Over Security

Over Security

33813 bookmarks
Custom sorting
2026 Browser Data Reveals Major Enterprise Security Blind Spots
2026 Browser Data Reveals Major Enterprise Security Blind Spots
The browser is becoming the operating system for modern work, yet many enterprises still treat it as an extension of network or endpoint security. Keep Aware's 2026 State of Browser Security Report shows 41% of employees used AI web tools while browser-based phishing, extensions, and social engineering drive new security blind spots.
·bleepingcomputer.com·
2026 Browser Data Reveals Major Enterprise Security Blind Spots
Google says 90 zero-days were exploited in attacks last year
Google says 90 zero-days were exploited in attacks last year
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities actively exploited throughout 2025, almost half of them in enterprise software and appliances.
·bleepingcomputer.com·
Google says 90 zero-days were exploited in attacks last year
Quando il rischio torna nel mondo fisico: il cloud e la sicurezza dimenticata
Quando il rischio torna nel mondo fisico: il cloud e la sicurezza dimenticata
Il cloud viene raccontato come qualcosa di etereo, astratto: una “nuvola”. In realtà, è un’infrastruttura industriale distribuita, composta da edifici, sistemi energetici, apparati di rete, fibre ottiche e personale operativo. Dunque, la sicurezza è sempre di più anche una questione di infrastrutture, energia, geografia e resilienza
·cybersecurity360.it·
Quando il rischio torna nel mondo fisico: il cloud e la sicurezza dimenticata
Police dismantles online gambling ring exploiting Ukrainian women
Police dismantles online gambling ring exploiting Ukrainian women
Spanish and Ukrainian law enforcement authorities dismantled a criminal ring that exploited war-displaced Ukrainian women to run an online gambling scheme that laundered nearly €4.75 million in illicit proceeds.
·bleepingcomputer.com·
Police dismantles online gambling ring exploiting Ukrainian women
Iran, Russia e non solo: l’architettura della repressione digitale
Iran, Russia e non solo: l’architettura della repressione digitale
I regimi autoritari fanno sempre più spesso affidamento agli spegnimenti di internet per reprimere il dissenso e bloccare le informazioni: ecco come funzionano i blackout della rete
·guerredirete.it·
Iran, Russia e non solo: l’architettura della repressione digitale
Cisco flags more SD-WAN flaws as actively exploited in attacks
Cisco flags more SD-WAN flaws as actively exploited in attacks
​Cisco has flagged two more Catalyst SD-WAN Manager security flaws as actively exploited in the wild, urging administrators to upgrade vulnerable devices.
·bleepingcomputer.com·
Cisco flags more SD-WAN flaws as actively exploited in attacks
La Direttiva NIS2 e la gestione della sicurezza nella supply chain
La Direttiva NIS2 e la gestione della sicurezza nella supply chain
La gestione sicura della catena di approvvigionamento e del ciclo di vita della fornitura nell’ambito della Direttiva NIS2 e del D.lgs. 138/2024 e suoi provvedimenti attuativi: un sistema normativo integrato, organico e strutturato
·cybersecurity360.it·
La Direttiva NIS2 e la gestione della sicurezza nella supply chain
Phobos ransomware admin pleads guilty to wire fraud conspiracy
Phobos ransomware admin pleads guilty to wire fraud conspiracy
A Russian national pleaded guilty to a wire fraud conspiracy charge related to his role in administering the Phobos ransomware operation, which breached hundreds of victims worldwide.
·bleepingcomputer.com·
Phobos ransomware admin pleads guilty to wire fraud conspiracy
Bitwarden adds support for passkey login on Windows 11
Bitwarden adds support for passkey login on Windows 11
Bitwarden announced support for logging into Windows 11 devices using passkeys stored in the manager's vault, enabling phishing-resistant authentication.
·bleepingcomputer.com·
Bitwarden adds support for passkey login on Windows 11
Windows 10 KB5075039 update fixes broken Recovery Environment
Windows 10 KB5075039 update fixes broken Recovery Environment
Microsoft has released the KB5075039 Windows Recovery Environment update for Windows 10 to fix a long-standing issue that prevented some users from accessing the Recovery environment.
·bleepingcomputer.com·
Windows 10 KB5075039 update fixes broken Recovery Environment
Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks
Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks
A previously undocumented set of 23 iOS exploits named "Coruna" has been deployed by multiple threat actors in targeted espionage campaigns and financially motivated attacks.
·bleepingcomputer.com·
Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks
Hacker mass-mails HungerRush extortion emails to restaurant patrons
Hacker mass-mails HungerRush extortion emails to restaurant patrons
Customers of restaurants using the HungerRush point-of-sale (POS) platform say they received emails from a threat actor attempting to extort the company, warning that restaurant and customer data could be exposed if HungerRush fails to respond.
·bleepingcomputer.com·
Hacker mass-mails HungerRush extortion emails to restaurant patrons
La sicurezza nazionale tra quantum, cyber e geopolitica: la relazione 2026 dell’Intelligence
La sicurezza nazionale tra quantum, cyber e geopolitica: la relazione 2026 dell’Intelligence
La Relazione annuale della sicurezza della Repubblica, edizione 2026, colloca la tecnologia al centro delle dinamiche strategiche contemporanee. Ecco perché la sicurezza nazionale ha come priorità quantum, cyber e geopolitica, mentre cyber spazio, infrastrutture digitali, sistemi di comunicazione, dati e capacità computazionale sono elementi dell'architettura di potere
·cybersecurity360.it·
La sicurezza nazionale tra quantum, cyber e geopolitica: la relazione 2026 dell’Intelligence
Europol-coordinated action disrupts Tycoon2FA phishing platform
Europol-coordinated action disrupts Tycoon2FA phishing platform
An international law enforcement operation coordinated by Europol has disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform linked to tens of millions of phishing messages each month.
·bleepingcomputer.com·
Europol-coordinated action disrupts Tycoon2FA phishing platform
RedAlert Trojan Campaign: Fake Emergency Alert App Spread via SMS Spoofing Israeli Home Front Command | CloudSEK
RedAlert Trojan Campaign: Fake Emergency Alert App Spread via SMS Spoofing Israeli Home Front Command | CloudSEK
CloudSEK has uncovered a malicious SMS spoofing campaign spreading a fake version of Israel’s “Red Alert” emergency app amid the ongoing conflict. Disguised as a trusted warning platform, the trojanized Android app can steal SMS, contacts, and location data while appearing legitimate. The report highlights how cybercriminals are weaponising public fear during crises to deploy mobile spyware with serious security and real-world implications.
·cloudsek.com·
RedAlert Trojan Campaign: Fake Emergency Alert App Spread via SMS Spoofing Israeli Home Front Command | CloudSEK