Over Security

Over Security

The time of much patching is coming
The time of much patching is coming
In this week’s newsletter, Martin reflects on what the next iteration of AI tools means for vulnerability discovery and our ability to manage large-scale patch releases.
·blog.talosintelligence.com·
The time of much patching is coming
Fragnesia, la nuova falla nel kernel Linux che regala privilegi di root: come difendersi
Fragnesia, la nuova falla nel kernel Linux che regala privilegi di root: come difendersi
Una terza vulnerabilità critica in meno di tre settimane colpisce il kernel Linux. Fragnesia consente a qualsiasi utente locale senza privilegi di ottenere accesso root corrompendo la page cache del kernel. Il PoC è già pubblico. Ecco l'analisi tecnica, le distribuzioni coinvolte e le indicazioni operative per mitigare il rischio
·cybersecurity360.it·
Fragnesia, la nuova falla nel kernel Linux che regala privilegi di root: come difendersi
Assunzioni nella cyber: pesa il divario di competenze nell’era AI
Assunzioni nella cyber: pesa il divario di competenze nell’era AI
Il Global Cybersecurity Skills Gap Report 2026 di Fortinet analizza il persistente gap di competenze nella sicurezza informatica nell’attuale panorama di rischio in continua evoluzione, alla luce dei progressi dell'AI. Ecco l'ombra che si allunga sulle assunzioni in cyber security
·cybersecurity360.it·
Assunzioni nella cyber: pesa il divario di competenze nell’era AI
Quando condividere una notizia diventa un trattamento dati: ecco le responsabilità concrete
Quando condividere una notizia diventa un trattamento dati: ecco le responsabilità concrete
Chi prende una notizia, la modifica e la rilancia online, anche senza intenzione di danneggiare, può esporsi a responsabilità penali per diffamazione e, in molti casi, a responsabilità ai sensi del GDPR. Ecco perché il soggetto assume il ruolo di titolare del trattamento e deve rispettare regole precise
·cybersecurity360.it·
Quando condividere una notizia diventa un trattamento dati: ecco le responsabilità concrete
La mutazione del GRU nella dottrina russa della guerra cibernetica
La mutazione del GRU nella dottrina russa della guerra cibernetica
L’eclissi di Icaro e la fabbrica degli ufficiali: riorganizzazione strutturale delle potenze avversarie - con la Russia del GRU e la Cina in prima linea - volta a riscrivere le regole della proiezione del potere globale attraverso una guerra invisibile, ma totale. Ecco la mutazione genetica della sovranità digitale
·cybersecurity360.it·
La mutazione del GRU nella dottrina russa della guerra cibernetica
Classificare o non classificare, questo è il dilemma!
Classificare o non classificare, questo è il dilemma!
Classificare gli asset è un passaggio indispensabile soprattutto negli ambienti sempre più virtualizzati e negli ecosistemi complessi in cui possono intervenire più soggetti, al fine di proteggere e creare il valore della sicurezza cyber. Tutto sta nel farlo con metodo
·cybersecurity360.it·
Classificare o non classificare, questo è il dilemma!
Data manipulation, l’attacco che non si vede: minaccia strutturale dell’industria connessa
Data manipulation, l’attacco che non si vede: minaccia strutturale dell’industria connessa
A differenza del ransomware, che si annuncia con una nota di riscatto, la Data Manipulation può restare invisibile per settimane o mesi. Ecco perché è la minaccia numero uno rilevata nei sistemi OT e IoT delle organizzazioni italiane e perché per il manifatturiero italiano la visibilità OT non è un investimento opzionale
·cybersecurity360.it·
Data manipulation, l’attacco che non si vede: minaccia strutturale dell’industria connessa
1-15 April 2026 Cyber Attacks Timeline
1-15 April 2026 Cyber Attacks Timeline
The first timeline of April 2026 brings an evolution in terms of methodology: from now on I will map the initial access techniques with the MITRE ATT&CK model. I also decided to merge the cate…
·hackmageddon.com·
1-15 April 2026 Cyber Attacks Timeline
Q1 2026 Cyber Attack Statistics
Q1 2026 Cyber Attack Statistics
This post aggregates the statistics created from the cyber attacks timelines published in the first quarter of 2026.
·hackmageddon.com·
Q1 2026 Cyber Attack Statistics
Identity Is the New Perimeter: Access, Authentication, and Control That Actually Hold Up
Identity Is the New Perimeter: Access, Authentication, and Control That Actually Hold Up
Part 3 of a series on creating information security policies. Attackers don’t break in…they log in. That’s a bit of a dramatic exaggeration, and it seems cliché, but it’s not really too far off. Consider the 2022 Uber breach. The attacker didn’t exploit a sophisticated vulnerability; they obtained a contractor’s credentials and then bombarded the user with MFA push requests until one was approved. That single moment of fatigue opened the door to internal systems and broader access. Or look a
·secjuice.com·
Identity Is the New Perimeter: Access, Authentication, and Control That Actually Hold Up
For The Dogs
For The Dogs
An introduction to the canine intelligence cell, a volunteer investigative effort focused on exposing the criminal networks exploiting dogs through trafficking, legal loopholes, fraud, violence, and organised abuse.
·secjuice.com·
For The Dogs
April 2026 Cyber Attacks Statistics
April 2026 Cyber Attacks Statistics
In April 2026, Cyber Crime continued to lead the Motivations, once again ahead of Cyber Espionage. Cyber Warfare took the third place, ahead of Hacktivism.
·hackmageddon.com·
April 2026 Cyber Attacks Statistics
Websites with an undefined trust level: avoiding the trap
Websites with an undefined trust level: avoiding the trap
We explain what suspicious websites are and how to distinguish a safe site from a fraudulent one. A new category in Kaspersky solutions: we’re sharing global statistics on untrusted site detection.
·securelist.com·
Websites with an undefined trust level: avoiding the trap
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
Kaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot. We attribute this activity to OceanLotus APT.
·securelist.com·
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
Exploits and vulnerabilities in Q1 2026
Exploits and vulnerabilities in Q1 2026
This report provides statistical data on published vulnerabilities and exploits we researched during Q1 2026. It also includes summary data on the use of C2 frameworks in APT attacks.
·securelist.com·
Exploits and vulnerabilities in Q1 2026
CVE-2025-68670: discovering an RCE vulnerability in xrdp
CVE-2025-68670: discovering an RCE vulnerability in xrdp
During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.
·securelist.com·
CVE-2025-68670: discovering an RCE vulnerability in xrdp
State of ransomware in 2026
State of ransomware in 2026
Kaspersky researchers are sharing insights into the main ransomware trends for 2026: EDR killers on the rise, switching from data encryption to data leaks, and more.
·securelist.com·
State of ransomware in 2026
Kimsuky targets organizations with PebbleDash-based tools
Kimsuky targets organizations with PebbleDash-based tools
Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.
·securelist.com·
Kimsuky targets organizations with PebbleDash-based tools
The Browser Under Siege: Q1 2026 Phishing Report
The Browser Under Siege: Q1 2026 Phishing Report
Across Q1 2026, PIXM detected and analyzed over 75 distinct phishing campaigns. What stands out is not the volume — it is how rapidly the campaigns matured across the quarter. January's attacks relied on credential harvesting forms and consumer brand impersonation. By March, the same threat surface featured 100+ phishing pages hosted on Microsoft's own Azure infrastructure, comprehensive MFA bypass against authenticator apps and FIDO tokens, and fully functional proxy-based site clones.
·pixmsecurity.com·
The Browser Under Siege: Q1 2026 Phishing Report
Cybersecurity “intro”
Cybersecurity “intro”
Come ho raccontato qualche giorno fa su altri canali ho iniziato a lavorare su una serie di video + articoli tecnici dedicati esclusivamente a chi vuole iniziare a lavorare nel contesto cybersecuri…
·roccosicilia.com·
Cybersecurity “intro”
Info per i supporter
Info per i supporter
Cari supporter – ovvero coloro che oltre a leggere i miei post e vedere i video hanno anche deciso di sostenere il mio progetto di divulgazione – ho un aggiornamento strutturale da farv…
·roccosicilia.com·
Info per i supporter