Over Security

Over Security

34848 bookmarks
Custom sorting
Software Bill of Materials per l’AI: la supply chain dell’intelligenza artificiale diventa verificabile
Software Bill of Materials per l’AI: la supply chain dell’intelligenza artificiale diventa verificabile
Il G7 definisce per la prima volta gli elementi minimi di un SBOM dedicato ai sistemi AI, estendendo l'inventario software a modelli, dataset, infrastrutture e proprietà di sicurezza. Una base comune per rendere la supply chain più tracciabile e prepararsi a requisiti che potrebbero diventare vincolanti
·cybersecurity360.it·
Software Bill of Materials per l’AI: la supply chain dell’intelligenza artificiale diventa verificabile
SafePal data breach impacts 39,798 customers, stolen info for sale
SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.
·bleepingcomputer.com·
SafePal data breach impacts 39,798 customers, stolen info for sale
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser.
·bleepingcomputer.com·
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
·bleepingcomputer.com·
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
Mastering Claude Code Series - Part 1
Mastering Claude Code Series - Part 1
An Introduction to the Series from a Security Engineer's Perspective
·attacker-codeninja.github.io·
Mastering Claude Code Series - Part 1
How Anthropic plans to watermark Claude's AI-generated text
How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials.
·bleepingcomputer.com·
How Anthropic plans to watermark Claude's AI-generated text
What we know about the alleged Iranian hacks on U.S. water utilities
What we know about the alleged Iranian hacks on U.S. water utilities
Over the last couple of weeks, hackers have targeted and broken into the systems of several water plants in the United States. Here’s what we know and don’t know about this wave of attacks allegedly carried out by the Iranian government.
·techcrunch.com·
What we know about the alleged Iranian hacks on U.S. water utilities
Hackers arrested over €30M bank fraud exploiting service provider flaw
Hackers arrested over €30M bank fraud exploiting service provider flaw
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts.
·bleepingcomputer.com·
Hackers arrested over €30M bank fraud exploiting service provider flaw
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
·bleepingcomputer.com·
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain.
·bleepingcomputer.com·
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Max severity SAP Commerce Cloud flaw now targeted in attacks
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.
·bleepingcomputer.com·
Max severity SAP Commerce Cloud flaw now targeted in attacks
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and…
·krebsonsecurity.com·
Who’s Tracking You? Use This New Service to Find Out