcomputer.com·
Man gets six years for hacking 750 women's Snapchat accounts
Malware nella supply chain software: gli sviluppatori sono il punto più vulnerabile
Malware nella supply chain software: gli sviluppatori sono il punto più vulnerabile
Il nuovo malware individuato da Doctor Web non si limita a sottrarre credenziali o installare backdoor: compromette i progetti C++ e C# trasformando gli ambienti di sviluppo in vettori di attacco. Un’evoluzione che conferma come la supply chain software sia ormai uno dei principali fronti della minaccia cyber
·cybersecurity360.it·
Malware nella supply chain software: gli sviluppatori sono il punto più vulnerabile
CRA e Direttiva UE sui prodotti difettosi: come cambia la responsabilità cyber delle imprese
CRA e Direttiva UE sui prodotti difettosi: come cambia la responsabilità cyber delle imprese
Il Cyber Resilience Act definisce i requisiti di sicurezza dei prodotti digitali, ma la nuova Direttiva UE 2024/2853 sulla responsabilità per danno da prodotti difettosi aggiunge un tassello decisivo: la cyber security esce dall'ambito della compliance e diventa un fattore di responsabilità civile e di rischio d'impresa
·cybersecurity360.it·
CRA e Direttiva UE sui prodotti difettosi: come cambia la responsabilità cyber delle imprese
Smart grid e transizione energetica: perché la governance dei dati è un vantaggio competitivo
Smart grid e transizione energetica: perché la governance dei dati è un vantaggio competitivo
La trasparenza nella gestione dei dati non costituisce un vincolo, ma si traduce in un elemento di differenziazione competitiva presso consumatori sempre più consapevoli dei propri diritti. Ecco come principi, progettazione e vantaggio competitivo agevolano la fiducia dei consumatori
·cybersecurity360.it·
Smart grid e transizione energetica: perché la governance dei dati è un vantaggio competitivo
New Dolphin X malware uses AI to rank high-value targets
New Dolphin X malware uses AI to rank high-value targets
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.
·bleepingcomputer.com·
New Dolphin X malware uses AI to rank high-value targets
Australian energy provider Origin says data breach exposes client data
Australian energy provider Origin says data breach exposes client data
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others.
·bleepingcomputer.com·
Australian energy provider Origin says data breach exposes client data
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.
·bleepingcomputer.com·
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Don’t swing at everything
Don’t swing at everything
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
·blog.talosintelligence.com·
Don’t swing at everything
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
·bleepingcomputer.com·
Russian hackers exploit Zimbra zero-click flaw for email theft