Over Security

Over Security

PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
PTC Inc. is warning of a critical vulnerability in Windchill and FlexPLM, widely used product lifecycle management (PLM) solutions, that could allow remote code execution.
·bleepingcomputer.com·
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack
Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack
The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI and claiming to have stolen data from hundreds of thousands of devices during the attack.
·bleepingcomputer.com·
Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack
FCC bans new routers made outside the USA over security risks
FCC bans new routers made outside the USA over security risks
The Federal Communications Commission has updated its Covered List to include all consumer routers made in foreign countries, banning the sale of new models in the U.S.
·bleepingcomputer.com·
FCC bans new routers made outside the USA over security risks
Kali Linux 2026.1 Release (2026 Theme & BackTrack Mode)
Kali Linux 2026.1 Release (2026 Theme & BackTrack Mode)
New year, new release - Kali 2026.1 is here! There is everything from a fresh coat of paint to a nod to our roots, with normal ongoing improvements. Building on from December’s 2025.4, the summary of the changelog: 2026 Theme Refresh - Our yearly theme refresh BackTrack Mode For Kali-Undercover - New mode celebrating BackTrack’s 20th anniversary Kali’s 13th Birthday Event - A little community event New Tools - 8 new programs 2026 Theme Refresh As with previous 20xx.1 releases, this major update brings our annual theme refresh, a long-standing tradition that keeps the Kali Linux interface as modern and innovative. This year’s release unveils a brand-new theme from the moment you boot. Everything from the boot menu, installer to the login display, and a fresh set of desktop wallpapers.
·kali.org·
Kali Linux 2026.1 Release (2026 Theme & BackTrack Mode)
API sotto attacco: la sicurezza dell’AI passa dall’infrastruttura applicativa
API sotto attacco: la sicurezza dell’AI passa dall’infrastruttura applicativa
Akamai ha appena rilasciato il suo report “2026 Apps, API, and DDoS State of the Internet” dove viene messo in evidenza come la crescita dell’intelligenza artificiale stia ridefinendo le priorità della sicurezza applicativa. Il punto centrale è che le API, diventate il tessuto connettivo dei sistemi AI, si stanno trasformando nella principale superficie di attacco …
·securityinfo.it·
API sotto attacco: la sicurezza dell’AI passa dall’infrastruttura applicativa
Reati informatici e punibilità in Italia: un sistema “aperto” non è reato
Reati informatici e punibilità in Italia: un sistema “aperto” non è reato
Secondo la giurisprudenza italiana vigente, l’accesso a sistemi informatici non protetti da “misure di sicurezza idonee” non costituisce reato penale. È una distinzione fondamentale tra “introduzione” e “intrusione” che ha implicazioni profonde per organizzazioni, sviluppatori e cittadini digitali. Ecco quali
·cybersecurity360.it·
Reati informatici e punibilità in Italia: un sistema “aperto” non è reato
Recensione pCloud 2026: Privacy svizzera e storage a vita
Recensione pCloud 2026: Privacy svizzera e storage a vita
Scegli pCloud storage sicuro con piani per famiglie e business: risparmia sui canoni mensili con la privacy svizzera e 10TB di spazio a vita.
·cybersecurity360.it·
Recensione pCloud 2026: Privacy svizzera e storage a vita
Claudy Day: quando la prompt injection esfiltra dati riservati
Claudy Day: quando la prompt injection esfiltra dati riservati
Claudy Day rappresenta un caso concreto di attacco moderno contro i sistemi AI, basato sulla combinazione di fiducia, manipolazione del linguaggio e abuso di funzionalità legittime. Ecco tutti i dettagli tecnici e i consigli sulle contromisure più adatte per mitigare il rischio
·cybersecurity360.it·
Claudy Day: quando la prompt injection esfiltra dati riservati
HackerOne discloses employee data breach after Navia hack
HackerOne discloses employee data breach after Navia hack
Bug bounty platform HackerOne is notifying hundreds of employees that their data was stolen after attackers hacked Navia, one of its U.S. benefits administrators.
·bleepingcomputer.com·
HackerOne discloses employee data breach after Navia hack
Zero Trust: Bridging the Gap Between Authentication and Trust
Zero Trust: Bridging the Gap Between Authentication and Trust
Passing MFA doesn't mean a session is safe, attackers can hijack tokens and bypass identity checks. Specops Software explains why Zero Trust must verify both user identity and device health.
·bleepingcomputer.com·
Zero Trust: Bridging the Gap Between Authentication and Trust
Yanluowang ransomware access broker gets 81 months in prison
Yanluowang ransomware access broker gets 81 months in prison
A Russian national was sentenced to nearly 7 years in prison after pleading guilty to acting as an initial access broker (IAB) for Yanluowang ransomware attacks.
·bleepingcomputer.com·
Yanluowang ransomware access broker gets 81 months in prison
Cyber attacchi, Italia tra i Paesi più colpiti: ma quanto tempo serve alle aziende per ripartire?
Cyber attacchi, Italia tra i Paesi più colpiti: ma quanto tempo serve alle aziende per ripartire?
In uno scenario in cui gli attacchi cyber sono sempre più frequenti, la vera differenza non è tra chi viene colpito e chi no, ma tra chi riesce a ripartire rapidamente e chi rimane fermo giorni o settimane. È nella capacità di conoscere e testare i tempi di ripartenza che si misura la maturità cyber
·cybersecurity360.it·
Cyber attacchi, Italia tra i Paesi più colpiti: ma quanto tempo serve alle aziende per ripartire?