Over Security

Over Security

34848 bookmarks
Custom sorting
Hackers run khunt post-exploitation toolkit from Oracle database
Hackers run khunt post-exploitation toolkit from Oracle database
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network.
·bleepingcomputer.com·
Hackers run khunt post-exploitation toolkit from Oracle database
COLDCARD security audit phishing attack installs remote access tool
COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
·bleepingcomputer.com·
COLDCARD security audit phishing attack installs remote access tool
PSA: Apple’s Private Relay can leak your real IP address
PSA: Apple’s Private Relay can leak your real IP address
A bug in how Apple implements its Private Relay feature, which in theory masks users’ IP addresses from the sites they visit, can reveal users’ real IP addresses.
·techcrunch.com·
PSA: Apple’s Private Relay can leak your real IP address
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited.
·bleepingcomputer.com·
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
Security Wals: il podcast
Security Wals: il podcast
Lo ammetto, è stato un anno difficile. Uno di quelli dove le volte che hai ingioiato il rospo, sono in pari con quelle in cui ti sei rialzato.
·codiceinsicuro.it·
Security Wals: il podcast
Google Blogger locks hundreds of blogs in malware false positive
Google Blogger locks hundreds of blogs in malware false positive
Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform.
·bleepingcomputer.com·
Google Blogger locks hundreds of blogs in malware false positive
Supply chain software: Amazon conferma una campagna d’attacco che l’Italia ha già intercettato
Supply chain software: Amazon conferma una campagna d’attacco che l’Italia ha già intercettato
In due episodi Amazon ha analizzato gli attaccanti far leva su tecniche di ingegneria sociale per conquistare la fiducia degli amministratori dei pacchetti e ottenere così i privilegi. Ecco come gruppi legati alla Corea del Nord hanno sferrato gli attacchi ai pacchetti NPM e come difendersi da una minaccia strutturale sull'ecosistema di dipendenze
·cybersecurity360.it·
Supply chain software: Amazon conferma una campagna d’attacco che l’Italia ha già intercettato
How AI-powered phishing killed blocklists for good
How AI-powered phishing killed blocklists for good
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators.
·bleepingcomputer.com·
How AI-powered phishing killed blocklists for good
Un dato anonimo per chi? Le nuove linee guida EDPB cambiano prospettiva
Un dato anonimo per chi? Le nuove linee guida EDPB cambiano prospettiva
Le nuove linee guida EDPB superano la visione tradizionale dell'anonimizzazione: un dato può essere anonimo per alcuni soggetti ma non per altri. Per i titolari del trattamento cambia il modo di valutare rischio, accountability e governance dei dati, anche nei progetti di intelligenza artificiale
·cybersecurity360.it·
Un dato anonimo per chi? Le nuove linee guida EDPB cambiano prospettiva
Un dato anonimo per chi? Le nuove linee guida EDPB cambiano prospettiva
Un dato anonimo per chi? Le nuove linee guida EDPB cambiano prospettiva
Le nuove linee guida EDPB superano la visione tradizionale dell'anonimizzazione: un dato può essere anonimo per alcuni soggetti ma non per altri. Per i titolari del trattamento cambia il modo di valutare rischio, accountability e governance dei dati, anche nei progetti di intelligenza artificiale
·cybersecurity360.it·
Un dato anonimo per chi? Le nuove linee guida EDPB cambiano prospettiva
NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain
NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain
La gestione dei fornitori non può essere ridotta a un elenco anagrafico o contrattuale. In ottica NIS2, la criticità di un fornitore dipende dagli asset che gestisce, dai servizi IT che supporta, dagli accessi di cui dispone e dall’impatto che una sua indisponibilità o compromissione può produrre sull’organizzazione
·cybersecurity360.it·
NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain