Over Security

Over Security

34601 bookmarks
Custom sorting
ChatGPT tests a new feature to find jobs, improve your resume, and more
ChatGPT tests a new feature to find jobs, improve your resume, and more
OpenAI is testing "Jobs," a new feature that could help you explore roles, improve your resume, and plan your career. This feature is being tested after ChatGPT gained support for the Health dashboard.
·bleepingcomputer.com·
ChatGPT tests a new feature to find jobs, improve your resume, and more
Microsoft may soon allow IT admins to uninstall Copilot
Microsoft may soon allow IT admins to uninstall Copilot
Microsoft is testing a new policy that allows IT administrators to uninstall the AI-powered Copilot digital assistant on managed devices.
·bleepingcomputer.com·
Microsoft may soon allow IT admins to uninstall Copilot
Raccolta dati e AI: le sfide legali del web scraping secondo la CNIL
Raccolta dati e AI: le sfide legali del web scraping secondo la CNIL
La CNIL chiarisce che la raccolta di dati accessibili online tramite web scraping è legittima se accompagnata da misure a salvaguardia dei diritti degli interessati. Con un interessante focus sheet sul punto, la base giuridica del legittimo interesse prende forza. Vediamo meglio
·cybersecurity360.it·
Raccolta dati e AI: le sfide legali del web scraping secondo la CNIL
Spogliati dall’AI: come difendersi dalla minaccia social
Spogliati dall’AI: come difendersi dalla minaccia social
Grok su X è molto usato per “spogliare” donne e minori senza consenso, creando immagini sexualizzate. Il Garante italiano avverte: generare e diffondere questi contenuti (deepfake) può integrare reati e gravi violazioni dei diritti, con conseguenze anche privacy. Ecco cosa si rischia e come difendersi
·cybersecurity360.it·
Spogliati dall’AI: come difendersi dalla minaccia social
Il “peccato” dell’incident response
Il “peccato” dell’incident response
L’incident response è una funzione vitale dell'organizzazione, ma adottare una corretta strategia a riguardo implica il compiere scelte condivise e coordinate, per non disperdere risorse e mantenere strategie coerenti ed efficaci. Motivo per cui non è da sottovalutare l'aspetto della comunicazione interna
·cybersecurity360.it·
Il “peccato” dell’incident response
IntelOwl 6.5.0
IntelOwl 6.5.0
Managed Detection & Response services (MDR) 24/7 for network, endpoint, cloud, SaaS and OT, against every type of cyber attack
·certego.net·
IntelOwl 6.5.0
Email security needs more seatbelts: Why click rate is the wrong metric
Email security needs more seatbelts: Why click rate is the wrong metric
Click rate misses the real email security risk: what attackers can do after they access a mailbox. Material Security explains why containment and post-compromise impact matter more than phishing metrics.
·bleepingcomputer.com·
Email security needs more seatbelts: Why click rate is the wrong metric
Illinois Department of Human Services data breach affects 700K people
Illinois Department of Human Services data breach affects 700K people
The Illinois Department of Human Services (IDHS), one of Illinois' largest state agencies, accidentally exposed the personal and health data of nearly 700,000 residents due to incorrect privacy settings.
·bleepingcomputer.com·
Illinois Department of Human Services data breach affects 700K people
L’archiviazione non cancella il passato digitale: la Cassazione fa chiarezza sul diritto all’oblio
L’archiviazione non cancella il passato digitale: la Cassazione fa chiarezza sul diritto all’oblio
La Cassazione boccia l'automatismo Cartabia: archiviazione penale non significa diritto all'oblio. Google mantiene la discrezionalità sul delisting. Per le piattaforme un presidio di bilanciamento, per l'interessato una pena reputazionale potenzialmente senza fine. Ecco tutti i punti critici
·cybersecurity360.it·
L’archiviazione non cancella il passato digitale: la Cassazione fa chiarezza sul diritto all’oblio
Illinois man charged with hacking Snapchat accounts to steal nude photos
Illinois man charged with hacking Snapchat accounts to steal nude photos
U.S. prosecutors have charged an Illinois man with orchestrating a phishing operation that allowed him to hack the Snapchat accounts of nearly 600 women to steal private photos and sell them online.
·bleepingcomputer.com·
Illinois man charged with hacking Snapchat accounts to steal nude photos
PHALT#BLYX e finte schermate di errore di Windows: la nuova tecnica di social engineering
PHALT#BLYX e finte schermate di errore di Windows: la nuova tecnica di social engineering
È stata individuata una nuova campagna malware, ribattezzata PHALT#BLYX, che segna un cambio di paradigma nelle tecniche di social engineering, sfruttando false schermate di errore di Windows per spingere gli utenti a compilare ed eseguire manualmente codice malevolo. Tutti i dettagli
·cybersecurity360.it·
PHALT#BLYX e finte schermate di errore di Windows: la nuova tecnica di social engineering
Trend Micro warns of critical Apex Central RCE vulnerability
Trend Micro warns of critical Apex Central RCE vulnerability
Japanese cybersecurity software firm Trend Micro has patched a critical security flaw in Apex Central (on-premise) that could allow attackers to execute arbitrary code with SYSTEM privileges.
·bleepingcomputer.com·
Trend Micro warns of critical Apex Central RCE vulnerability
DORA: così il CdA delle entità finanziarie entra nel nuovo dominio digitale
DORA: così il CdA delle entità finanziarie entra nel nuovo dominio digitale
Un comandante militare può delegare molte funzioni, ma non può delegare l’esito dell’operazione che gli è stata affidata. Il DORA introduce questo concetto nel governo d’impresa. Ecco cosa definiscono gli articoli 5 e 6, per trasformare il Cda nel centro di gravità dell’intera resilienza operativa
·cybersecurity360.it·
DORA: così il CdA delle entità finanziarie entra nel nuovo dominio digitale
CISA retires 10 emergency cyber orders in rare bulk closure
CISA retires 10 emergency cyber orders in rare bulk closure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired 10 Emergency Directives issued between 2019 and 2024, saying that the required actions have been completed or are now covered by Binding Operational Directive 22-01.
·bleepingcomputer.com·
CISA retires 10 emergency cyber orders in rare bulk closure
New China-linked hackers breach telcos using edge device exploits
New China-linked hackers breach telcos using edge device exploits
A sophisticated threat actor that uses Linux-based malware to target telecommunications providers has recently broadened its operations to include organizations in Southeastern Europe.
·bleepingcomputer.com·
New China-linked hackers breach telcos using edge device exploits
Who Benefited from the Aisuru and Kimwolf Botnets?
Who Benefited from the Aisuru and Kimwolf Botnets?
Our first story of 2026 revealed how a destructive new botnet called Kimwolf rapidly grew to infect more than two million devices by mass-compromising a vast number of unofficial Android TV streaming boxes. Today, we'll dig through digital clues left…
·krebsonsecurity.com·
Who Benefited from the Aisuru and Kimwolf Botnets?
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
The North Korean state-sponsored hacker group Kimsuki is using malicious QR codes in spearphishing campaigns that target U.S. organizations, the Federal Bureau of Investigation warns in a flash alert.
·bleepingcomputer.com·
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs