Over Security

Over Security

Signed software abused to deploy antivirus-killing scripts
Signed software abused to deploy antivirus-killing scripts
A digitally signed adware tool has deployed payloads running with SYSTEM privileges that disabled antivirus protections on thousands of endpoints, some in the educational, utilities, government, and healthcare sectors.
·bleepingcomputer.com·
Signed software abused to deploy antivirus-killing scripts
Hackerati i Pc di varie banche: ma è un problema di modello di sicurezza
Hackerati i Pc di varie banche: ma è un problema di modello di sicurezza
Un criminale, arrestato dalla Polizia, è riuscito ad installare dispositivi sui computer di un istituto di credito, intercettando il traffico dati e rubando credenziali di accesso dei clienti ai sistemi bancari. Ecco come sono stati hackerati i Pc di più banche e come mitigare il rischio
·cybersecurity360.it·
Hackerati i Pc di varie banche: ma è un problema di modello di sicurezza
Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest
Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest
Microsoft has awarded $2.3 million to security researchers after receiving nearly 700 submissions during this year's Zero Day Quest hacking contest.
·bleepingcomputer.com·
Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest
Attività promozionali, l’Agenzia assicurativa è titolare del trattamento: la sanzione privacy
Attività promozionali, l’Agenzia assicurativa è titolare del trattamento: la sanzione privacy
Il Garante privacy ha sanzionato un’agenzia assicurativa che, ritenendo erroneamente di agire quale responsabile del trattamento per conto della Compagnia mandante, ha inviato e-mail promozionali in assenza di una propria informativa e autonomo consenso. Ecco gli insegnamenti da trarre
·cybersecurity360.it·
Attività promozionali, l’Agenzia assicurativa è titolare del trattamento: la sanzione privacy
QR code scam e ingegneria sociale: come evolvono le truffe digitali
QR code scam e ingegneria sociale: come evolvono le truffe digitali
Dai falsi avvisi di violazione stradale ai QR code malevoli: l’attacco si sposta sul mobile e sfrutta fiducia, urgenza e automatismi cognitivi. Ecco l'analisi tecnica, i modelli di attacco e le strategie di difesa
·cybersecurity360.it·
QR code scam e ingegneria sociale: come evolvono le truffe digitali
CISA flags Windows Task Host vulnerability as exploited in attacks
CISA flags Windows Task Host vulnerability as exploited in attacks
CISA warned U.S. government agencies to secure their systems against a Windows Task Host privilege escalation vulnerability that could allow attackers to gain SYSTEM privileges.
·bleepingcomputer.com·
CISA flags Windows Task Host vulnerability as exploited in attacks
OpenAI svela GPT-5.4-Cyber: ecco l’approccio graduale all’AI applicata alla sicurezza
OpenAI svela GPT-5.4-Cyber: ecco l’approccio graduale all’AI applicata alla sicurezza
Dopo l'anteprima di Anthropic Claude Mythos, arriva GPT-5.4-Cyber con cui OpenAI, usando un approccio dideployment iterativo e controllato che diventa punto di riferimento utile per l'intera industria, espande il proprio programma Trusted Access for Cyber (TAC)
·cybersecurity360.it·
OpenAI svela GPT-5.4-Cyber: ecco l’approccio graduale all’AI applicata alla sicurezza
LmCompatibilityLevel and the PDC Trap
LmCompatibilityLevel and the PDC Trap
LmCompatibilityLevel determines which NTLM and LM authentication protocols are accepted for inbound and outbound connections for Windows machines. On domain controllers, the minimum recommended set…
·decoder.cloud·
LmCompatibilityLevel and the PDC Trap
Rolling Networks: Securing the Transportation Sector
Rolling Networks: Securing the Transportation Sector
Modern trucks are rolling networks packed with sensors, connectivity, and attack surfaces, creating new cyber risks. NMFTA's Cybersecurity Conference brings industry leaders together to tackle emerging threats in transportation.
·bleepingcomputer.com·
Rolling Networks: Securing the Transportation Sector
MACOBOX is back from San Francisco
MACOBOX is back from San Francisco
AI agents, on-premise inference, IoT scanning and PDF reports: a roundup of the latest features
·mandomat.github.io·
MACOBOX is back from San Francisco
Threat landscape for industrial automation systems in Q4 2025
Threat landscape for industrial automation systems in Q4 2025
The report contains industrial threat statistics for Q4 2025. It covers various infection vectors and malware types, as well as regional statistics and statistics by industry.
·securelist.com·
Threat landscape for industrial automation systems in Q4 2025
Cybersecurity e ROI
Cybersecurity e ROI
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
·certego.net·
Cybersecurity e ROI
Aggiornamenti Microsoft aprile 2026: corretta una zero-day in SharePoint già sfruttata
Aggiornamenti Microsoft aprile 2026: corretta una zero-day in SharePoint già sfruttata
Il Patch Tuesday di aprile 2026 corregge 165 vulnerabilità tra cui una zero-day su SharePoint già attivamente sfruttata, l'exploit BlueHammer su Microsoft Defender rilasciato pubblicamente da un ricercatore scontento e una falla critica nel servizio IKE di Windows. Urgente l’updati dei propri sistemi
·cybersecurity360.it·
Aggiornamenti Microsoft aprile 2026: corretta una zero-day in SharePoint già sfruttata
Unpacking the Unpackable: Malformed APKs as an Anti-Analysis Technique
Unpacking the Unpackable: Malformed APKs as an Anti-Analysis Technique
This article explores the most common malformation techniques in the wild and introduces Malfixer, a new open-source tool developed by Cleafy's TIR team to detect and repair malformed APKs, enabling more effective malware analysis and response.
·cleafy.com·
Unpacking the Unpackable: Malformed APKs as an Anti-Analysis Technique
The n8n n8mare: How threat actors are misusing AI workflow automation
The n8n n8mare: How threat actors are misusing AI workflow automation
Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026.
·blog.talosintelligence.com·
The n8n n8mare: How threat actors are misusing AI workflow automation
La Cina è in vantaggio sui robot umanoidi
La Cina è in vantaggio sui robot umanoidi
AgiBot, Unitree, UBTech e non solo: mentre negli Stati Uniti si attende l’arrivo di Optimus di Tesla, le società cinesi di robotica sono pronte a invadere il mercato, puntando soprattutto sulle applicazioni industriali
·guerredirete.it·
La Cina è in vantaggio sui robot umanoidi
La sicurezza delle interfacce cervello-computer
La sicurezza delle interfacce cervello-computer
Il mercato delle interfacce cervello-computer (BCI) si condensa di concorrenti e si addensa di nubi. Uscite dai laboratori, queste interfacce si stanno guadagnando un’utilità pratica che pone interrogativi tecnici, etici e normativi
·cybersecurity360.it·
La sicurezza delle interfacce cervello-computer