Over Security

Over Security

Input validation: perché la sicurezza applicativa comincia dai dati che lasciamo entrare
Input validation: perché la sicurezza applicativa comincia dai dati che lasciamo entrare
Ogni dato proveniente dall'esterno può diventare un vettore di attacco. Per questo l'input validation non dovrebbe essere un controllo aggiunto a valle, ma un requisito di progettazione: un approccio multilivello che riduce la superficie di attacco senza sacrificare l'usabilità
·cybersecurity360.it·
Input validation: perché la sicurezza applicativa comincia dai dati che lasciamo entrare
Gestione dei rischi NIS 2: la scelta del metodo determina la qualità del sistema
Gestione dei rischi NIS 2: la scelta del metodo determina la qualità del sistema
La scelta del metodo non è una decisione tecnica di secondo piano, ma stabilisce il modo in cui l’organizzazione comprenderà i propri rischi, selezionerà le misure e dimostrerà la coerenza del proprio sistema. Ecco perché la gestione dei rischi occupa il centro esatto della NIS 2
·cybersecurity360.it·
Gestione dei rischi NIS 2: la scelta del metodo determina la qualità del sistema
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network.
·bleepingcomputer.com·
Hackers breached a small Polish energy plant via private APN last year
BdThemes plugins supply-chain hack creates rogue WordPress admins
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts.
·bleepingcomputer.com·
BdThemes plugins supply-chain hack creates rogue WordPress admins
New StormEncryptor ransomware used by former Medusa affiliate
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
·bleepingcomputer.com·
New StormEncryptor ransomware used by former Medusa affiliate
AI, ora controlli preventivi sui modelli: il blocco di Astra, le regole di Trump
AI, ora controlli preventivi sui modelli: il blocco di Astra, le regole di Trump
Gli Usa procedono con cautela contro il rischio incontrollato dell'AI. OpenAI ha sospeso parte delle attività interne sul nuovo modello Astra, per pericoli cybersecurity. Il Governo Trump sperimenta un patto volontario per la sicurezza AI. Si cerca un difficile equilibrio tra sicurezza e innovazione, con conseguenze globali
·cybersecurity360.it·
AI, ora controlli preventivi sui modelli: il blocco di Astra, le regole di Trump
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
·bleepingcomputer.com·
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
When Credentials Are No Longer Enough: Device Trust in the AI Era
When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies.
·bleepingcomputer.com·
When Credentials Are No Longer Enough: Device Trust in the AI Era
Member of The Com sent to prison for blackmail, sextortion
Member of The Com sent to prison for blackmail, sextortion
A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide.
·bleepingcomputer.com·
Member of The Com sent to prison for blackmail, sextortion
LexisNexis shuts down services after suspicious activity on servers
LexisNexis shuts down services after suspicious activity on servers
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor.
·bleepingcomputer.com·
LexisNexis shuts down services after suspicious activity on servers
Valve notifies Steam hardware customers of a data breach
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics.
·bleepingcomputer.com·
Valve notifies Steam hardware customers of a data breach
InPost, mancano dati per la consegna. Ma è phishing!
InPost, mancano dati per la consegna. Ma è phishing!
Nella giornata odierna il team anti-frode D3Lab ha individuato un sito di phishing riproducente la grafica di InPost, note servizio di consegna basato su locker sparsi su tutto il territorio nazionale. Pagina di phishing principale Comunicando l'impossibilità di effettuare una consegna
·d3lab.net·
InPost, mancano dati per la consegna. Ma è phishing!
IT threat evolution in Q2 2026. Mobile statistics
IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
·securelist.com·
IT threat evolution in Q2 2026. Mobile statistics
IT threat evolution in Q2 2026. Non-mobile statistics
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
·securelist.com·
IT threat evolution in Q2 2026. Non-mobile statistics
Critical Progress LoadMaster flaw now actively exploited in attacks
Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
·bleepingcomputer.com·
Critical Progress LoadMaster flaw now actively exploited in attacks