Over Security

Over Security

Attività promozionali, l’Agenzia assicurativa è titolare del trattamento: la sanzione privacy
Attività promozionali, l’Agenzia assicurativa è titolare del trattamento: la sanzione privacy
Il Garante privacy ha sanzionato un’agenzia assicurativa che, ritenendo erroneamente di agire quale responsabile del trattamento per conto della Compagnia mandante, ha inviato e-mail promozionali in assenza di una propria informativa e autonomo consenso. Ecco gli insegnamenti da trarre
·cybersecurity360.it·
Attività promozionali, l’Agenzia assicurativa è titolare del trattamento: la sanzione privacy
QR code scam e ingegneria sociale: come evolvono le truffe digitali
QR code scam e ingegneria sociale: come evolvono le truffe digitali
Dai falsi avvisi di violazione stradale ai QR code malevoli: l’attacco si sposta sul mobile e sfrutta fiducia, urgenza e automatismi cognitivi. Ecco l'analisi tecnica, i modelli di attacco e le strategie di difesa
·cybersecurity360.it·
QR code scam e ingegneria sociale: come evolvono le truffe digitali
CISA flags Windows Task Host vulnerability as exploited in attacks
CISA flags Windows Task Host vulnerability as exploited in attacks
CISA warned U.S. government agencies to secure their systems against a Windows Task Host privilege escalation vulnerability that could allow attackers to gain SYSTEM privileges.
·bleepingcomputer.com·
CISA flags Windows Task Host vulnerability as exploited in attacks
OpenAI svela GPT-5.4-Cyber: ecco l’approccio graduale all’AI applicata alla sicurezza
OpenAI svela GPT-5.4-Cyber: ecco l’approccio graduale all’AI applicata alla sicurezza
Dopo l'anteprima di Anthropic Claude Mythos, arriva GPT-5.4-Cyber con cui OpenAI, usando un approccio dideployment iterativo e controllato che diventa punto di riferimento utile per l'intera industria, espande il proprio programma Trusted Access for Cyber (TAC)
·cybersecurity360.it·
OpenAI svela GPT-5.4-Cyber: ecco l’approccio graduale all’AI applicata alla sicurezza
LmCompatibilityLevel and the PDC Trap
LmCompatibilityLevel and the PDC Trap
LmCompatibilityLevel determines which NTLM and LM authentication protocols are accepted for inbound and outbound connections for Windows machines. On domain controllers, the minimum recommended set…
·decoder.cloud·
LmCompatibilityLevel and the PDC Trap
Rolling Networks: Securing the Transportation Sector
Rolling Networks: Securing the Transportation Sector
Modern trucks are rolling networks packed with sensors, connectivity, and attack surfaces, creating new cyber risks. NMFTA's Cybersecurity Conference brings industry leaders together to tackle emerging threats in transportation.
·bleepingcomputer.com·
Rolling Networks: Securing the Transportation Sector
MACOBOX is back from San Francisco
MACOBOX is back from San Francisco
AI agents, on-premise inference, IoT scanning and PDF reports: a roundup of the latest features
·mandomat.github.io·
MACOBOX is back from San Francisco
Threat landscape for industrial automation systems in Q4 2025
Threat landscape for industrial automation systems in Q4 2025
The report contains industrial threat statistics for Q4 2025. It covers various infection vectors and malware types, as well as regional statistics and statistics by industry.
·securelist.com·
Threat landscape for industrial automation systems in Q4 2025
Cybersecurity e ROI
Cybersecurity e ROI
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
·certego.net·
Cybersecurity e ROI
Aggiornamenti Microsoft aprile 2026: corretta una zero-day in SharePoint già sfruttata
Aggiornamenti Microsoft aprile 2026: corretta una zero-day in SharePoint già sfruttata
Il Patch Tuesday di aprile 2026 corregge 165 vulnerabilità tra cui una zero-day su SharePoint già attivamente sfruttata, l'exploit BlueHammer su Microsoft Defender rilasciato pubblicamente da un ricercatore scontento e una falla critica nel servizio IKE di Windows. Urgente l’updati dei propri sistemi
·cybersecurity360.it·
Aggiornamenti Microsoft aprile 2026: corretta una zero-day in SharePoint già sfruttata
Unpacking the Unpackable: Malformed APKs as an Anti-Analysis Technique
Unpacking the Unpackable: Malformed APKs as an Anti-Analysis Technique
This article explores the most common malformation techniques in the wild and introduces Malfixer, a new open-source tool developed by Cleafy's TIR team to detect and repair malformed APKs, enabling more effective malware analysis and response.
·cleafy.com·
Unpacking the Unpackable: Malformed APKs as an Anti-Analysis Technique
The n8n n8mare: How threat actors are misusing AI workflow automation
The n8n n8mare: How threat actors are misusing AI workflow automation
Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026.
·blog.talosintelligence.com·
The n8n n8mare: How threat actors are misusing AI workflow automation
La Cina è in vantaggio sui robot umanoidi
La Cina è in vantaggio sui robot umanoidi
AgiBot, Unitree, UBTech e non solo: mentre negli Stati Uniti si attende l’arrivo di Optimus di Tesla, le società cinesi di robotica sono pronte a invadere il mercato, puntando soprattutto sulle applicazioni industriali
·guerredirete.it·
La Cina è in vantaggio sui robot umanoidi
La sicurezza delle interfacce cervello-computer
La sicurezza delle interfacce cervello-computer
Il mercato delle interfacce cervello-computer (BCI) si condensa di concorrenti e si addensa di nubi. Uscite dai laboratori, queste interfacce si stanno guadagnando un’utilità pratica che pone interrogativi tecnici, etici e normativi
·cybersecurity360.it·
La sicurezza delle interfacce cervello-computer
Microsoft adds Windows protections for malicious Remote Desktop files
Microsoft adds Windows protections for malicious Remote Desktop files
Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (.rdp) files, adding warnings and disabling risky shared resources by default.
·bleepingcomputer.com·
Microsoft adds Windows protections for malicious Remote Desktop files
Crypto-exchange Kraken extorted by hackers after insider breach
Crypto-exchange Kraken extorted by hackers after insider breach
The Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data.
·bleepingcomputer.com·
Crypto-exchange Kraken extorted by hackers after insider breach
Patch Tuesday, April 2026 Edition
Patch Tuesday, April 2026 Edition
Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed "BlueHammer." Separately, Google Chrome fixed its…
·krebsonsecurity.com·
Patch Tuesday, April 2026 Edition