Over Security

Over Security

35917 bookmarks
Custom sorting
The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets
The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets
Group-IB discovers a sophisticated multi-layered scam scheme targeting fans with fake ticket sales on two fronts: social network platforms and fraudulent websites impersonating official distributors.
·group-ib.com·
The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets
US sanctions VPN, malware providers for enabling ransomware attacks
US sanctions VPN, malware providers for enabling ransomware attacks
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations.
·bleepingcomputer.com·
US sanctions VPN, malware providers for enabling ransomware attacks
L’AI inventa un nuovo ransomware nel browser: il rischio vero è che riduce la soglia tecnica
L’AI inventa un nuovo ransomware nel browser: il rischio vero è che riduce la soglia tecnica
La tipica allucinazione generativa, a una prima occhiata, si è invece trasformata in un'AI in grado di generare ransomware nel browser, collegando il rischio ipotetico dei browser a una tecnica di cifratura, classica da attacco ransomware, attivabile senza competenze evolute. Ecco come proteggersi dall'AI che genera ransomware nei browser
·cybersecurity360.it·
L’AI inventa un nuovo ransomware nel browser: il rischio vero è che riduce la soglia tecnica
Japan's largest taxi operator shuts systems after cyberattack
Japan's largest taxi operator shuts systems after cyberattack
Japan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure.
·bleepingcomputer.com·
Japan's largest taxi operator shuts systems after cyberattack
Hackers backdoor Jscrambler npm package with infostealer malware
Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times.
·bleepingcomputer.com·
Hackers backdoor Jscrambler npm package with infostealer malware
New CrashStealer malware poses as Apple crash reporting tool
New CrashStealer malware poses as Apple crash reporting tool
A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets.
·bleepingcomputer.com·
New CrashStealer malware poses as Apple crash reporting tool
Spazio e cyber spazio non sono più separati: nasce il Polo Italiano che li unisce
Spazio e cyber spazio non sono più separati: nasce il Polo Italiano che li unisce
Nasce il Polo Italiano per il Cyber e la Space Economy. Partnership strategica con gli Emirati Arabi per integrare cyber, intelligenza artificiale e sicurezza spaziale. Obiettivo: rafforzare autonomia tecnologica italiana e costruire un ecosistema innovativo, con una cooperazione internazionale su domini critici per la sicurezza nazionale
·cybersecurity360.it·
Spazio e cyber spazio non sono più separati: nasce il Polo Italiano che li unisce
CISA warns of actively exploited RCE flaws in Joomla extensions
CISA warns of actively exploited RCE flaws in Joomla extensions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads.
·bleepingcomputer.com·
CISA warns of actively exploited RCE flaws in Joomla extensions
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months…
·krebsonsecurity.com·
Lessons Learned from CISA’s Recent GitHub Leak
Lidl discloses online shop breach after service provider hack
Lidl discloses online shop breach after service provider hack
German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider.
·bleepingcomputer.com·
Lidl discloses online shop breach after service provider hack
Oltre 15 anni di cyber attacchi russi contro l’Europa: arriva la sanzione UE
Oltre 15 anni di cyber attacchi russi contro l’Europa: arriva la sanzione UE
L'UE sanziona ufficiali dei servizi segreti russi per quindici anni di attacchi cyber contro gli Stati Membri: un'azione che non blocca le operazioni, ma crea un precedente giuridico e politico che rende più difficile negare l'attribuzione in futuro. Ecco il ruolo degli attacchi cyber russi nella guerra ibrida per destabilizzare l'UE
·cybersecurity360.it·
Oltre 15 anni di cyber attacchi russi contro l’Europa: arriva la sanzione UE
Breach at the Beach: Play the Ultimate Entra ID CTF
Breach at the Beach: Play the Ultimate Entra ID CTF
Learn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios.
·bleepingcomputer.com·
Breach at the Beach: Play the Ultimate Entra ID CTF
GigaWiper, la piattaforma malware che spia e distrugge i sistemi compromessi
GigaWiper, la piattaforma malware che spia e distrugge i sistemi compromessi
I laboratori di Threat Intelligence Microsoft hanno identificato il nuovo malware GigaWiper che, oltre alla capacità di cancellare dati, si caratterizza per la sua architettura modulare che combina funzionalità di accesso remoto, spionaggio e distruzione dei sistemi compromessi. Ecco tutti i dettagli e i consigli per difendersi
·cybersecurity360.it·
GigaWiper, la piattaforma malware che spia e distrugge i sistemi compromessi
UK charges suspects linked to Russian Coms call spoofing platform
UK charges suspects linked to Russian Coms call spoofing platform
UK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls.
·bleepingcomputer.com·
UK charges suspects linked to Russian Coms call spoofing platform
VPN veloce: con NordVPN 75% di sconto e 3 mesi extra
VPN veloce: con NordVPN 75% di sconto e 3 mesi extra
NordVPN propone un'offerta per avere per 2 anni una VPN veloce e affidabile disponibile oggi con il 75% di sconto e 3 mesi extra.
·cybersecurity360.it·
VPN veloce: con NordVPN 75% di sconto e 3 mesi extra
EU sanctions Russian GRU military hackers over cyberattacks
EU sanctions Russian GRU military hackers over cyberattacks
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe.
·bleepingcomputer.com·
EU sanctions Russian GRU military hackers over cyberattacks
US and allies warn of Russian critical infrastructure attacks
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks.
·bleepingcomputer.com·
US and allies warn of Russian critical infrastructure attacks
Le vulnerabilità delle periferiche wireless a cui (quasi) nessuno pensa
Le vulnerabilità delle periferiche wireless a cui (quasi) nessuno pensa
L'Istituto nazionale elvetico di test per la cibersicurezza NCT rivela come tastiere, mouse e cuffie senza fili possano diventare pericolose porte d'accesso per gli attaccanti. Cosa sapere e perché tenerne conto
·cybersecurity360.it·
Le vulnerabilità delle periferiche wireless a cui (quasi) nessuno pensa