Over Security

Over Security

CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application.
·bleepingcomputer.com·
CISA orders feds to patch actively exploited Oracle flaw by Saturday
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT.
·bleepingcomputer.com·
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
The Hunter's Paradox: Is it time to embrace automated threat hunting?
The Hunter's Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.
·blog.talosintelligence.com·
The Hunter's Paradox: Is it time to embrace automated threat hunting?
L’industria della colonizzazione lunare
L’industria della colonizzazione lunare
Mappe, porti, regolamenti e soprattutto rapporti di potere: come funziona la logistica della space economy
·guerredirete.it·
L’industria della colonizzazione lunare
Dalle password alle passkey: ecco come usarle per il click to pay
Dalle password alle passkey: ecco come usarle per il click to pay
Secondo un'indagine di Thales, quasi 7 utenti su dieci ammettono di condividere o prendere in prestito credenziali, evidenziando quanto rapidamente la difficoltà si trasformi in rischio. Ecco perché il superamento delle password, per migrare alle passkey, è urgente, in vista del click to pay
·cybersecurity360.it·
Dalle password alle passkey: ecco come usarle per il click to pay
Le 12 best practice dell’ingegneria dei sistemi di intelligenza artificiale
Le 12 best practice dell’ingegneria dei sistemi di intelligenza artificiale
Le pratiche non vanno intese come una sequenza procedurale o una checklist, ma come un quadro di riferimento per le decisioni progettuali. Ecco una sintesi e un'analisi critica del documento aggiornato sull'ingegneria dei sistemi di intelligenza artificiale con le 12 raccomandazioni del Software Engineering Institute (SEI)
·cybersecurity360.it·
Le 12 best practice dell’ingegneria dei sistemi di intelligenza artificiale
ClickLock Stealer: Paste Once, Lose Everything
ClickLock Stealer: Paste Once, Lose Everything
Analysis of ClickLock, a modular macOS stealer delivered via ClickFix that uses fake dialogs, kill loops, and a GSocket backdoor to steal passwords, browser data, and crypto wallets.
·group-ib.com·
ClickLock Stealer: Paste Once, Lose Everything
Dutch police bust investment fraud ring stealing over €100 million
Dutch police bust investment fraud ring stealing over €100 million
The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims.
·bleepingcomputer.com·
Dutch police bust investment fraud ring stealing over €100 million
Zoom warns of critical account takeover vulnerability
Zoom warns of critical account takeover vulnerability
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts.
·bleepingcomputer.com·
Zoom warns of critical account takeover vulnerability
Microsoft patches bug in video game Age of Empires II
Microsoft patches bug in video game Age of Empires II
The vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.
·techcrunch.com·
Microsoft patches bug in video game Age of Empires II
​ ​AsyncAPI npm packages infected with credential-stealing malware
​ ​AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
·bleepingcomputer.com·
​ ​AsyncAPI npm packages infected with credential-stealing malware
We built a vulnerability vending machine: AI tokens in, zero-days out
We built a vulnerability vending machine: AI tokens in, zero-days out
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure.
·bleepingcomputer.com·
We built a vulnerability vending machine: AI tokens in, zero-days out
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega
Le nuove FAQ dell’ACN ribadiscono che la nomina di un CISO non esaurisce gli obblighi previsti dalla NIS2. La cyber security entra stabilmente nella governance d’impresa: le attività operative si delegano, ma responsabilità, indirizzo e supervisione restano in capo al CdA
·cybersecurity360.it·
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega