Over Security

Over Security

35917 bookmarks
Custom sorting
Tutto al DPO? L’AI Act riapre il problema della governance nelle aziende
Tutto al DPO? L’AI Act riapre il problema della governance nelle aziende
Un’indagine della CNIL sul ruolo del DPO e dell’impatto dell’intelligenza artificiale e dell’AI Act mostrano il crescente coinvolgimento di questa figura nella governance AI, a fronte di assetti organizzativi ancora poco definiti. Un quadro che consente di interrogarsi su un ruolo ai confini tra privacy, AI compliance e funzioni di controllo
·cybersecurity360.it·
Tutto al DPO? L’AI Act riapre il problema della governance nelle aziende
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure.
·bleepingcomputer.com·
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Continuous compliance: perché la conformità cyber deve passare dalla fotografia al processo
Continuous compliance: perché la conformità cyber deve passare dalla fotografia al processo
NIS2 e gli altri framework di sicurezza rendono sempre meno efficace una compliance basata su assessment periodici, fogli Excel ed evidenze raccolte manualmente. Ecco la soluzione per collegare governance e sistemi IT e trasformare la conformità da fotografia statica a processo continuo, verificabile e orientato al rischio
·cybersecurity360.it·
Continuous compliance: perché la conformità cyber deve passare dalla fotografia al processo
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
Cleafy's TIR team analyzed the operator infrastructure behind RATHat, an Android banking trojan that abuses Accessibility Services to enable wireless debugging on the victim's phone, obtain a shell, and deploy a hidden native service outside the app. The investigation recovered three generations of the Chinese-language control panel, consistent with a Malware-as-a-Service model.
·cleafy.com·
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.
·bleepingcomputer.com·
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Gestione dei rischi cyber degli agenti IA: i 4 limiti delle regole europee
Gestione dei rischi cyber degli agenti IA: i 4 limiti delle regole europee
Sistemi agentici, durante i test di valutazione condotti dalle stesse aziende, sono usciti dagli ambienti chiusi in cui erano confinati e hanno toccato infrastrutture reali, appartenenti a terzi ignari. Ecco cosa succede quando un algoritmo esce dalla gabbia e svanisce la soglia tra simulazione controllata ed esecuzione ostile
·cybersecurity360.it·
Gestione dei rischi cyber degli agenti IA: i 4 limiti delle regole europee
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
·bleepingcomputer.com·
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
Kiteworks Systems Went Offline After Federal Threat Warning
Kiteworks Systems Went Offline After Federal Threat Warning
Kiteworks shutdown advisory lifted after federal threat intelligence prompted a precautionary system shutdown. No compromise has been identified.
·thecyberexpress.com·
Kiteworks Systems Went Offline After Federal Threat Warning
CISA orders feds to patch exploited Citrix flaws by Wednesday
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
·bleepingcomputer.com·
CISA orders feds to patch exploited Citrix flaws by Wednesday
Threat Hunting and Defending #2: concepts, framework, Threat Model (p4)
Threat Hunting and Defending #2: concepts, framework, Threat Model (p4)
Intro Devo un po’ accelerare con lo studio anche perché mi si è sovrapposta un’altra certificazione :-) Chiuso il giro su questa parte con il Threat Modeling, argomento che ricorre in d…
·roccosicilia.com·
Threat Hunting and Defending #2: concepts, framework, Threat Model (p4)
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.
·bleepingcomputer.com·
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
·bleepingcomputer.com·
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Che cosa sono le ambasciate dei dati
Che cosa sono le ambasciate dei dati
Dall’Estonia a Singapore, fino all’India: in un’epoca di attacchi informatici, guerre e crisi geopolitiche, ecco come gli Stati mettono al sicuro i propri dati.
·guerredirete.substack.com·
Che cosa sono le ambasciate dei dati
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
·bleepingcomputer.com·
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks