Found 34919 bookmarks
Newest
Il gruppo criminale cinese TA4922 adesso punta anche all’Europa
Il gruppo criminale cinese TA4922 adesso punta anche all’Europa
Un gruppo cybercriminale di lingua cinese fino a poco tempo fa concentrato prevalentemente sul mercato asiatico sta ampliando rapidamente il proprio raggio d’azione verso Europa e Africa. Secondo le analisi pubblicate da Proofpoint, il gruppo chiamato TA4922 ha aumentato sensibilmente il volume delle proprie operazioni nel corso del 2026, prendendo di mira organizzazioni nel Regno …
·securityinfo.it·
Il gruppo criminale cinese TA4922 adesso punta anche all’Europa
Hola Browser for Windows compromised to deliver cryptominer
Hola Browser for Windows compromised to deliver cryptominer
The Windows version of the Hola Browser has been compromised in a supply chain attack that delivered an undeclared executable identified by researchers as a cryptocurrency miner.
·bleepingcomputer.com·
Hola Browser for Windows compromised to deliver cryptominer
In memoria di Carola Frediani
In memoria di Carola Frediani
La comunità di No Hat e Berghem-In-The-Middle piange la scomparsa di Carola Frediani, giornalista, autrice, ricercatrice e professionista della sicurezza …
·hacklabg.net·
In memoria di Carola Frediani
Reporting from Vegas: Networking, AI, and good boys
Reporting from Vegas: Networking, AI, and good boys
Joe’s on-the-ground report from Cisco Live U.S. is here, complete with therapy dog pictures and tips on handling conference overstimulation.
·blog.talosintelligence.com·
Reporting from Vegas: Networking, AI, and good boys
Pink Extortion Group Emerges Targeting Microsoft 365 Data
Pink Extortion Group Emerges Targeting Microsoft 365 Data
A newly identified cyber operation dubbed "Pink" extortion is gaining attention among incident responders after security researchers uncovered a threat group using voice phishing, cloud data theft and aggressive extortion tactics to target organizations.
·thecyberexpress.com·
Pink Extortion Group Emerges Targeting Microsoft 365 Data
Pink Extortion Group Emerges Targeting Microsoft 365 Data
Pink Extortion Group Emerges Targeting Microsoft 365 Data
A newly identified cyber operation dubbed "Pink" extortion is gaining attention among incident responders after security researchers uncovered a threat group using voice phishing, cloud data theft and aggressive extortion tactics to target organizations.
·thecyberexpress.com·
Pink Extortion Group Emerges Targeting Microsoft 365 Data
Pink Extortion Group Emerges Targeting Microsoft 365 Data
Pink Extortion Group Emerges Targeting Microsoft 365 Data
A newly identified cyber operation dubbed "Pink" extortion is gaining attention among incident responders after security researchers uncovered a threat group using voice phishing, cloud data theft and aggressive extortion tactics to target organizations.
·thecyberexpress.com·
Pink Extortion Group Emerges Targeting Microsoft 365 Data
UN food agency discloses breach affecting 600,000 Gaza households
UN food agency discloses breach affecting 600,000 Gaza households
The United Nations' World Food Programme (WFP), the world's largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached.
·bleepingcomputer.com·
UN food agency discloses breach affecting 600,000 Gaza households
Machines Triage. Humans Decide.
Machines Triage. Humans Decide.
The AI-orchestrated cyberespionage campaign that Anthropic disclosed in late 2025 , the most agentic offensive operation publicly documented, required humans at four to six decision points per campaign. Deterministic work is where agents earn their keep The work agents do well has a few features in common. Each of those tasks has a deterministic core: there is a right answer, the answer can be checked against ground truth, and the failure modes are bounded. The bulk of what arrives in an alert queue does not require judgment. Putting humans on that work doesn't make the work better. Ambiguous judgment is where humans stay irreplaceable The other layer is harder to describe because it is not a list of tasks. It is a property of certain decisions: they require judgment under ambiguity, with material consequences, on incomplete evidence. The right answer depends on context the model does not have access to: the user's recent project history, the company's quarterly close calendar, what the security team negotiated with that engineering manager last month, whether the org is in a sensitive contract renewal that would change the cost of a wrong call. The decision is not "is this malicious" but "what is the right next step given what we know and what we don't." Models hallucinate confidently in this space. When a model encounters ambiguity, it tends to produce a confident-sounding answer that pattern-matches to its training distribution rather than to the specific situation in front of it. Humans handle this layer not because humans are smarter than models in some general sense. Humans handle it because the calculus on ambiguous decisions involves stakes, context, and accountability that the model has no exposure to. The naive answer is "the agent handles tier-1, the human handles tier-3, tier-2 is the handoff." That description is roughly right but undersells what good handoff design actually requires. Over time, the model gets better at routing the same shape of case to the human earlier, and the false-positive surface narrows. Without it, the agent layer drifts and the human layer gets noisier over time. Every model verdict and every human decision is logged in a way that lets a third party reconstruct what happened and why. Is the decision deterministic, or does it require judgment under ambiguity? Is there context outside the alert data that materially affects the right answer? Processes that involve ambiguous judgment, asymmetric cost-of-error, or external context belong to humans. The right boundary is rarely "fully autonomous" or "fully manual." It is usually "agent processes the case to a specific point, hands to a human at the decision moment, human approves or modifies, system logs the decision." That design discipline, process by process, decision by decision, is the part that takes the longest and pays the most. The right question is "what kind of decision is this, and where should it live?" The answer comes out the same way every time. Deterministic work runs better on machines. Ambiguous judgment runs better through humans. The category does not yet have a clean answer for the second layer, and pretending it does is what produced the false dichotomy between "AI replaces analysts" and "AI is dangerous." Neither is right.
·binarydefense.com·
Machines Triage. Humans Decide.
Machines Triage. Humans Decide.
Machines Triage. Humans Decide.
The AI-orchestrated cyberespionage campaign that Anthropic disclosed in late 2025 , the most agentic offensive operation publicly documented, required humans at four to six decision points per campaign. Deterministic work is where agents earn their keep The work agents do well has a few features in common. Each of those tasks has a deterministic core: there is a right answer, the answer can be checked against ground truth, and the failure modes are bounded. The bulk of what arrives in an alert queue does not require judgment. Putting humans on that work doesn't make the work better. Ambiguous judgment is where humans stay irreplaceable The other layer is harder to describe because it is not a list of tasks. It is a property of certain decisions: they require judgment under ambiguity, with material consequences, on incomplete evidence. The right answer depends on context the model does not have access to: the user's recent project history, the company's quarterly close calendar, what the security team negotiated with that engineering manager last month, whether the org is in a sensitive contract renewal that would change the cost of a wrong call. The decision is not "is this malicious" but "what is the right next step given what we know and what we don't." Models hallucinate confidently in this space. When a model encounters ambiguity, it tends to produce a confident-sounding answer that pattern-matches to its training distribution rather than to the specific situation in front of it. Humans handle this layer not because humans are smarter than models in some general sense. Humans handle it because the calculus on ambiguous decisions involves stakes, context, and accountability that the model has no exposure to. The naive answer is "the agent handles tier-1, the human handles tier-3, tier-2 is the handoff." That description is roughly right but undersells what good handoff design actually requires. Over time, the model gets better at routing the same shape of case to the human earlier, and the false-positive surface narrows. Without it, the agent layer drifts and the human layer gets noisier over time. Every model verdict and every human decision is logged in a way that lets a third party reconstruct what happened and why. Is the decision deterministic, or does it require judgment under ambiguity? Is there context outside the alert data that materially affects the right answer? Processes that involve ambiguous judgment, asymmetric cost-of-error, or external context belong to humans. The right boundary is rarely "fully autonomous" or "fully manual." It is usually "agent processes the case to a specific point, hands to a human at the decision moment, human approves or modifies, system logs the decision." That design discipline, process by process, decision by decision, is the part that takes the longest and pays the most. The right question is "what kind of decision is this, and where should it live?" The answer comes out the same way every time. Deterministic work runs better on machines. Ambiguous judgment runs better through humans. The category does not yet have a clean answer for the second layer, and pretending it does is what produced the false dichotomy between "AI replaces analysts" and "AI is dangerous." Neither is right.
·binarydefense.com·
Machines Triage. Humans Decide.
Campagna LLMShare: come il malvertising abusa di ChatGPT e Claude
Campagna LLMShare: come il malvertising abusa di ChatGPT e Claude
Una nuova campagna di malvertising denominata LLMShare conferma che i criminali informatici hanno smesso di fare affidamento esclusivamente sulle classiche campagne di phishing via e-mail preferendo sfruttare l’autorità e la reputazione incontaminata dei domini ufficiali di OpenAI e Anthropic. Ecco tutti i dettagli e come difendersi
·cybersecurity360.it·
Campagna LLMShare: come il malvertising abusa di ChatGPT e Claude
Crisis Management: piani di comunicazione post-breach
Crisis Management: piani di comunicazione post-breach
Dopo un data breach o un attacco ransomware, la percezione pubblica dell’evento può influenzare reputazione, fiducia e continuità operativa quanto il danno tecnico stesso. Ecco perché, nel corso di una crisis management, la comunicazione è parte della difesa
·cybersecurity360.it·
Crisis Management: piani di comunicazione post-breach
Campagna LLMShare: come il malvertising abusa di ChatGPT e Claude
Campagna LLMShare: come il malvertising abusa di ChatGPT e Claude
Una nuova campagna di malvertising denominata LLMShare conferma che i criminali informatici hanno smesso di fare affidamento esclusivamente sulle classiche campagne di phishing via e-mail preferendo sfruttare l’autorità e la reputazione incontaminata dei domini ufficiali di OpenAI e Anthropic. Ecco tutti i dettagli e come difendersi
·cybersecurity360.it·
Campagna LLMShare: come il malvertising abusa di ChatGPT e Claude
Crisis Management: piani di comunicazione post-breach
Crisis Management: piani di comunicazione post-breach
Dopo un data breach o un attacco ransomware, la percezione pubblica dell’evento può influenzare reputazione, fiducia e continuità operativa quanto il danno tecnico stesso. Ecco perché, nel corso di una crisis management, la comunicazione è parte della difesa
·cybersecurity360.it·
Crisis Management: piani di comunicazione post-breach