Over Security

Over Security

Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio
Ogni prospettiva descrive un livello di una catena d'attacco. Da sola, nessuna la descrive tutta. Ma il modello ibrido nasce dalla consapevolezza: non elimina i metodi esistenti, ma li collega. Ecco perché nella gestione dei rischi NIS 2, si fa largo il modello ibrido
·cybersecurity360.it·
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio
AI Models Escaped Test Environments and Hit Real Targets
AI Models Escaped Test Environments and Hit Real Targets
AI security incidents expose gaps in model evaluation environments as Irregular reviews internet access, monitoring and containment controls.
·thecyberexpress.com·
AI Models Escaped Test Environments and Hit Real Targets
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.
·bleepingcomputer.com·
Pokémon Center data breach exposes customer info, cancels some orders
Microsoft confirms GitHub is down worldwide
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services.
·bleepingcomputer.com·
Microsoft confirms GitHub is down worldwide
Certighost and the Privilege Hiding in Your Certificate Authority
Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been.
·bleepingcomputer.com·
Certighost and the Privilege Hiding in Your Certificate Authority
Windows Server 2022 reaches end of mainstream support in 60 days
Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support.
·bleepingcomputer.com·
Windows Server 2022 reaches end of mainstream support in 60 days
Philips and GE investigating Clop ransomware data theft claims
Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data.
·bleepingcomputer.com·
Philips and GE investigating Clop ransomware data theft claims
French tax authority data breach affects 678,000 individuals
French tax authority data breach affects 678,000 individuals
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.
·bleepingcomputer.com·
French tax authority data breach affects 678,000 individuals
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414.
·bleepingcomputer.com·
Microsoft working on Defender patch for ShieldBreak zero-day
Software Bill of Materials per l’AI: la supply chain dell’intelligenza artificiale diventa verificabile
Software Bill of Materials per l’AI: la supply chain dell’intelligenza artificiale diventa verificabile
Il G7 definisce per la prima volta gli elementi minimi di un SBOM dedicato ai sistemi AI, estendendo l'inventario software a modelli, dataset, infrastrutture e proprietà di sicurezza. Una base comune per rendere la supply chain più tracciabile e prepararsi a requisiti che potrebbero diventare vincolanti
·cybersecurity360.it·
Software Bill of Materials per l’AI: la supply chain dell’intelligenza artificiale diventa verificabile
SafePal data breach impacts 39,798 customers, stolen info for sale
SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.
·bleepingcomputer.com·
SafePal data breach impacts 39,798 customers, stolen info for sale
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser.
·bleepingcomputer.com·
New AmnesiaStealer macOS malware hijacks browser sessions via remote control