Over Security

Over Security

34848 bookmarks
Custom sorting
Microsoft tests faster Windows File Explorer, new context menu
Microsoft tests faster Windows File Explorer, new context menu
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week.
·bleepingcomputer.com·
Microsoft tests faster Windows File Explorer, new context menu
CISA: Windows Task Host flaw now exploited by ransomware gangs
CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
·bleepingcomputer.com·
CISA: Windows Task Host flaw now exploited by ransomware gangs
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive.
·bleepingcomputer.com·
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.
·bleepingcomputer.com·
Microsoft starts removing WMIC tool used by cybercriminals
La complessità è nemica della cyber security: la lezione del principio KISS
La complessità è nemica della cyber security: la lezione del principio KISS
Ogni funzione, dipendenza e riga di codice aggiuntiva può ampliare la superficie di attacco. Dal principio KISS a DRY e YAGNI, progettare sistemi più semplici non è minimalismo fine a sé stesso: significa ridurre vulnerabilità, costi e complessità operativa, trasformando la sicurezza in un vantaggio competitivo
·cybersecurity360.it·
La complessità è nemica della cyber security: la lezione del principio KISS
678,000 People Hit in French Tax Authority Data Breach
678,000 People Hit in French Tax Authority Data Breach
DGFiP cyberattack exposed tax & cadastral data linked to 678,000 individuals and professionals, while a separate claim alleges 2 mn were affected.
·thecyberexpress.com·
678,000 People Hit in French Tax Authority Data Breach
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio
Ogni prospettiva descrive un livello di una catena d'attacco. Da sola, nessuna la descrive tutta. Ma il modello ibrido nasce dalla consapevolezza: non elimina i metodi esistenti, ma li collega. Ecco perché nella gestione dei rischi NIS 2, si fa largo il modello ibrido
·cybersecurity360.it·
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio
AI Models Escaped Test Environments and Hit Real Targets
AI Models Escaped Test Environments and Hit Real Targets
AI security incidents expose gaps in model evaluation environments as Irregular reviews internet access, monitoring and containment controls.
·thecyberexpress.com·
AI Models Escaped Test Environments and Hit Real Targets
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.
·bleepingcomputer.com·
Pokémon Center data breach exposes customer info, cancels some orders
Microsoft confirms GitHub is down worldwide
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services.
·bleepingcomputer.com·
Microsoft confirms GitHub is down worldwide
Certighost and the Privilege Hiding in Your Certificate Authority
Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been.
·bleepingcomputer.com·
Certighost and the Privilege Hiding in Your Certificate Authority
Windows Server 2022 reaches end of mainstream support in 60 days
Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support.
·bleepingcomputer.com·
Windows Server 2022 reaches end of mainstream support in 60 days
Philips and GE investigating Clop ransomware data theft claims
Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data.
·bleepingcomputer.com·
Philips and GE investigating Clop ransomware data theft claims
French tax authority data breach affects 678,000 individuals
French tax authority data breach affects 678,000 individuals
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.
·bleepingcomputer.com·
French tax authority data breach affects 678,000 individuals
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414.
·bleepingcomputer.com·
Microsoft working on Defender patch for ShieldBreak zero-day