Over Security

Over Security

34600 bookmarks
Custom sorting
Vendor Risk Management: come rendere misurabile il rischio dei fornitori
Vendor Risk Management: come rendere misurabile il rischio dei fornitori
In un contesto caratterizzato dagli attacchi alla supply chain, in cui ogni fornitore rappresenta un potenziale punto di ingresso per gli attaccanti, serve un approccio strutturato e continuo di Third-Party Risk Management (TPRM) dinamico. Ecco cos'è un vendor risk management moderno e maturo
·cybersecurity360.it·
Vendor Risk Management: come rendere misurabile il rischio dei fornitori
Microsoft disrupts massive RedVDS cybercrime virtual desktop service
Microsoft disrupts massive RedVDS cybercrime virtual desktop service
Microsoft announced on Wednesday that it disrupted RedVDS, a massive cybercrime platform linked to at least $40 million in reported losses in the United States alone since March 2025.
·bleepingcomputer.com·
Microsoft disrupts massive RedVDS cybercrime virtual desktop service
ChatGPT's upcoming cross-platform feature is codenamed "Agora"
ChatGPT's upcoming cross-platform feature is codenamed "Agora"
OpenAI is internally testing a new feature called "Agora," and it could be related to some sort of cross-platform feature that works in real time or some other new product.
·bleepingcomputer.com·
ChatGPT's upcoming cross-platform feature is codenamed "Agora"
South Korean giant Kyowon confirms data theft in ransomware attack
South Korean giant Kyowon confirms data theft in ransomware attack
The Kyowon Group (Kyowon), a South Korean conglomerate, disclosed that a cyberattack has disrupted its operations and customer information may have been exposed in the incident.
·bleepingcomputer.com·
South Korean giant Kyowon confirms data theft in ransomware attack
France fines Free Mobile €42 million over 2024 data breach incident
France fines Free Mobile €42 million over 2024 data breach incident
The French data protection authority (CNIL) has imposed cumulative fines of €42 million on Free Mobile and its parent company, Free, for inadequate protection of customer data against cyber threats.
·bleepingcomputer.com·
France fines Free Mobile €42 million over 2024 data breach incident
Exploit code public for critical FortiSIEM command injection flaw
Exploit code public for critical FortiSIEM command injection flaw
Technical details and a public exploit have been published for a critical vulnerability affecting Fortinet's Security Information and Event Management (SIEM) solution that could be leveraged by a remote, unauthenticated attacker to execute commands or code.
·bleepingcomputer.com·
Exploit code public for critical FortiSIEM command injection flaw
“La tua tessera sanitaria è in scadenza”, ma è phishing: come difendersi
“La tua tessera sanitaria è in scadenza”, ma è phishing: come difendersi
Il CERT-AgID ha identificato una nuova campagna di phishing che sfrutta indebitamente il nome e l’immagine del Ministero della Salute per indurre i cittadini a rinnovare la tessera sanitaria. Ecco come funziona la truffa e i consigli per tenere al sicuro i propri dati personali
·cybersecurity360.it·
“La tua tessera sanitaria è in scadenza”, ma è phishing: come difendersi
Microsoft updates Windows DLL that triggered security alerts
Microsoft updates Windows DLL that triggered security alerts
Microsoft has resolved a known issue that was causing security applications to incorrectly flag a core Windows component, the company said in a service alert posted this week.
·bleepingcomputer.com·
Microsoft updates Windows DLL that triggered security alerts
Microsoft smantella RedVDS: sotto i fari la convergenza tra cloud abusato, GenAI e crimine
Microsoft smantella RedVDS: sotto i fari la convergenza tra cloud abusato, GenAI e crimine
Microsoft ha annunciato lo smantellamento di un servizio di abbonamento globale dedicato alla criminalità informatica responsabile di frodi per 40 milioni di dollari in un anno solo negli Usa. Ecco cosa significa questa operazione contro il marketplace RedVDS che unisce un approccio legale e operativo
·cybersecurity360.it·
Microsoft smantella RedVDS: sotto i fari la convergenza tra cloud abusato, GenAI e crimine
ConsentFix debrief: Insights from the new OAuth phishing attack
ConsentFix debrief: Insights from the new OAuth phishing attack
ConsentFix is an OAuth phishing technique abusing browser-based authorization flows to hijack Microsoft accounts. Push Security shares new insights from continued tracking, community research, and evolving attacker techniques.
·bleepingcomputer.com·
ConsentFix debrief: Insights from the new OAuth phishing attack
Reprompt attack let hackers hijack Microsoft Copilot sessions
Reprompt attack let hackers hijack Microsoft Copilot sessions
Researchers identified an attack method dubbed "Reprompt" that could allow attackers to infiltrate a user's Microsoft Copilot session and issue commands to exfiltrate sensitive data.
·bleepingcomputer.com·
Reprompt attack let hackers hijack Microsoft Copilot sessions
Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners
Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners
Cloud marketplace and distributor Pax8 has confirmed that it mistakenly sent an email to fewer than 40 UK-based partners containing a spreadsheet with internal business information, including MSP customer and Microsoft licensing data.
·bleepingcomputer.com·
Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners