Over Security

Over Security

34916 bookmarks
Custom sorting
L’archiviazione non cancella il passato digitale: la Cassazione fa chiarezza sul diritto all’oblio
L’archiviazione non cancella il passato digitale: la Cassazione fa chiarezza sul diritto all’oblio
La Cassazione boccia l'automatismo Cartabia: archiviazione penale non significa diritto all'oblio. Google mantiene la discrezionalità sul delisting. Per le piattaforme un presidio di bilanciamento, per l'interessato una pena reputazionale potenzialmente senza fine. Ecco tutti i punti critici
·cybersecurity360.it·
L’archiviazione non cancella il passato digitale: la Cassazione fa chiarezza sul diritto all’oblio
Illinois man charged with hacking Snapchat accounts to steal nude photos
Illinois man charged with hacking Snapchat accounts to steal nude photos
U.S. prosecutors have charged an Illinois man with orchestrating a phishing operation that allowed him to hack the Snapchat accounts of nearly 600 women to steal private photos and sell them online.
·bleepingcomputer.com·
Illinois man charged with hacking Snapchat accounts to steal nude photos
PHALT#BLYX e finte schermate di errore di Windows: la nuova tecnica di social engineering
PHALT#BLYX e finte schermate di errore di Windows: la nuova tecnica di social engineering
È stata individuata una nuova campagna malware, ribattezzata PHALT#BLYX, che segna un cambio di paradigma nelle tecniche di social engineering, sfruttando false schermate di errore di Windows per spingere gli utenti a compilare ed eseguire manualmente codice malevolo. Tutti i dettagli
·cybersecurity360.it·
PHALT#BLYX e finte schermate di errore di Windows: la nuova tecnica di social engineering
Trend Micro warns of critical Apex Central RCE vulnerability
Trend Micro warns of critical Apex Central RCE vulnerability
Japanese cybersecurity software firm Trend Micro has patched a critical security flaw in Apex Central (on-premise) that could allow attackers to execute arbitrary code with SYSTEM privileges.
·bleepingcomputer.com·
Trend Micro warns of critical Apex Central RCE vulnerability
DORA: così il CdA delle entità finanziarie entra nel nuovo dominio digitale
DORA: così il CdA delle entità finanziarie entra nel nuovo dominio digitale
Un comandante militare può delegare molte funzioni, ma non può delegare l’esito dell’operazione che gli è stata affidata. Il DORA introduce questo concetto nel governo d’impresa. Ecco cosa definiscono gli articoli 5 e 6, per trasformare il Cda nel centro di gravità dell’intera resilienza operativa
·cybersecurity360.it·
DORA: così il CdA delle entità finanziarie entra nel nuovo dominio digitale
CISA retires 10 emergency cyber orders in rare bulk closure
CISA retires 10 emergency cyber orders in rare bulk closure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired 10 Emergency Directives issued between 2019 and 2024, saying that the required actions have been completed or are now covered by Binding Operational Directive 22-01.
·bleepingcomputer.com·
CISA retires 10 emergency cyber orders in rare bulk closure
New China-linked hackers breach telcos using edge device exploits
New China-linked hackers breach telcos using edge device exploits
A sophisticated threat actor that uses Linux-based malware to target telecommunications providers has recently broadened its operations to include organizations in Southeastern Europe.
·bleepingcomputer.com·
New China-linked hackers breach telcos using edge device exploits
Who Benefited from the Aisuru and Kimwolf Botnets?
Who Benefited from the Aisuru and Kimwolf Botnets?
Our first story of 2026 revealed how a destructive new botnet called Kimwolf rapidly grew to infect more than two million devices by mass-compromising a vast number of unofficial Android TV streaming boxes. Today, we'll dig through digital clues left…
·krebsonsecurity.com·
Who Benefited from the Aisuru and Kimwolf Botnets?
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
The North Korean state-sponsored hacker group Kimsuki is using malicious QR codes in spearphishing campaigns that target U.S. organizations, the Federal Bureau of Investigation warns in a flash alert.
·bleepingcomputer.com·
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
xAI teases major Grok upgrade, hints at Grok Code CLI
xAI teases major Grok upgrade, hints at Grok Code CLI
Elon Musk-backed xAI has been missing in action for a while now, but today, Musk teased a major upgrade for Grok alongside new products.
·bleepingcomputer.com·
xAI teases major Grok upgrade, hints at Grok Code CLI
VMware ESXi zero-days likely exploited a year before disclosure
VMware ESXi zero-days likely exploited a year before disclosure
Chinese-speaking threat actors used a compromised SonicWall VPN appliance to deliver a VMware ESXi exploit toolkit that seems to have been developed more than a year before the targeted vulnerabilities became publicly known.
·bleepingcomputer.com·
VMware ESXi zero-days likely exploited a year before disclosure
Texas court blocks Samsung from tracking TV viewing, then vacates order
Texas court blocks Samsung from tracking TV viewing, then vacates order
The State of Texas obtained a short-lived, temporary restraining order (TRO) against Samsung that prohibited the South Korean company from collecting audio and visual data about what Texas consumers are watching on their TVs.
·bleepingcomputer.com·
Texas court blocks Samsung from tracking TV viewing, then vacates order
Cisco switches hit by reboot loops due to DNS client bug
Cisco switches hit by reboot loops due to DNS client bug
Multiple Cisco switch models are suddenly experiencing reboot loops after logging fatal DNS client errors, according to reports seen by BleepingComputer.
·bleepingcomputer.com·
Cisco switches hit by reboot loops due to DNS client bug
Resolutions, shmesolutions (and what’s actually worked for me)
Resolutions, shmesolutions (and what’s actually worked for me)
Talos' editor ditches the pressure of traditional New Year’s resolutions in favor of practical, in-the-moment changes, and finds more success by letting go of perfection. Plus, we break down the latest on UAT-7290, a newly disclosed threat actor targeting critical infrastructure.
·blog.talosintelligence.com·
Resolutions, shmesolutions (and what’s actually worked for me)
Texas court blocks Samsung from collecting smart TV viewing data
Texas court blocks Samsung from collecting smart TV viewing data
The State of Texas has obtained a temporary restraining order (TRO) against Samsung that prohibits the South Korean company from collecting audio and visual data about what Texas consumers are watching on their TVs.
·bleepingcomputer.com·
Texas court blocks Samsung from collecting smart TV viewing data
Data poisoning: cos’è e come proteggersi dall’avvelenamento dei modelli di AI generativa
Data poisoning: cos’è e come proteggersi dall’avvelenamento dei modelli di AI generativa
Secondo uno studio, condotto da Anthropic, in collaborazione con il UK AI Security Institute e l'Alan Turing Institute, meno dello 0,0002% del dataset complessivo di addestramento pre-training è sufficiente per il data poisoning: bastano 250 documenti malevoli per avvelenare un modello di AI generativa. Ecco le misure di mitigazione
·cybersecurity360.it·
Data poisoning: cos’è e come proteggersi dall’avvelenamento dei modelli di AI generativa
Crif, il borseggio digitale colpisce un Under30 su 5: come proteggersi
Crif, il borseggio digitale colpisce un Under30 su 5: come proteggersi
Il ritorno su importi medio-bassi è una scelta strategica razionale da parte dei frodatori. Operazioni che attirano meno attenzione, bypassano i controlli automatici e, su larga scala, generano comunque volumi economici importanti. Ecco nei dettagli l'osservatorio Crif per la prima metà del 2025
·cybersecurity360.it·
Crif, il borseggio digitale colpisce un Under30 su 5: come proteggersi
Gestione degli incidenti informatici: adesso serve avere un piano
Gestione degli incidenti informatici: adesso serve avere un piano
La normativa NIS 2 impone, dal 31 dicembre 2025, di predisporre i piani di risposta agli attacchi informatici. Ecco come strutturarli e perché è fondamentale dotarsene anche se non si è sottoposti direttamente alla direttiva europea
·cybersecurity360.it·
Gestione degli incidenti informatici: adesso serve avere un piano