Over Security

Over Security

34089 bookmarks
Custom sorting
Microsoft adds Copilot data controls to all storage locations
Microsoft adds Copilot data controls to all storage locations
Microsoft is expanding data loss prevention (DLP) controls to block the Microsoft 365 Copilot AI assistant from processing confidential Word, Excel, and PowerPoint documents, regardless of their location.
·bleepingcomputer.com·
Microsoft adds Copilot data controls to all storage locations
Sandworm_Mode: il “worm” della supply chain NPM
Sandworm_Mode: il “worm” della supply chain NPM
Un attacco che riprende la logica Shai-Hulud, ma sposta l’asticella sul toolchain moderno Una recente analisi dei  ricercatori di Socket, un’azienda specializzata in sicurezza informatica, ha svelato una nuova campagna d’attacco alla supply chain dello sviluppo software colpendo NPM, l’ecosistema dove risiedono migliaia di librerie Javascript largamente usate dai programmatori di tutto il mondo. L’attacco …
·securityinfo.it·
Sandworm_Mode: il “worm” della supply chain NPM
Identity-First AI Security: Why CISOs Must Add Intent to the Equation
Identity-First AI Security: Why CISOs Must Add Intent to the Equation
AI agents now provision infrastructure and approve actions, but many inherit over-scoped privileges without proper governance. Token Security explains why CISOs must treat agents as identities and add intent-based controls so access is granted only when purpose and context align.
·bleepingcomputer.com·
Identity-First AI Security: Why CISOs Must Add Intent to the Equation
UK fines Reddit $19 million for using children’s data unlawfully
UK fines Reddit $19 million for using children’s data unlawfully
The UK Information Commissioner's Office (ICO) has fined Reddit £14.47 million (over $19.5 million) for collecting and using the personal information of children under 13 without adequate safeguards.
·bleepingcomputer.com·
UK fines Reddit $19 million for using children’s data unlawfully
NightBeacon: Rapid Deployment of AI Capabilities
NightBeacon: Rapid Deployment of AI Capabilities
What NightBeacon Is NightBeacon is Binary Defense’s AI-powered threat analysis platform built to take real-world security inputs—logs, files, and emails—and turn them into clear, explainable risk signals that analysts can act on fast. Less than 24 hours later, the detection techniques described in that research were live in production inside NightBeacon, Binary Defense’s AI-powered threat analysis platform. This post breaks down exactly how that happened, focusing on the architecture, the detection logic, and the implementation details that allowed new threat research to become operational almost immediately.
·binarydefense.com·
NightBeacon: Rapid Deployment of AI Capabilities
PromptSpy e l’ingresso della GenAI nel malware per Android
PromptSpy e l’ingresso della GenAI nel malware per Android
PromptSpy è la prima minaccia Android a integrare l’AI generativa nel proprio flusso di attacco, impiegando direttamente il modello durante l’esecuzione del malware sul dispositivo della vittima e introducendo capacità di adattamento dinamico finora assenti negli strumenti tradizionali basati su script statici
·cybersecurity360.it·
PromptSpy e l’ingresso della GenAI nel malware per Android
ShinyHunters extortion gang claims Odido breach affecting millions
ShinyHunters extortion gang claims Odido breach affecting millions
The ShinyHunters extortion gang has claimed responsibility for breaching Dutch telecommunications provider Odido and stealing millions of user records from its compromised systems.
·bleepingcomputer.com·
ShinyHunters extortion gang claims Odido breach affecting millions
North Korean Lazarus group linked to Medusa ransomware attacks
North Korean Lazarus group linked to Medusa ransomware attacks
North Korean state-backed hackers associated with the Lazarus threat group are targeting U.S. healthcare organizations in extortion attack using the Medusa ransomware.
·bleepingcomputer.com·
North Korean Lazarus group linked to Medusa ransomware attacks
Whaling e CEO Fraud: perché il pesce grosso è il più facile da pescare
Whaling e CEO Fraud: perché il pesce grosso è il più facile da pescare
Il C-Level è il bersaglio più facile, più esposto e tecnicamente più vulnerabile dell'organigramma aziendale. È dunque necessario fornire strategie di difesa specifiche, attraverso la combinazione di tecniche di controspionaggio digitale e procedure operative che blindano i processi decisionali critici senza rallentare il business
·cybersecurity360.it·
Whaling e CEO Fraud: perché il pesce grosso è il più facile da pescare
La NIS 2 non necessita di documenti: richiede governo
La NIS 2 non necessita di documenti: richiede governo
Con la NIS 2, la sicurezza informatica diventa materia di governo societario. Ecco perché il rischio digitale deve essere assunto, deliberato e tracciato dal vertice organizzativo
·cybersecurity360.it·
La NIS 2 non necessita di documenti: richiede governo
Spain arrests suspected hacktivists for DDoSing govt sites
Spain arrests suspected hacktivists for DDoSing govt sites
Spanish authorities have arrested four alleged members of a hacktivist group believed to have carried out cyberattacks targeting government ministries, political parties, and various public institutions.
·bleepingcomputer.com·
Spain arrests suspected hacktivists for DDoSing govt sites