Over Security

Over Security

Why AI SOC Agents Need Context to Investigate Alerts
Why AI SOC Agents Need Context to Investigate Alerts
AI SOC agents need more than an alert to investigate threats. See how telemetry, asset data, identities and threat intelligence help explain each verdict.
·sekoia.com·
Why AI SOC Agents Need Context to Investigate Alerts
Why One SOC Agent Isn’t Enough for Every Customer
Why One SOC Agent Isn’t Enough for Every Customer
One SOC can protect dozens of customers, but every customer works differently. See how multi-level agents give security teams one shared way to investigate alerts, while keeping the local context needed to make the right call.
·sekoia.com·
Why One SOC Agent Isn’t Enough for Every Customer
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
This article details how TDR pivoted from a forum advertisement to identify confirmed operator infrastructure, analyzes the Exvicy infection chain, and provides code evidence establishing that this emerging MaaS is a direct copycat of the adopted ErrTraffic framework.
·sekoia.com·
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
AI in the SOC: EU AI Act and Technology Sovereignty
AI in the SOC: EU AI Act and Technology Sovereignty
An analysis of how Europe’s emerging AI and cybersecurity framework is shaping trust, control and technology sovereignty in the SOC.
·sekoia.com·
AI in the SOC: EU AI Act and Technology Sovereignty
Allarme russo in Europa, il caso Kaspersky-SIC riapre il nodo della fiducia nell’intelligence
Allarme russo in Europa, il caso Kaspersky-SIC riapre il nodo della fiducia nell’intelligence
Gli attuali allarmi europei sulla minaccia ibrida russa e il caso Kaspersky-SIC non hanno un collegamento dimostrato. Ma letti insieme pongono una questione più ampia: quanto sono state esposte le catene tecnologiche e informative dell’intelligence occidentale e quali garanzie esistono oggi sulla loro integrità?
·cybersecurity360.it·
Allarme russo in Europa, il caso Kaspersky-SIC riapre il nodo della fiducia nell’intelligence
Ryuk ransomware member sentenced to 24 months in prison
Ryuk ransomware member sentenced to 24 months in prison
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.
·bleepingcomputer.com·
Ryuk ransomware member sentenced to 24 months in prison
Attacchi cyber iraniani contro navi Usa: il conflitto può estendersi al dominio marittimo
Attacchi cyber iraniani contro navi Usa: il conflitto può estendersi al dominio marittimo
Le autorità statunitensi non hanno confermato se dietro gli attacchi vi sia l'Iran oppure altri attori statali, tra cui vengono citati come possibili Russia e Cina. Ma gli attacchi informatici alle navi Usa, mentre transitavano nello Stretto di Gibilterra nel mese di agosto, comportano un rischio tecnico legato a questi attacchi non trascurabile
·cybersecurity360.it·
Attacchi cyber iraniani contro navi Usa: il conflitto può estendersi al dominio marittimo
RemControl: AI Built the Overlays. Victims Lose their PINs
RemControl: AI Built the Overlays. Victims Lose their PINs
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
·group-ib.com·
RemControl: AI Built the Overlays. Victims Lose their PINs
Il dato tra GDPR e AI Act: filiera, lineage e accountability
Il dato tra GDPR e AI Act: filiera, lineage e accountability
Dalla raccolta al modello, i dati attraversano fonti, sistemi, trasformazioni e riusi. GDPR e AI Act richiedono una governance capace non solo di mappare i trattamenti, ma di ricostruire e dimostrare la storia del dato
·cybersecurity360.it·
Il dato tra GDPR e AI Act: filiera, lineage e accountability
Rogue external MFA providers can steal passwords during logins
Rogue external MFA providers can steal passwords during logins
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts.
·bleepingcomputer.com·
Rogue external MFA providers can steal passwords during logins
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.
·bleepingcomputer.com·
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Chinese hackers exploit multiple technologies to steal govt data
Chinese hackers exploit multiple technologies to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases.
·bleepingcomputer.com·
Chinese hackers exploit multiple technologies to steal govt data
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
Flashpoint analysts examine Process Parameter Poisoning—a novel EDR evasion technique we validated in Rust—and detail how abusing undocumented process parameters allows attackers to inject code and bypass standard security products.
·flashpoint.io·
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
·bleepingcomputer.com·
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
New ClosedQuorum Windows malware uses AI for attack decisions
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.
·bleepingcomputer.com·
New ClosedQuorum Windows malware uses AI for attack decisions
Reducing shadow IT visibility gaps with Wazuh
Reducing shadow IT visibility gaps with Wazuh
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps.
·bleepingcomputer.com·
Reducing shadow IT visibility gaps with Wazuh
Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset
Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset
La gestione del rischio non può prescindere da una visibilità completa dei sistemi IT/OT. Il progetto sviluppato da Lutech per un'importante azienda manifatturiera mostra come monitoraggio passivo, Cyber Asset Management e Continuous Threat Exposure Management trasformano l'inventario degli asset in strumento strategico di cyber resilience
·cybersecurity360.it·
Cyber Asset Management: perché la resilienza inizia dalla conoscenza degli asset
Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio
Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio
Un solo errore dell’algoritmo può bastare per spingere gli analisti a ricontrollare ogni decisione automatica. Ma la sfiducia ha un costo: rallenta l’incident response e può offrire agli attaccanti tempo prezioso. Per i CISO, progettare l’automazione significa quindi progettare anche la fiducia di chi dovrà utilizzarla
·cybersecurity360.it·
Automazione nella cyber security: quando non fidarsi della macchina diventa un rischio
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
·bleepingcomputer.com·
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California
Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California
Con ponderazione ma con urgenza, il 18 settembre 2026 il governatore della California Gavin Newsom ha firmato l’ordine esecutivo N-9-26 dedicato ai modelli di frontiera. Ecco cosa comporta in termini di supervisione indipendente e sicurezza dei sistemi di intelligenza artificiale e le differenze con la SB 1047 respinta nel 2024
·cybersecurity360.it·
Supervisione indipendente e sicurezza dei sistemi di AI: cosa cambia con l’ordine esecutivo della California
PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco
PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco
Niente malware sui PC, nessun file cifrato e nessun processo sospetto da intercettare. In un incidente analizzato da Kaspersky, gli attaccanti hanno utilizzato le Group Policy di Active Directory per colpire contemporaneamente l’intero dominio, trasformando uno degli strumenti più fidati dell’amministrazione Windows in un meccanismo di estorsione
·cybersecurity360.it·
PAYLOAD, il ransomware che trasforma Active Directory in strumento d’attacco