Over Security

Over Security

34205 bookmarks
Custom sorting
Why the shift left dream has become a nightmare for security and developers
Why the shift left dream has become a nightmare for security and developers
The "shift left" approach has increased pressure on developers, as speed demands override security checks in modern CI pipelines. Qualys explains how analyzing 34,000 public container images revealed 7.3% were malicious and why security must be enforced at the infrastructure layer by default.
·bleepingcomputer.com·
Why the shift left dream has become a nightmare for security and developers
PayPal discloses data breach that exposed user info for 6 months
PayPal discloses data breach that exposed user info for 6 months
PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year.
·bleepingcomputer.com·
PayPal discloses data breach that exposed user info for 6 months
FBI: Over $20 million stolen in surge of ATM malware attacks in 2025
FBI: Over $20 million stolen in surge of ATM malware attacks in 2025
The FBI warned that Americans lost more than $20 million last year amid a massive surge in ATM "jackpotting" attacks, in which criminals use malware to force cash machines to dispense money.
·bleepingcomputer.com·
FBI: Over $20 million stolen in surge of ATM malware attacks in 2025
ClickFix: la nuova frontiera del social engineering, tra DNS e Google Ads
ClickFix: la nuova frontiera del social engineering, tra DNS e Google Ads
È stata identificata una nuova variante del malware ClickFix che, usando lo staging via DNS per distribuire payload su sistemi Windows e Google Ads per indurre le vittime a eseguire comandi malevoli, sta di fatto trasformando l’utente nel vero vettore di infezione. Ecco tutti i dettagli
·cybersecurity360.it·
ClickFix: la nuova frontiera del social engineering, tra DNS e Google Ads
Indicatori di compromissione
Indicatori di compromissione
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
·certego.net·
Indicatori di compromissione
La compliance che non protegge. Quando il GDPR resta solo sulla carta
La compliance che non protegge. Quando il GDPR resta solo sulla carta
Il GDPR diventa inefficace se ridotto a un insieme di adempimenti scollegati dalle decisioni che modellano realmente l’organizzazione. Da sola, la conformità formale non è una garanzia. Ecco come trasformare la compliance in tutela effettiva delle persone e in qualità reale delle organizzazioni
·cybersecurity360.it·
La compliance che non protegge. Quando il GDPR resta solo sulla carta
CarMax - 431,371 breached accounts
CarMax - 431,371 breached accounts
In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt. The data included 431k unique email addresses along with names, phone numbers and physical addresses.
·haveibeenpwned.com·
CarMax - 431,371 breached accounts
PromptSpy is the first Android malware to use generative AI at runtime
PromptSpy is the first Android malware to use generative AI at runtime
Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google's Gemini model to adapt its persistence across different devices.
·bleepingcomputer.com·
PromptSpy is the first Android malware to use generative AI at runtime
Using AI to defeat AI
Using AI to defeat AI
In this week’s newsletter Martin considers how defenders can turn offensive AI tools against themselves.
·blog.talosintelligence.com·
Using AI to defeat AI
Google blocked over 1.75 million Play Store app submissions in 2025
Google blocked over 1.75 million Play Store app submissions in 2025
Google says that through 2025, it blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data and rejected over 1.75 million apps from being published on Google Play due to policy violations.
·bleepingcomputer.com·
Google blocked over 1.75 million Play Store app submissions in 2025
Attacco hacker cinese al Viminale: una violazione mirata per esfiltrare identità di agenti Digos
Attacco hacker cinese al Viminale: una violazione mirata per esfiltrare identità di agenti Digos
La violazione, definita "mirata" e non distruttiva - finalizzata cioè all'acquisizione silenziosa di informazioni strategiche piuttosto che al sabotaggio dei sistemi -ha comportato l’esfiltrazione di dati relativi a circa 5mila agenti della Digos. Ecco cosa sappiamo
·cybersecurity360.it·
Attacco hacker cinese al Viminale: una violazione mirata per esfiltrare identità di agenti Digos