Over Security

Over Security

34363 bookmarks
Custom sorting
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers.
·bleepingcomputer.com·
Chinese hackers develop LONGLEASH malware to expand ORB network
Hidden backdoor in Tenda router firmware grants admin access
Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel.
·bleepingcomputer.com·
Hidden backdoor in Tenda router firmware grants admin access
Ultimatum BCE alle banche: alzate le difese contro la minaccia AI
Ultimatum BCE alle banche: alzate le difese contro la minaccia AI
Le banche hanno tempo fino al 31 ottobre 2026 per presentare un piano contro le minacce cyber abilitate dall’intelligenza artificiale. La richiesta dà seguito agli allarmi dopo uscita di Mythos
·cybersecurity360.it·
Ultimatum BCE alle banche: alzate le difese contro la minaccia AI
Model stealing: quando il modello AI diventa il vero bersaglio degli attaccanti
Model stealing: quando il modello AI diventa il vero bersaglio degli attaccanti
La distillazione, una tecnica messa a punto più di un decennio fa per rendere più efficienti i sistemi di apprendimento automatico, oggi è utilizzata anche per replicare, senza autorizzazione, il comportamento di modelli proprietari altrui. Ecco perché la minaccia sta assumendo proporzioni industriali
·cybersecurity360.it·
Model stealing: quando il modello AI diventa il vero bersaglio degli attaccanti
16-30 June 2026 Cyber Attacks Timeline Infographic
16-30 June 2026 Cyber Attacks Timeline Infographic
16–30 June 2026 — Cyber Attacks Infographic | HACKMAGEDDON Cyber Threat Intelligence · HACKMAGEDDON 16–30 June 2026Cyber Attacks Infographic 96 confirmed incidents across t…
·hackmageddon.com·
16-30 June 2026 Cyber Attacks Timeline Infographic
Spain arrests suspected member of pro-Russian hacktivist groups
Spain arrests suspected member of pro-Russian hacktivist groups
The National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups.
·bleepingcomputer.com·
Spain arrests suspected member of pro-Russian hacktivist groups
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
ActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows.
·bleepingcomputer.com·
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
JADEPUFFER, il ransomware agentico che cambia le regole della cyber security: come difendersi
JADEPUFFER, il ransomware agentico che cambia le regole della cyber security: come difendersi
JADEPUFFER è la prima operazione ransomware pilotata end-to-end da un agente IA: violazione di un'istanza Langflow, furto massivo di credenziali e attacco automatizzato a database Nacos/MySQL. Tecniche, indicatori di compromissione e contromisure per CISO e aziende
·cybersecurity360.it·
JADEPUFFER, il ransomware agentico che cambia le regole della cyber security: come difendersi
Webinar tomorrow: Why modern email attacks require a new approach to defense
Webinar tomorrow: Why modern email attacks require a new approach to defense
Tomorrow's webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and response workflows.
·bleepingcomputer.com·
Webinar tomorrow: Why modern email attacks require a new approach to defense
16-30 June 2026 Cyber Attacks Timeline
16-30 June 2026 Cyber Attacks Timeline
16–30 June 2026 cyber attacks timeline: 96 incidents — ransomware, supply-chain attacks, and nation-state espionage analyzed.
·hackmageddon.com·
16-30 June 2026 Cyber Attacks Timeline
Microsoft to enable Windows settings backup by default for orgs
Microsoft to enable Windows settings backup by default for orgs
Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2.
·bleepingcomputer.com·
Microsoft to enable Windows settings backup by default for orgs
Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPs
Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPs
This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added clarification on 0ktapus and how it is related to Scattered Spider.
·group-ib.com·
Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPs
BeyondTrust warns of critical flaws in remote access software
BeyondTrust warns of critical flaws in remote access software
BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication.
·bleepingcomputer.com·
BeyondTrust warns of critical flaws in remote access software
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel.
·bleepingcomputer.com·
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
La resilienza non si scrive una volta sola: il vero problema è il riesame continuo
La resilienza non si scrive una volta sola: il vero problema è il riesame continuo
La resilienza, infatti, non è uno stato stabile ma una capacità dinamica che deve evolvere insieme ad altri fattori. Ecco il ruolo strategico del riesame continuo, degli aggiornamenti periodici, delle esercitazioni e degli audit, per evitare che un piano non aggiornato si trasformi in fattore di rischio
·cybersecurity360.it·
La resilienza non si scrive una volta sola: il vero problema è il riesame continuo
Fake IT support calls on Microsoft Teams push EtherRAT malware
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks.
·bleepingcomputer.com·
Fake IT support calls on Microsoft Teams push EtherRAT malware
Phishing poses as big-brand job interview to steal Google accounts
Phishing poses as big-brand job interview to steal Google accounts
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals.
·bleepingcomputer.com·
Phishing poses as big-brand job interview to steal Google accounts