Over Security

Over Security

34848 bookmarks
Custom sorting
Cost of a Data Breach 2026: l’AI fa esplodere costi e velocità degli attacchi
Cost of a Data Breach 2026: l’AI fa esplodere costi e velocità degli attacchi
Il report IBM 2026 fotografa una cyber security a due velocità: violazioni a quota 4,99 milioni di dollari (3,55 milioni in Italia), attacchi AI-driven +56% e modelli di AI aziendali sotto attacco. Ecco i numeri chiave e le contromisure per i team di sicurezza e i CISO
·cybersecurity360.it·
Cost of a Data Breach 2026: l’AI fa esplodere costi e velocità degli attacchi
Attacco hacker a Levi’s: il dipendente non è l’anello debole, va ripensata la sicurezza
Attacco hacker a Levi’s: il dipendente non è l’anello debole, va ripensata la sicurezza
Tre dipendenti colpiti con tecniche di social engineering sono bastati agli attaccanti per accedere ai sistemi Levi's ed esfiltrare dati aziendali. Il caso dimostra perché la formazione non basta: la sicurezza deve partire dall'errore umano e impedirgli di trasformarsi in un incidente
·cybersecurity360.it·
Attacco hacker a Levi’s: il dipendente non è l’anello debole, va ripensata la sicurezza
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do.
·bleepingcomputer.com·
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
DDoS attacks over 1 Tbps surged fivefold in the second quarter
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year.
·bleepingcomputer.com·
DDoS attacks over 1 Tbps surged fivefold in the second quarter
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
·bleepingcomputer.com·
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
·securelist.com·
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Network Security Policy Management (NSPM): colmare il gap tra normativa UE e adozione in azienda
Network Security Policy Management (NSPM): colmare il gap tra normativa UE e adozione in azienda
Normative come NIS2 e DORA stanno innalzando gli standard in termini di resilienza, responsabilità e governance operativa, imponendo alle organizzazioni di dimostrare l'esistenza dei controlli di sicurezza e l'efficacia nel tempo. Ecco cos'è il Network Security Policy Management, l'anello mancante fra la normativa europea e l'implementazione reale
·cybersecurity360.it·
Network Security Policy Management (NSPM): colmare il gap tra normativa UE e adozione in azienda
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks.
·bleepingcomputer.com·
Cisco warns of high-severity ClamAV flaws with public exploits
Gunra Ransomware Builds a New Attack Network Through RaaS
Gunra Ransomware Builds a New Attack Network Through RaaS
Gunra ransomware has expanded through a RaaS affiliate program, using double extortion, data theft and encryption to target across sectors.
·thecyberexpress.com·
Gunra Ransomware Builds a New Attack Network Through RaaS
US and South Korea warn of Gunra ransomware targeting govt agencies
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.
·bleepingcomputer.com·
US and South Korea warn of Gunra ransomware targeting govt agencies
Input validation: perché la sicurezza applicativa comincia dai dati che lasciamo entrare
Input validation: perché la sicurezza applicativa comincia dai dati che lasciamo entrare
Ogni dato proveniente dall'esterno può diventare un vettore di attacco. Per questo l'input validation non dovrebbe essere un controllo aggiunto a valle, ma un requisito di progettazione: un approccio multilivello che riduce la superficie di attacco senza sacrificare l'usabilità
·cybersecurity360.it·
Input validation: perché la sicurezza applicativa comincia dai dati che lasciamo entrare
Gestione dei rischi NIS 2: la scelta del metodo determina la qualità del sistema
Gestione dei rischi NIS 2: la scelta del metodo determina la qualità del sistema
La scelta del metodo non è una decisione tecnica di secondo piano, ma stabilisce il modo in cui l’organizzazione comprenderà i propri rischi, selezionerà le misure e dimostrerà la coerenza del proprio sistema. Ecco perché la gestione dei rischi occupa il centro esatto della NIS 2
·cybersecurity360.it·
Gestione dei rischi NIS 2: la scelta del metodo determina la qualità del sistema
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network.
·bleepingcomputer.com·
Hackers breached a small Polish energy plant via private APN last year
BdThemes plugins supply-chain hack creates rogue WordPress admins
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts.
·bleepingcomputer.com·
BdThemes plugins supply-chain hack creates rogue WordPress admins
New StormEncryptor ransomware used by former Medusa affiliate
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
·bleepingcomputer.com·
New StormEncryptor ransomware used by former Medusa affiliate
AI, ora controlli preventivi sui modelli: il blocco di Astra, le regole di Trump
AI, ora controlli preventivi sui modelli: il blocco di Astra, le regole di Trump
Gli Usa procedono con cautela contro il rischio incontrollato dell'AI. OpenAI ha sospeso parte delle attività interne sul nuovo modello Astra, per pericoli cybersecurity. Il Governo Trump sperimenta un patto volontario per la sicurezza AI. Si cerca un difficile equilibrio tra sicurezza e innovazione, con conseguenze globali
·cybersecurity360.it·
AI, ora controlli preventivi sui modelli: il blocco di Astra, le regole di Trump