Over Security

Over Security

Identity & Access Management e approccio Zero Trust: la governance degli accessi logici
Identity & Access Management e approccio Zero Trust: la governance degli accessi logici
Per proteggere l'identità digitale aziendale nell'era del lavoro distribuito la strategia più efficace per garantire una governance solida e scalabile degli accessi logici consiste nell’adottare un sistema di Identity & Access Management (IAM) unito a una filosofia Zero Trust. Ecco come e perché
·cybersecurity360.it·
Identity & Access Management e approccio Zero Trust: la governance degli accessi logici
Critical wp2shell WordPress flaws exploited to install webshells
Critical wp2shell WordPress flaws exploited to install webshells
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.
·bleepingcomputer.com·
Critical wp2shell WordPress flaws exploited to install webshells
Cyber security industriale, arriva l’iperammortamento: la roadmap in 4 fasi
Cyber security industriale, arriva l’iperammortamento: la roadmap in 4 fasi
La sicurezza informatica cessa di essere una voce di spesa dell'ufficio IT e diventa una condizione di continuità del business. Il Credito d'Imposta 4.0/5.0 lascia il posto all'iperammortamento, ecco quali vantaggi offre e perché non è un pranzo gratis. Ecco cosa deve fare chi guida la sicurezza in azienda
·cybersecurity360.it·
Cyber security industriale, arriva l’iperammortamento: la roadmap in 4 fasi
Closing the Identity Gaps in Critical Infrastructure Security
Closing the Identity Gaps in Critical Infrastructure Security
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems.
·bleepingcomputer.com·
Closing the Identity Gaps in Critical Infrastructure Security
Situation-Based SOC: Why Alerts Are the Wrong Unit of Work
Situation-Based SOC: Why Alerts Are the Wrong Unit of Work
Alerts are the unit of detection, not of work. Reorganizing the SOC around Situations and working toward zero queue changes where human judgment lands.
·binarydefense.com·
Situation-Based SOC: Why Alerts Are the Wrong Unit of Work
AI Act, dal 2 agosto cambiano gli obblighi di trasparenza dei sistemi di AI: ecco come
AI Act, dal 2 agosto cambiano gli obblighi di trasparenza dei sistemi di AI: ecco come
La Commissione europea ha pubblicato le linee guida definitive per aiutare fornitori e operatori dei sistemi di AI a rispettare gli obblighi di trasparenza imposti dall’art. 50 dell’AI Act che scatteranno dal prossimo 2 agosto 2026, l’unica scadenza importante rimasta valida indipendentemente dal Digital Omnibus. Vediamo meglio
·cybersecurity360.it·
AI Act, dal 2 agosto cambiano gli obblighi di trasparenza dei sistemi di AI: ecco come
Hugging Face violata da un agente AI: perché il primo attacco autonomo segna una svolta per la cybersecurity
Hugging Face violata da un agente AI: perché il primo attacco autonomo segna una svolta per la cybersecurity
Per anni l’idea di un attacco informatico condotto interamente da un agente di Intelligenza Artificiale è rimasta confinata ai laboratori di ricerca e alle presentazioni dei vendor. Oggi non è più così. La piattaforma Hugging Face, punto di riferimento mondiale per lo sviluppo e la distribuzione di modelli AI open source, ha confermato di essere …
·securityinfo.it·
Hugging Face violata da un agente AI: perché il primo attacco autonomo segna una svolta per la cybersecurity
Controllo degli accessi: la matematica nascosta dietro ogni login
Controllo degli accessi: la matematica nascosta dietro ogni login
Il controllo degli accessi rappresenta il cuore pulsante della sicurezza informatica, eppure molti amministratori ne sottovalutano la complessità e le implicazioni operative. Ecco come costruire strategie operative gestibili senza compromettere la produttività dei dipendenti
·cybersecurity360.it·
Controllo degli accessi: la matematica nascosta dietro ogni login
NIS2, l’articolo 17 esce dall’ombra: cosa cambia per gli accordi con i fornitori cyber
NIS2, l’articolo 17 esce dall’ombra: cosa cambia per gli accordi con i fornitori cyber
SOC, MDR, Vulnerability Assessment, Penetration Test, Red Teaming e Cyber Threat Intelligence implicano uno scambio bidirezionale di informazioni spesso molto sensibili. Le FAQ ACN chiariscono cosa sono gli accordi previsti dall’articolo 17, quando diventano necessari, con quali fornitori devono essere formalizzati e come devono essere comunicati
·cybersecurity360.it·
NIS2, l’articolo 17 esce dall’ombra: cosa cambia per gli accordi con i fornitori cyber
Patching WP2Shell in the dark using PAI
Patching WP2Shell in the dark using PAI
Will AI let me spend my time at the beach while patching a critical vulnerability in one of the most used CMS in the world? Yes it will. We recently released PAI, our AI Security Agent that acts as a Senior Security Specialist for a wide range of security tasks. For our WAAP (Web Application & API Protection) service WP2Shell was the perfect test run. WP2Shell dropped Friday night (CEST). By Saturday morning we had a virtual patch live on every WordPress site behind our WAAP: one shared rule, ab
·blog.sicuranext.com·
Patching WP2Shell in the dark using PAI
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
·bleepingcomputer.com·
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
·bleepingcomputer.com·
Microsoft shares manual fix for WSUS sync delays and timeouts
Windows LegacyHive zero-day flaw gets free, unofficial patches
Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
·bleepingcomputer.com·
Windows LegacyHive zero-day flaw gets free, unofficial patches
Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
We are presenting here our most complete analysis to date of the Pegasus spyware. This blog post builds on previous technical reports and forensic investigations by Amnesty International’s Security Lab. Significantly it also draws on previously unpublished internal NSO Group marketing material and internal technical material which was disclosed as part of a long-running civil […]
·securitylab.amnesty.org·
Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
Estée Lauder discloses data breach via Oracle E-Business flaw
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.
·bleepingcomputer.com·
Estée Lauder discloses data breach via Oracle E-Business flaw
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol.
·bleepingcomputer.com·
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
·bleepingcomputer.com·
SonicWall SMA1000 flaws exploited as zero-days to push custom malware