Over Security

Over Security

34931 bookmarks
Custom sorting
xAI teases major Grok upgrade, hints at Grok Code CLI
xAI teases major Grok upgrade, hints at Grok Code CLI
Elon Musk-backed xAI has been missing in action for a while now, but today, Musk teased a major upgrade for Grok alongside new products.
·bleepingcomputer.com·
xAI teases major Grok upgrade, hints at Grok Code CLI
VMware ESXi zero-days likely exploited a year before disclosure
VMware ESXi zero-days likely exploited a year before disclosure
Chinese-speaking threat actors used a compromised SonicWall VPN appliance to deliver a VMware ESXi exploit toolkit that seems to have been developed more than a year before the targeted vulnerabilities became publicly known.
·bleepingcomputer.com·
VMware ESXi zero-days likely exploited a year before disclosure
Texas court blocks Samsung from tracking TV viewing, then vacates order
Texas court blocks Samsung from tracking TV viewing, then vacates order
The State of Texas obtained a short-lived, temporary restraining order (TRO) against Samsung that prohibited the South Korean company from collecting audio and visual data about what Texas consumers are watching on their TVs.
·bleepingcomputer.com·
Texas court blocks Samsung from tracking TV viewing, then vacates order
Cisco switches hit by reboot loops due to DNS client bug
Cisco switches hit by reboot loops due to DNS client bug
Multiple Cisco switch models are suddenly experiencing reboot loops after logging fatal DNS client errors, according to reports seen by BleepingComputer.
·bleepingcomputer.com·
Cisco switches hit by reboot loops due to DNS client bug
Resolutions, shmesolutions (and what’s actually worked for me)
Resolutions, shmesolutions (and what’s actually worked for me)
Talos' editor ditches the pressure of traditional New Year’s resolutions in favor of practical, in-the-moment changes, and finds more success by letting go of perfection. Plus, we break down the latest on UAT-7290, a newly disclosed threat actor targeting critical infrastructure.
·blog.talosintelligence.com·
Resolutions, shmesolutions (and what’s actually worked for me)
Texas court blocks Samsung from collecting smart TV viewing data
Texas court blocks Samsung from collecting smart TV viewing data
The State of Texas has obtained a temporary restraining order (TRO) against Samsung that prohibits the South Korean company from collecting audio and visual data about what Texas consumers are watching on their TVs.
·bleepingcomputer.com·
Texas court blocks Samsung from collecting smart TV viewing data
Data poisoning: cos’è e come proteggersi dall’avvelenamento dei modelli di AI generativa
Data poisoning: cos’è e come proteggersi dall’avvelenamento dei modelli di AI generativa
Secondo uno studio, condotto da Anthropic, in collaborazione con il UK AI Security Institute e l'Alan Turing Institute, meno dello 0,0002% del dataset complessivo di addestramento pre-training è sufficiente per il data poisoning: bastano 250 documenti malevoli per avvelenare un modello di AI generativa. Ecco le misure di mitigazione
·cybersecurity360.it·
Data poisoning: cos’è e come proteggersi dall’avvelenamento dei modelli di AI generativa
Crif, il borseggio digitale colpisce un Under30 su 5: come proteggersi
Crif, il borseggio digitale colpisce un Under30 su 5: come proteggersi
Il ritorno su importi medio-bassi è una scelta strategica razionale da parte dei frodatori. Operazioni che attirano meno attenzione, bypassano i controlli automatici e, su larga scala, generano comunque volumi economici importanti. Ecco nei dettagli l'osservatorio Crif per la prima metà del 2025
·cybersecurity360.it·
Crif, il borseggio digitale colpisce un Under30 su 5: come proteggersi
Gestione degli incidenti informatici: adesso serve avere un piano
Gestione degli incidenti informatici: adesso serve avere un piano
La normativa NIS 2 impone, dal 31 dicembre 2025, di predisporre i piani di risposta agli attacchi informatici. Ecco come strutturarli e perché è fondamentale dotarsene anche se non si è sottoposti direttamente alla direttiva europea
·cybersecurity360.it·
Gestione degli incidenti informatici: adesso serve avere un piano
Six for 2026: The cyber threats you can’t ignore
Six for 2026: The cyber threats you can’t ignore
Cybersecurity threats in 2026 are accelerating, driven by AI, automation, and more effective social engineering. Corelight outlines six emerging attack trends and explains how network visibility can help defenders respond faster.
·bleepingcomputer.com·
Six for 2026: The cyber threats you can’t ignore
Microsoft Exchange Online outage blocks access to mailboxes via IMAP4
Microsoft Exchange Online outage blocks access to mailboxes via IMAP4
Microsoft is working to fix an Exchange Online service outage that intermittently prevents users from accessing their mailboxes via the Internet Mailbox Access Protocol 4 (IMAP4).
·bleepingcomputer.com·
Microsoft Exchange Online outage blocks access to mailboxes via IMAP4
ESXi Exploitation in the Wild | Huntress
ESXi Exploitation in the Wild | Huntress
Huntress outlines a complex, multi-step attack designed to break out of guest VMs and target the ESXi hypervisor, using potential zero-day vulnerabilities and sneaky VSOCK communication.
·huntress.com·
ESXi Exploitation in the Wild | Huntress
UAT-7290 targets high value telecommunications infrastructure in South Asia
UAT-7290 targets high value telecommunications infrastructure in South Asia
Talos assesses with high confidence that UAT-7290 is a sophisticated threat actor falling under the China-nexus of Advanced Persistent Threat actors (APTs). UAT-7290 primarily targets telecommunications providers in South Asia.
·blog.talosintelligence.com·
UAT-7290 targets high value telecommunications infrastructure in South Asia
Q-Day: strategie di crypto-agility per la sicurezza delle infrastrutture crittografiche
Q-Day: strategie di crypto-agility per la sicurezza delle infrastrutture crittografiche
La capacità di calcolo ha implicazioni innovative in numerosi ambiti scientifici, ma rappresenta anche una minaccia esistenziale per i sistemi crittografici che proteggono le infrastrutture digitali globali. Ecco quando è previsto il Q-Day e cosa implica la rivoluzione della computazione quantistica per la sicurezza crittografica
·cybersecurity360.it·
Q-Day: strategie di crypto-agility per la sicurezza delle infrastrutture crittografiche
CISA tags max severity HPE OneView flaw as actively exploited
CISA tags max severity HPE OneView flaw as actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a maximum-severity HPE OneView vulnerability as actively exploited in attacks.
·bleepingcomputer.com·
CISA tags max severity HPE OneView flaw as actively exploited