Over Security

Over Security

35917 bookmarks
Custom sorting
Spain's data agency gets first report of AI-powered data breach
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
·bleepingcomputer.com·
Spain's data agency gets first report of AI-powered data breach
Managed Detection & Response: perché la vera sfida oggi è personalizzare la detection
Managed Detection & Response: perché la vera sfida oggi è personalizzare la detection
Nel settore finanziario, dove DORA e NIS2 impongono requisiti sempre più stringenti in materia di resilienza operativa, un MDR standard può non essere sufficiente. Il progetto sviluppato da Certego insieme a TrendAI mostra come trasformare la telemetria degli endpoint in intelligence operativa, migliorando detection e capacità di risposta
·cybersecurity360.it·
Managed Detection & Response: perché la vera sfida oggi è personalizzare la detection
Spain reports first alleged AI-powered data theft attack
Spain reports first alleged AI-powered data theft attack
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
·bleepingcomputer.com·
Spain reports first alleged AI-powered data theft attack
Supply chain cyber risk: come AI e automazione stanno cambiando il Vendor Risk Management
Supply chain cyber risk: come AI e automazione stanno cambiando il Vendor Risk Management
La NIS2 impone di estendere la gestione del rischio anche ai fornitori. Il progetto SupplyShield di Arsenalia mostra come trasformare il Third Party Risk Management da processo manuale e frammentato a modello continuo, automatizzato e integrato con i processi aziendali, grazie ad AI, threat intelligence e integrazione nativa con SAP
·cybersecurity360.it·
Supply chain cyber risk: come AI e automazione stanno cambiando il Vendor Risk Management
I costi del downtime industriale da attacco cyber: come quantificare l’impatto economico dei blocchi di produzione
I costi del downtime industriale da attacco cyber: come quantificare l’impatto economico dei blocchi di produzione
Il downtime causato da un attacco cyber può trasformare rapidamente un incidente OT in una perdita economica rilevante. Mancata produzione, ripristino, penali e danni alla supply chain devono essere misurati per quantificare il rischio e definire investimenti efficaci in resilienza
·cybersecurity360.it·
I costi del downtime industriale da attacco cyber: come quantificare l’impatto economico dei blocchi di produzione
The true cost of a ransomware attack, with and without BCDR
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery.
·bleepingcomputer.com·
The true cost of a ransomware attack, with and without BCDR
From Alert Triage to Threat Hunting: The New SOC Analyst Priority
From Alert Triage to Threat Hunting: The New SOC Analyst Priority
Ask what changed on the shift schedule, and the answer usually gets a lot less clear. I want to talk about the part that gets less attention: when that work actually happens. Only 33% say they actually discover incidents that way ( Devo/Wakefield, April 2025 ). 47% of organizations still discover incidents primarily through alerts ( Devo/Wakefield, 2025 ), so the old scheduling logic is still running underneath even where AI triage sits in front of it. Microsoft describes its own agentic SOC model in a similar way, saying analysts move “from triaging alerts to supervising outcomes.” I like that phrasing because it gets at the real shift. What the Week Actually Looks Like Now In practice, four things need to replace what the queue used to do: protected hunt blocks, AI-output review loops with clear depth, escalation paths for ambiguity, and handoffs that carry reasoning instead of ticket counts. Rhythm element Cadence (illustrative) What it produces What it replaces Hunt block Two protected hours, twice a week, per analyst, scheduled like an on-call shift A written hypothesis and a recorded result Hunting when the queue happens to be quiet AI-output review loop Every shift, depth set by consequence, not a fixed sampling percentage Agent verdicts confirmed or overturned, with the reason attached Rubber-stamping, or re-doing the agent's work Escalation window A standing slot per shift plus a named path for ambiguity A second opinion on the unclear, not just the severe Escalation routed by ticket severity Shift handoff 15 minutes, structured on reasoning The next analyst starts where you stopped Open ticket counts and tool status Hunt blocks are calendar objects, not intentions Hunting that gets scheduled happens. Unprotected time is exactly what a staffing shortage, customer escalation, or noisy day will eat first. Hunt time needs the same treatment. Case management is the top unmet capability gap Devo/Wakefield respondents named, at 77% ( Devo/Wakefield, 2025 ). Review loops need defined depth, not a spot-check percentage AI review does not make analyst attention disappear. Review depth should follow consequence, not a fixed sample rate. A mixed-methods study of explainable AI in SOCs found that analysts sometimes accepted lower-accuracy outputs when the explanation looked evidence-based, and that they preferred contextual depth over dashboard summaries ( Rastogi et al., arXiv, July 2025 ). Set review depth by consequence. Escalation paths built for ambiguity, not severity Queue-era escalation ran on severity because severity was the main signal a ticket carried. Analysts at 84% of organizations unknowingly re-investigate the same incident multiple times a month, and 60% of those teams do it weekly or more ( Devo/Wakefield, 2025 ). 85% of analysts already spend substantial time manually gathering and connecting evidence into a case ( Devo/Wakefield, 2025 ). That is the work that gets repeated when the next analyst has to reconstruct the story. Without hunt blocks, defined review depth, and a real escalation path, the hours an agent frees up do not automatically become better investigations or more careful review. I have run delivery organizations at scale, and I have seen what happens instead: the open time gets swallowed by whatever is loudest that day. Fewer than one-third of organizations use AI for automated alert triage, and 36% use it for enrichment ( Devo/Wakefield, 2025 ). That is the harder half of this problem, and it is where SOC leaders need to spend real time next.
·binarydefense.com·
From Alert Triage to Threat Hunting: The New SOC Analyst Priority
Webinar: What happens in the first hours of a Google Workspace breach
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse.
·bleepingcomputer.com·
Webinar: What happens in the first hours of a Google Workspace breach
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users.
·bleepingcomputer.com·
Microsoft says Copilot buttons still missing in classic Outlook
Critical ScreenConnect flaw now actively exploited in attacks
Critical ScreenConnect flaw now actively exploited in attacks
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
·bleepingcomputer.com·
Critical ScreenConnect flaw now actively exploited in attacks
Caso Revolut, il giallo dei dati istituzionali italiani sottratti dai criminali
Caso Revolut, il giallo dei dati istituzionali italiani sottratti dai criminali
Il caso Revolut porta dentro le infrastrutture istituzionali italiane: una PEC riconducibile alla Prefettura di Reggio Calabria sarebbe stata compromessa e gli attaccanti rivendicano 147 GB di dati sottratti alle forze dell’ordine. Un dato ancora da verificare, ma che sposta l’indagine dalla fintech alla sicurezza dei sistemi dello Stato
·cybersecurity360.it·
Caso Revolut, il giallo dei dati istituzionali italiani sottratti dai criminali
NightEagle targets Russian companies
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
·securelist.com·
NightEagle targets Russian companies
Securing the unpatchable in an age of AI-driven vulnerabilities
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.
·blog.talosintelligence.com·
Securing the unpatchable in an age of AI-driven vulnerabilities
10 Best Brand Protection Solutions (Ranked and Compared)
10 Best Brand Protection Solutions (Ranked and Compared)
Compare the 10 best brand protection solutions of 2026 — Cyble, BrandShield, Red Points, and more — to find the right fit for your threat profile.
·thecyberexpress.com·
10 Best Brand Protection Solutions (Ranked and Compared)
Apple Patches 273 Vulnerabilities as iOS 26.7 Rolls Out
Apple Patches 273 Vulnerabilities as iOS 26.7 Rolls Out
Apple security update iOS 26.7 patches 273 vulnerabilities across iPhone, iPad, and Mac. Here's what iPhone users need to know before updating.
·thecyberexpress.com·
Apple Patches 273 Vulnerabilities as iOS 26.7 Rolls Out