Over Security

Over Security

35917 bookmarks
Custom sorting
EU fines Google $1 billion for search, app store antitrust violations
EU fines Google $1 billion for search, app store antitrust violations
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition.
·bleepingcomputer.com·
EU fines Google $1 billion for search, app store antitrust violations
New RefluXFS Linux flaw lets attackers gain root privileges
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
·bleepingcomputer.com·
New RefluXFS Linux flaw lets attackers gain root privileges
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
Le sanzioni del Garante privacy a due operatori del settore energetico ridefiniscono le regole del credit scoring automatizzato. Trasparenza, qualità dei dati, governance degli algoritmi e tutela dei diritti diventano i pilastri di un modello destinato a estendersi ben oltre il mercato dell'energia
·cybersecurity360.it·
Credit scoring nel settore energetico: cosa cambia dopo le sanzioni del Garante privacy
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
Explore 10 best threat intelligence feeds for SOCs and MSSPs in 2026, including their data sources, integrations, threat context, and common security use cases.
·any.run·
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026
Preview: Cisco Talos at Black Hat USA 2026
Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
·blog.talosintelligence.com·
Preview: Cisco Talos at Black Hat USA 2026
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
·blog.talosintelligence.com·
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
·bleepingcomputer.com·
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
Il problema non è soltanto l’agente AI che ha superato una sandbox. Il vero punto è che una valutazione delle capacità cyber ha prodotto effetti su un’infrastruttura reale di un soggetto terzo. Per i modelli più avanzati non bastano benchmark e guardrail: servono regole d’ingaggio, responsabilità e gli stessi controlli di un’operazione offensiva
·cybersecurity360.it·
Quando il test diventa l’incidente: il caso OpenAI-Hugging Face è un fallimento di governance
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
During ongoing monitoring of malicious infrastructure, Group-IB identified an exposed staging server that uncovered an active China-nexus operation. Subsequent investigation confirmed intrusion attempts across government, healthcare, and education sectors in Vietnam, Malaysia, and Hong Kong to parallel phishing campaigns in LATAM, all connected through a shared loader tracked as TriBack Loader.
·group-ib.com·
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
·bleepingcomputer.com·
Check Point warns of SmartConsole zero-day exploited in attacks
Chick-fil-A Confirms Customer Data Accessed in Cyberattack
Chick-fil-A Confirms Customer Data Accessed in Cyberattack
The Chick-fil-A data security incident may have exposed customer account information after an automated attack targeted Chick-fil-A One accounts.
·thecyberexpress.com·
Chick-fil-A Confirms Customer Data Accessed in Cyberattack
1-15 July 2026 Cyber Attacks Timeline
1-15 July 2026 Cyber Attacks Timeline
85 confirmed cyber attacks, July 1-15 2026: cyber crime drove 76% of incidents, malware led at 43%, and IT & communications was the hardest-hit sector.
·hackmageddon.com·
1-15 July 2026 Cyber Attacks Timeline
1-15 July 2026 Cyber Attacks Timeline Infographic
1-15 July 2026 Cyber Attacks Timeline Infographic
85 confirmed incidents, July 1-15 2026: Cyber Crime drove 76.5% of attacks, Malware led techniques at 43.5%, and Info & Communication was the top-hit sector.
·hackmageddon.com·
1-15 July 2026 Cyber Attacks Timeline Infographic
South Korea discloses data breach impacting diplomats worldwide
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats.
·bleepingcomputer.com·
South Korea discloses data breach impacting diplomats worldwide
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.
·techcrunch.com·
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers.
·bleepingcomputer.com·
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack