Over Security

Over Security

33814 bookmarks
Custom sorting
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
Le sanzioni del Garante privacy a due operatori del settore energetico ridefiniscono le regole del credit scoring automatizzato. Trasparenza, qualità dei dati, governance degli algoritmi e tutela dei diritti diventano i pilastri di un modello destinato a estendersi ben oltre il mercato dell'energia
·cybersecurity360.it·
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
Explore 10 best threat intelligence feeds for SOCs and MSSPs in 2026, including their data sources, integrations, threat context, and common security use cases.
·any.run·
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
Preview: Cisco Talos at Black Hat USA 2026
Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
·blog.talosintelligence.com·
Preview: Cisco Talos at Black Hat USA 2026
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
·blog.talosintelligence.com·
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
·bleepingcomputer.com·
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Il problema non è soltanto l’agente AI che ha superato una sandbox. Il vero punto è che una valutazione delle capacità cyber ha prodotto effetti su un’infrastruttura reale di un soggetto terzo. Per i modelli più avanzati non bastano benchmark e guardrail: servono regole d’ingaggio, responsabilità e gli stessi controlli di un’operazione offensiva
·cybersecurity360.it·
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
During ongoing monitoring of malicious infrastructure, Group-IB identified an exposed staging server that uncovered an active China-nexus operation. Subsequent investigation confirmed intrusion attempts across government, healthcare, and education sectors in Vietnam, Malaysia, and Hong Kong to parallel phishing campaigns in LATAM, all connected through a shared loader tracked as TriBack Loader.
·group-ib.com·
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
·bleepingcomputer.com·
Check Point warns of SmartConsole zero-day exploited in attacks
Chick-fil-A Confirms Customer Data Accessed in Cyberattack
Chick-fil-A Confirms Customer Data Accessed in Cyberattack
The Chick-fil-A data security incident may have exposed customer account information after an automated attack targeted Chick-fil-A One accounts.
·thecyberexpress.com·
Chick-fil-A Confirms Customer Data Accessed in Cyberattack
1-15 July 2026 Cyber Attacks Timeline
1-15 July 2026 Cyber Attacks Timeline
85 confirmed cyber attacks, July 1-15 2026: cyber crime drove 76% of incidents, malware led at 43%, and IT & communications was the hardest-hit sector.
·hackmageddon.com·
1-15 July 2026 Cyber Attacks Timeline
1-15 July 2026 Cyber Attacks Timeline Infographic
1-15 July 2026 Cyber Attacks Timeline Infographic
85 confirmed incidents, July 1-15 2026: Cyber Crime drove 76.5% of attacks, Malware led techniques at 43.5%, and Info & Communication was the top-hit sector.
·hackmageddon.com·
1-15 July 2026 Cyber Attacks Timeline Infographic
Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products
Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products
Oracle's July 2026 Critical Patch Update fixes 1,449 security flaws across 334 products, including 600 remotely exploitable vulnerabilities.
·thecyberexpress.com·
Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products
Upbound says hack caused $13 million in fraudulent Acima leases
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases.
·bleepingcomputer.com·
Upbound says hack caused $13 million in fraudulent Acima leases
South Korea discloses data breach impacting diplomats worldwide
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats.
·bleepingcomputer.com·
South Korea discloses data breach impacting diplomats worldwide
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.
·techcrunch.com·
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers.
·bleepingcomputer.com·
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
How enterprise GenAI can amplify ransomware risk — and how to contain it
How enterprise GenAI can amplify ransomware risk — and how to contain it
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption.
·bleepingcomputer.com·
How enterprise GenAI can amplify ransomware risk — and how to contain it