Over Security

Over Security

34363 bookmarks
Custom sorting
Agenti AI che attaccano: la lezione dai casi Anthropic e OpenAI
Agenti AI che attaccano: la lezione dai casi Anthropic e OpenAI
Anche Anthropic riporta un caso di un'agente AI che fa attacchi cyber. Si aggiunge al pericoloso precedente OpenAI-Hugging Face, che è il primo esempio di attacchi AI autonomi senza (anzi contro) la volontà umana. Ecco che succede e cosa imparare
·cybersecurity360.it·
Agenti AI che attaccano: la lezione dai casi Anthropic e OpenAI
Il jailbreak universale alla vigilia dell’AI Act: ecco l’impatto nella sicurezza aziendale
Il jailbreak universale alla vigilia dell’AI Act: ecco l’impatto nella sicurezza aziendale
Il prossimo 2 agosto si applicherà l'articolo 55 dell'AI Act, che impone ai fornitori di modelli general purpose, a rischio sistemico, obblighi stringenti di red teaming, gestione degli incidenti e resilienza. Tra rivendicazioni social, ricerca accademica e obblighi normativi: cosa cambia nella postura delle aziende contro le minacce alla GenAI
·cybersecurity360.it·
Il jailbreak universale alla vigilia dell’AI Act: ecco l’impatto nella sicurezza aziendale
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Chi si occupava di protezione dei dati cercava nella normativa un elenco di cose da fare. Nella struttura dell’articolo 24 del Regolamento, il GDPR mostra che una normativa fondata su principi e rischio non è più debole, ma più esigente. Ecco perché il regolamento europeo non ha abolito il diritto dell’obbedienza, ma lo ha reso insufficiente
·cybersecurity360.it·
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Chi si occupava di protezione dei dati cercava nella normativa un elenco di cose da fare. Nella struttura dell’articolo 24 del Regolamento, il GDPR mostra che una normativa fondata su principi e rischio non è più debole, ma più esigente. Ecco perché il regolamento europeo non ha abolito il diritto dell’obbedienza, ma lo ha reso insufficiente
·cybersecurity360.it·
Il GDPR non chiede solo obbedienza: principi, rischio, responsabilizzazione
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
·bleepingcomputer.com·
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
Claude uploaded malware to PyPI in Anthropic's botched test
Claude uploaded malware to PyPI in Anthropic's botched test
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
·bleepingcomputer.com·
Claude uploaded malware to PyPI in Anthropic's botched test
South Korea fines telco giant KT $39 million for customer data breach
South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations.
·bleepingcomputer.com·
South Korea fines telco giant KT $39 million for customer data breach
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution.
·bleepingcomputer.com·
JetBrains warns of critical TeamCity remote code execution flaw
VMware fixes three critical flaws allowing auth bypass, VM escapes
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
·bleepingcomputer.com·
VMware fixes three critical flaws allowing auth bypass, VM escapes
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI.
·bleepingcomputer.com·
Google says AI helped Chrome fix 1,072 security bugs in two releases
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a…
·krebsonsecurity.com·
Read This Before You Buy That TV Streaming Stick
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.
·bleepingcomputer.com·
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
After the Break-In: What Attackers Do Once They're Already Inside
After the Break-In: What Attackers Do Once They're Already Inside
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware.
·bleepingcomputer.com·
After the Break-In: What Attackers Do Once They're Already Inside