Found 35919 bookmarks
Newest
Trezor data breach impact now reaches 81,000 customers
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
·bleepingcomputer.com·
Trezor data breach impact now reaches 81,000 customers
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.
·bleepingcomputer.com·
Hackers exploit new MikroTik RouterOS flaws to hijack routers
ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.
·bleepingcomputer.com·
ConnectWise warns of new ScreenConnect flaw without patch
Il ciclo di vita digitale: perché CRA e AI Act cambiano la compliance
Il ciclo di vita digitale: perché CRA e AI Act cambiano la compliance
La compliance diventa una capacità organizzativa continua, documentata e verificabile, fino alla dismissione della tecnologia. Ecco le convergenze e le differenze tra i due regolamenti, il contributo degli standard tecnici e delle linee guida ENISA e le ricadute concrete per gli attori della filiera per tradurre i principi in operatività quotidiana
·cybersecurity360.it·
Il ciclo di vita digitale: perché CRA e AI Act cambiano la compliance
OpenAI-Hugging Face: il rischio non sono gli agenti che “fuggono”, ma i controlli che falliscono
OpenAI-Hugging Face: il rischio non sono gli agenti che “fuggono”, ma i controlli che falliscono
Gli agenti OpenAI non hanno sviluppato una volontà autonoma di “fuggire”: hanno sfruttato confini deboli, permessi eccessivi e canali di comunicazione non previsti fino a raggiungere sistemi esterni. Il caso Hugging Face mostra perché con l’AI agentica la sicurezza deve essere imposta dall’architettura, non affidata al comportamento del modello
·cybersecurity360.it·
OpenAI-Hugging Face: il rischio non sono gli agenti che “fuggono”, ma i controlli che falliscono
WRAITH – Browser Hooking and Blind XSS Page Mirroring
WRAITH – Browser Hooking and Blind XSS Page Mirroring
WRAITH combines BeEF-style browser hooks with blind-XSS capture and a credentialed Page Mirror. Tested locally, with its limits examined.
·darknet.org.uk·
WRAITH – Browser Hooking and Blind XSS Page Mirroring
N-able patches max severity N-central flaw amid ongoing attacks
N-able patches max severity N-central flaw amid ongoing attacks
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform.
·bleepingcomputer.com·
N-able patches max severity N-central flaw amid ongoing attacks
ChatGPT Astra is now rolling out to $20 Plus subscription
ChatGPT Astra is now rolling out to $20 Plus subscription
OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access..
·bleepingcomputer.com·
ChatGPT Astra is now rolling out to $20 Plus subscription
Google Maps peggiora il traffico?
Google Maps peggiora il traffico?
I navigatori ottimizzano il viaggio del singolo, ma quando tutti seguono la stessa logica l’effetto si ribalta: il traffico si concentra e le emissioni aumentano
·guerredirete.substack.com·
Google Maps peggiora il traffico?
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).
·bleepingcomputer.com·
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach.
·bleepingcomputer.com·
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
IDScan sued over alleged data breach affecting 153 million drivers
IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses.
·bleepingcomputer.com·
IDScan sued over alleged data breach affecting 153 million drivers
Critical Citrix NetScaler auth bypass now leveraged in attacks
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
·bleepingcomputer.com·
Critical Citrix NetScaler auth bypass now leveraged in attacks
Il budget? Non basta mai
Il budget? Non basta mai
Che la sicurezza cyber debba coinvolgere anche l'IA è vero, ma non è possibile delegarla a questi sistemi o, peggio ancora, considerarli come un focus principale sia d'attacco che di difesa. Perché altrimenti il rischio è quello di perdere quella visione d'insieme necessaria per mantenere una corretta postura di sicurezza cyber
·cybersecurity360.it·
Il budget? Non basta mai
Il phishing sfrutta le difficoltà economiche: come prevenire l’attacco che induce a telefonare all’attaccante
Il phishing sfrutta le difficoltà economiche: come prevenire l’attacco che induce a telefonare all’attaccante
L’ultima campagna phishing, che scommette sulle difficoltà economiche delle vittime, trasforma l’ansia economico-finanziaria in vettore di ingegneria sociale, incoraggiando le vittime a chiamare un numero di telefono sotto il controllo dei cyber criminali. Ecco come mitigare i rischi nelle interazioni telefoniche
·cybersecurity360.it·
Il phishing sfrutta le difficoltà economiche: come prevenire l’attacco che induce a telefonare all’attaccante