Over Security

Over Security

NIS2, continuità operativa e disaster recovery: definire priorità, RTO e RPO
NIS2, continuità operativa e disaster recovery: definire priorità, RTO e RPO
La continuità operativa non può essere ridotta alla presenza di backup o a un piano di ripristino tecnico. In ottica NIS2, resilienza significa sapere quali attività devono ripartire prima, quali asset le supportano, quali tempi di fermo sono accettabili e quanta perdita dati può essere tollerata
·cybersecurity360.it·
NIS2, continuità operativa e disaster recovery: definire priorità, RTO e RPO
Lo “shall” del GDPR: il dovere di protezione che obbliga a progettare il futuro
Lo “shall” del GDPR: il dovere di protezione che obbliga a progettare il futuro
Dietro il verbo "shall” del GDPR c'è l'idea antica del dovere come debito. Un debito di protezione che la norma impone al titolare senza prescrivere una soluzione predefinita: spetta a lui tradurre principi e risultati obbligatori in misure adeguate, assumendosi la responsabilità di progettare il futuro
·cybersecurity360.it·
Lo “shall” del GDPR: il dovere di protezione che obbliga a progettare il futuro
Exact Sciences - 10,869,543 breached accounts
Exact Sciences - 10,869,543 breached accounts
In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.
·haveibeenpwned.com·
Exact Sciences - 10,869,543 breached accounts
The Evolution of Phishing: A Brief History
The Evolution of Phishing: A Brief History
Learn how phishing attacks evolved from early online scams to AI-powered threats, key milestones, common techniques, and practical ways to reduce risk.
·bfore.ai·
The Evolution of Phishing: A Brief History
ClickFix attack pushes macOS infostealer for crypto theft attacks
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.
·bleepingcomputer.com·
ClickFix attack pushes macOS infostealer for crypto theft attacks
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group.
·bleepingcomputer.com·
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
Swiss government SharePoint breach compromised 200 accounts
Swiss government SharePoint breach compromised 200 accounts
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts.
·bleepingcomputer.com·
Swiss government SharePoint breach compromised 200 accounts
Why metaphor may dictate your security strategy
Why metaphor may dictate your security strategy
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
·blog.talosintelligence.com·
Why metaphor may dictate your security strategy
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider…
·krebsonsecurity.com·
Canadian Man Pleads Guilty in Snowflake Extortions
Meta AI model hacked a company during misconfigured cyber test
Meta AI model hacked a company during misconfigured cyber test
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face.
·bleepingcomputer.com·
Meta AI model hacked a company during misconfigured cyber test
Quando l’AI cambia il modo di decidere: come evolve l’Internal Auditing
Quando l’AI cambia il modo di decidere: come evolve l’Internal Auditing
L'intelligenza artificiale non modifica solo processi e controlli: trasforma il modo in cui le organizzazioni costruiscono conoscenza e formulano giudizi. Da qui nasce il concetto di rischio epistemico organizzativo, che propone una nuova prospettiva sull'evoluzione dell'assurance e del ruolo dell'Internal Audit
·cybersecurity360.it·
Quando l’AI cambia il modo di decidere: come evolve l’Internal Auditing