Over Security

Over Security

Viaggi e prenotazioni online nel mirino: l’estate è alta stagione anche per il phishing
Viaggi e prenotazioni online nel mirino: l’estate è alta stagione anche per il phishing
Con l’aumento delle prenotazioni online crescono anche le campagne di phishing che sfruttano marchi, offerte e comunicazioni legate ai viaggi. Il report di Check Point mostra come il turismo sia diventato uno dei settori più esposti agli attacchi di social engineering
·cybersecurity360.it·
Viaggi e prenotazioni online nel mirino: l’estate è alta stagione anche per il phishing
Standard universali privacy nei dispositivi IoT, per evitare il costo della comodità
Standard universali privacy nei dispositivi IoT, per evitare il costo della comodità
Dalle smart home a alla Internet of Medical Things, la promessa dell’IoT è rendere invisibile la complessità. Ma ciò che diventa invisibile all’utente rischia di diventare opaco anche per il controllo, la responsabilità e la protezione dei dati personali. Ecco perché nasce l'urgenza per standard universali per la privacy nei dispositivi IoT
·cybersecurity360.it·
Standard universali privacy nei dispositivi IoT, per evitare il costo della comodità
Phishing Interactive Brokers in italiano: oltre 6.000 email tentano di rubare le credenziali
Phishing Interactive Brokers in italiano: oltre 6.000 email tentano di rubare le credenziali
Il team antifrode di D3Lab ha rilevato il 17 luglio una campagna di phishing particolarmente massiva che sfrutta il nome e l’identità visiva di Interactive Brokers. Oltre 6.000 email, numerosi oggetti differenti e un’infrastruttura composta da più domini conducono le vittime verso una falsa procedur
·d3lab.net·
Phishing Interactive Brokers in italiano: oltre 6.000 email tentano di rubare le credenziali
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Group-IB uncovers HOLLOWGRAPH, a Windows malware that abuses Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.
·group-ib.com·
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
CVE-2026-42533 is a critical Pre-Auth nginx RCE flaw affecting multiple versions. Upgrade now to patched releases to mitigate the risk.
·thecyberexpress.com·
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
Paidwork - 23,272,765 breached accounts
Paidwork - 23,272,765 breached accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.
·haveibeenpwned.com·
Paidwork - 23,272,765 breached accounts
Hackers abuse ViPNet software to target Russian govt agencies
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.
·bleepingcomputer.com·
Hackers abuse ViPNet software to target Russian govt agencies
L’industria della colonizzazione lunare
L’industria della colonizzazione lunare
Mappe, porti, regolamenti e soprattutto rapporti di potere: come funziona la logistica della space economy.
·guerredirete.substack.com·
L’industria della colonizzazione lunare
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
·bleepingcomputer.com·
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.
·bleepingcomputer.com·
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
·bleepingcomputer.com·
Microsoft warns of surge in ACR Stealer attacks on customers
The Future of Age Verification: Your Face Never Leaves Your Device
The Future of Age Verification: Your Face Never Leaves Your Device
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance.
·bleepingcomputer.com·
The Future of Age Verification: Your Face Never Leaves Your Device
Abbott Laboratories probes two cyber incidents amid extortion claims
Abbott Laboratories probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.
·bleepingcomputer.com·
Abbott Laboratories probes two cyber incidents amid extortion claims
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.
·bleepingcomputer.com·
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
Così i Servizi russi hanno compromesso router in tutto il mondo: le contromisure
Così i Servizi russi hanno compromesso router in tutto il mondo: le contromisure
Una campagna decennale, orchestrata dal “Centro 16” del Servizio Federale di Sicurezza russo, l'FSB, ha compromesso router e dispositivi di rete, configurati in modo debole o non aggiornato, per trasformarli in nodi di appoggio da cui lanciare, in forma anonima, operazioni contro le infrastrutture critiche a livello globale. Il caso Turla
·cybersecurity360.it·
Così i Servizi russi hanno compromesso router in tutto il mondo: le contromisure
Recupero crediti, Garante Privacy: ecco chi paga il conto della mancata vigilanza
Recupero crediti, Garante Privacy: ecco chi paga il conto della mancata vigilanza
Due provvedimenti "gemelli" del Garante privacy ridisegnano i confini della responsabilità condivisa nella filiera del recupero crediti: non basta nominare un responsabile del trattamento, occorre vigilare sul suo operato e informare il titolare del trattamento. In ambito recupero crediti, ecco il principio che ispira i provvedimenti dell'Autorità
·cybersecurity360.it·
Recupero crediti, Garante Privacy: ecco chi paga il conto della mancata vigilanza
Inside the Search for "Clean" Residential Proxies for Carding
Inside the Search for "Clean" Residential Proxies for Carding
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.
·bleepingcomputer.com·
Inside the Search for "Clean" Residential Proxies for Carding
Meglio prima che mai!
Meglio prima che mai!
Quando la sicurezza cyber non è collocata come priorità su una linea temporale di intervento, è inevitabile che prima o poi la gestione stessa di questo aspetto inizierà a risentirne, sia per accumulo del debito tecnologico sia per aumento dell'incertezza ed aumento della probabilità di subire attacchi
·cybersecurity360.it·
Meglio prima che mai!
CyberCUBE: la cyber security spaziale passa dalla compliance ai test in orbita
CyberCUBE: la cyber security spaziale passa dalla compliance ai test in orbita
Il 7 luglio un satellite CubeSat è entrato in orbita per farsi “attaccare”. Non è una stranezza: è la risposta dell'ESA a un problema che, chi lavora nella governance del rischio cyber, conosce fin troppo bene: la distanza tra le contromisure scritte nei documenti e la prova che funzionino davvero
·cybersecurity360.it·
CyberCUBE: la cyber security spaziale passa dalla compliance ai test in orbita