Found 34370 bookmarks
Newest
CISA urges immediate action on actively exploited Fortinet flaws
CISA urges immediate action on actively exploited Fortinet flaws
CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform.
·bleepingcomputer.com·
CISA urges immediate action on actively exploited Fortinet flaws
Coca-Cola says Fairlife ransomware attack halts US dairy production
Coca-Cola says Fairlife ransomware attack halts US dairy production
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.
·bleepingcomputer.com·
Coca-Cola says Fairlife ransomware attack halts US dairy production
Claude Chrome extension flaw lets malicious extensions trigger AI actions
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
·bleepingcomputer.com·
Claude Chrome extension flaw lets malicious extensions trigger AI actions
New OkoBot framework deploys 20 payloads to steal data, crypto
New OkoBot framework deploys 20 payloads to steal data, crypto
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.
·bleepingcomputer.com·
New OkoBot framework deploys 20 payloads to steal data, crypto
Begun, the Patch Wars have
Begun, the Patch Wars have
Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.
·blog.talosintelligence.com·
Begun, the Patch Wars have
Shadow AI in azienda: come scoprirla, classificarla e governarla
Shadow AI in azienda: come scoprirla, classificarla e governarla
Secondo l'Osservatorio del Politecnico di Milano, un quinto degli utenti Ai generativa lo fa esclusivamente attraverso soluzioni aziendali approvate, mentre supera la metà dei dipendenti chi userebbe strumenti non autorizzati quando manca l’alternativa ufficiale. Ecco il fenomeno della Shadow AI in azienda, tutt’altro che marginale
·cybersecurity360.it·
Shadow AI in azienda: come scoprirla, classificarla e governarla
H1 2026 Cyber Attacks Statistics
H1 2026 Cyber Attacks Statistics
H1 2026 cyber attack data: 1,071 incidents, 68.7% financially motivated, malware in 40.5% of cases. Full breakdown by sector, vector & access method.
·hackmageddon.com·
H1 2026 Cyber Attacks Statistics
H1 2026 Cyber Attacks Statistics Infographic
H1 2026 Cyber Attacks Statistics Infographic
H1 2026 cyber attack data: 1,071 incidents, 68.7% financially motivated, malware in 40.5% of cases. Full breakdown by sector, vector & access method.
·hackmageddon.com·
H1 2026 Cyber Attacks Statistics Infographic
AI Agents Broke the Security Playbook. Here's What Replaces It.
AI Agents Broke the Security Playbook. Here's What Replaces It.
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments.
·bleepingcomputer.com·
AI Agents Broke the Security Playbook. Here's What Replaces It.
23andMe to pay $18 million in new genetics data breach settlement
23andMe to pay $18 million in new genetics data breach settlement
Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data.
·bleepingcomputer.com·
23andMe to pay $18 million in new genetics data breach settlement
Threat Hunting and Defending #2: frameworks (p1)
Threat Hunting and Defending #2: frameworks (p1)
Intro Nel primo post di questa serie ho riportato soprattutto la teoria della disciplina e l’estrema sintesi è che il Threat Hunting è un processo strutturato utile ad identificare e mitigare…
·roccosicilia.com·
Threat Hunting and Defending #2: frameworks (p1)
Scattered Spider members behind TfL hack get five years in prison
Scattered Spider members behind TfL hack get five years in prison
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.
·bleepingcomputer.com·
Scattered Spider members behind TfL hack get five years in prison
Windows 11 24H2 Home and Pro reach end of support in 90 days
Windows 11 24H2 Home and Pro reach end of support in 90 days
Microsoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months.
·bleepingcomputer.com·
Windows 11 24H2 Home and Pro reach end of support in 90 days
Zoom, scoperta una vulnerabilità che apre le porte all’account takeover su Windows
Zoom, scoperta una vulnerabilità che apre le porte all’account takeover su Windows
È stata corretta una vulnerabilità critica nel client Windows di Zoom che potrebbe consentire a un attaccante non autenticato di violare gli account via rete. Coinvolti anche VDI Client e Meeting SDK: ecco impatti, superficie di attacco e contromisure per i team di sicurezza aziendali
·cybersecurity360.it·
Zoom, scoperta una vulnerabilità che apre le porte all’account takeover su Windows
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application.
·bleepingcomputer.com·
CISA orders feds to patch actively exploited Oracle flaw by Saturday
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT.
·bleepingcomputer.com·
Russian hackers trojanize WebEx, Zoom apps to push Starland malware