Found 35917 bookmarks
Newest
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them.
·bleepingcomputer.com·
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
Rapporto Anthropic: l’AI non inventa il cybercrime, lo rende industriale
Rapporto Anthropic: l’AI non inventa il cybercrime, lo rende industriale
Il nuovo rapporto Anthropic mostra come l’AI stia riducendo tempi, costi e competenze necessari per condurre operazioni offensive complesse. Cybercrime, frodi, propaganda, sorveglianza e ricerca di vulnerabilità diventano workflow automatizzati e scalabili, gestibili da gruppi sempre più piccoli
·cybersecurity360.it·
Rapporto Anthropic: l’AI non inventa il cybercrime, lo rende industriale
AI Act, il controllo umano può diventare un’illusione: cosa insegna HAL 9000
AI Act, il controllo umano può diventare un’illusione: cosa insegna HAL 9000
Citando "2001: odissea nello spazio", HAL 9000 mostra il rischio di una supervisione solo apparente: l’uomo può restare nel processo e, allo stesso tempo, non avere informazioni, competenze o poteri reali per governarlo. È questo che l’articolo 14 dell’AI Act prova a evitare imponendo un controllo umano effettivo e concretamente esercitabile
·cybersecurity360.it·
AI Act, il controllo umano può diventare un’illusione: cosa insegna HAL 9000
Revolut discloses data breach exposing financial info, passports
Revolut discloses data breach exposing financial info, passports
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.
·bleepingcomputer.com·
Revolut discloses data breach exposing financial info, passports
Cloud native, modernizzare al tempo dell’AI: verso una governance incorporata nelle piattaforme
Cloud native, modernizzare al tempo dell’AI: verso una governance incorporata nelle piattaforme
Il mercato cloud è raddoppiato in valore rispetto al 2022, ma il contesto è cambiato. Geopolitica, regolazione, pressione sui costi, cyber security e sovranità del dato impongono scelte più selettive e misurabili. Ecco perché il focus è la Cloud governance, dove la selettività è condivisa con business, CISO, procurement e finance
·cybersecurity360.it·
Cloud native, modernizzare al tempo dell’AI: verso una governance incorporata nelle piattaforme
Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit
Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit
A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket communications, multi-stage credential theft, AES-256-CTR implementation, infrastructure, and actionable indicators for defenders.
·group-ib.com·
Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit
Microsoft: September updates break audio on some Windows PCs
Microsoft: September updates break audio on some Windows PCs
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates.
·bleepingcomputer.com·
Microsoft: September updates break audio on some Windows PCs
CISA: Hackers now exploit max severity GitLab flaw in attacks
CISA: Hackers now exploit max severity GitLab flaw in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
·bleepingcomputer.com·
CISA: Hackers now exploit max severity GitLab flaw in attacks
BSides Frankfurt: Deconstructing Modern macOS Initial Access Vectors
BSides Frankfurt: Deconstructing Modern macOS Initial Access Vectors
Abstract For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware. We will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). Finally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).
·dfir.ch·
BSides Frankfurt: Deconstructing Modern macOS Initial Access Vectors
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
·bleepingcomputer.com·
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Chess.com (2026) - 4,653,212 breached accounts
Chess.com (2026) - 4,653,212 breached accounts
In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.
·haveibeenpwned.com·
Chess.com (2026) - 4,653,212 breached accounts
Il fragile patto di fiducia della cybersecurity
Il fragile patto di fiducia della cybersecurity
Tra regole non scritte, patti traditi e vendette, il caso Nightmare Eclipse mostra quanto sia delicato il sistema che regola la divulgazione delle vulnerabilità informatiche.
·guerredirete.substack.com·
Il fragile patto di fiducia della cybersecurity
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
·bleepingcomputer.com·
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Hackers abused Claude to extract secrets from 1.8M Android apps
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
·bleepingcomputer.com·
Hackers abused Claude to extract secrets from 1.8M Android apps