Over Security

Over Security

35019 bookmarks
Custom sorting
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
New York City's 2026 mayoral inauguration of Zohran Mamdani has published a list of banned items for the event, specifically prohibiting the Flipper Zero and Raspberry Pi devices.
·bleepingcomputer.com·
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
Punto di “sniffing”
Punto di “sniffing”
In questi giorni ho rimesso mano al mio home lab aggiungendo qualche pezzo ed in particolare mi sono dotato di una componente hardware che solitamente, per esigenze di spazio e comodità, utilizzavo…
·roccosicilia.com·
Punto di “sniffing”
Hackers drain $3.9M from Unleash Protocol after multisig hijack
Hackers drain $3.9M from Unleash Protocol after multisig hijack
The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract upgrade that allowed asset withdrawals.
·bleepingcomputer.com·
Hackers drain $3.9M from Unleash Protocol after multisig hijack
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers.
·bleepingcomputer.com·
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
What the f**k is a CAO and do I need one?
What the f**k is a CAO and do I need one?
The CAO (Chief Automation Officer) is the "Chief Enabler." The role assesses automation feasibility, ensuring the right solution (deterministic vs. agentic) for business problems.
·bfore.ai·
What the f**k is a CAO and do I need one?
IBM warns of critical API Connect auth bypass vulnerability
IBM warns of critical API Connect auth bypass vulnerability
IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely.
·bleepingcomputer.com·
IBM warns of critical API Connect auth bypass vulnerability
Disney will pay $10 million to settle children's data privacy lawsuit
Disney will pay $10 million to settle children's data privacy lawsuit
Disney has agreed to pay a $10 million civil penalty to settle claims that it violated the Children's Online Privacy Protection Act by mislabeling videos and allowing data collection for targeted advertising.
·bleepingcomputer.com·
Disney will pay $10 million to settle children's data privacy lawsuit
AI come arma cognitiva: dall’ISIS alla tecnodestra, la nuova ingegneria della radicalizzazione
AI come arma cognitiva: dall’ISIS alla tecnodestra, la nuova ingegneria della radicalizzazione
L'IA abbassa le barriere dell'estremismo: ISIS produce deepfake credibili, la tecnodestra “inonda la zona” di contenuti alternativi. Non più propaganda unidirezionale ma radicalizzazione personalizzata. Ecco come l’intelligenza artificiale sta diventando un moltiplicatore di forza cognitiva
·cybersecurity360.it·
AI come arma cognitiva: dall’ISIS alla tecnodestra, la nuova ingegneria della radicalizzazione
Backup immutabili e offline, che cosa sono e perché possono beffare i ransomware
Backup immutabili e offline, che cosa sono e perché possono beffare i ransomware
I backup immutabili e offline dovrebbero essere una priorità per qualsiasi organizzazione. Costano poco, sono semplici da organizzare e gestire e consentono di riprendere le attività in caso di disastro o di attacco hacker. Tutto quello che c’è da sapere
·cybersecurity360.it·
Backup immutabili e offline, che cosa sono e perché possono beffare i ransomware
New ErrTraffic service enables ClickFix attacks via fake browser glitches
New ErrTraffic service enables ClickFix attacks via fake browser glitches
A new cybercrime tool called ErrTraffic allows threat actors to automate ClickFix attacks by generating 'fake glitches' on compromised websites to lure users into downloading payloads or following malicious instructions
·bleepingcomputer.com·
New ErrTraffic service enables ClickFix attacks via fake browser glitches
Zoom Stealer browser extensions harvest corporate meeting intelligence
Zoom Stealer browser extensions harvest corporate meeting intelligence
A newly discovered campaign, which researchers call Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through 18 extensions that collect online meeting-related data like URLs, IDs, topics, descriptions, and embedded passwords.
·bleepingcomputer.com·
Zoom Stealer browser extensions harvest corporate meeting intelligence
European Space Agency confirms breach of "external servers"
European Space Agency confirms breach of "external servers"
The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described as "unclassified" information on collaborative engineering activities.
·bleepingcomputer.com·
European Space Agency confirms breach of "external servers"
ACN: il report di novembre conferma un quadro di minaccia “a fisarmonica”
ACN: il report di novembre conferma un quadro di minaccia “a fisarmonica”
Il rapporto mensile di CSIRT Italia osserva un declino degli eventi cyber e in particolare degli attacchi a matrice hacktivista, ma il perimetro critico nazionale è ormai bersaglio strutturale. Ecco l'operational summary dell'ACN di novembre 2025 nei dettagli, con il parere dei nostri esperti
·cybersecurity360.it·
ACN: il report di novembre conferma un quadro di minaccia “a fisarmonica”
US cybersecurity experts plead guilty to BlackCat ransomware attacks
US cybersecurity experts plead guilty to BlackCat ransomware attacks
Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.
·bleepingcomputer.com·
US cybersecurity experts plead guilty to BlackCat ransomware attacks
Strategia di spesa dei CISO: trasformare la cyber in un abilitante indispensabile
Strategia di spesa dei CISO: trasformare la cyber in un abilitante indispensabile
Spendere di più non significa spendere bene. Il 99% dei CISO e dei responsabili della sicurezza prevede aumenti, ma serve un cambio di mindset da “spesa” a “investimento strategico”: ROI quantificabile, riduzione del rischio e abilitazione del business per convincere i board
·cybersecurity360.it·
Strategia di spesa dei CISO: trasformare la cyber in un abilitante indispensabile
CISA orders feds to patch MongoBleed flaw exploited in attacks
CISA orders feds to patch MongoBleed flaw exploited in attacks
CISA ordered U.S. federal agencies to patch an actively exploited MongoDB vulnerability (MongoBleed) that can be exploited to steal credentials, API keys, and other sensitive data.
·bleepingcomputer.com·
CISA orders feds to patch MongoBleed flaw exploited in attacks
WebUSB Unpinner: network analysis for the masses
WebUSB Unpinner: network analysis for the masses
In this blog post we will introduce WebUSB Unpinner, an open-source Web application that makes Android network analysis more accessible by leveraging WebUSB. We will explain how to bootstrap the application, which kind of security measures it can bypass and how to better understand its components to benefit as much as possible from this tool. One of the key aspects of WebUSB Unpinner is that it does not require to install any additional tool on the user premises, or to compromise the security of the user device, and it does not require any previous knowledge of Android reverse engineering techniques to be used at its best.
·reversing.works·
WebUSB Unpinner: network analysis for the masses
Asset management: dal parrucchiere al social network, come quantificare ciò che ha valore
Asset management: dal parrucchiere al social network, come quantificare ciò che ha valore
Dal parrucchiere che deve cancellare dati vecchi per il GDPR al social che li usa per profilare: lo stesso dato ha valore diverso per contesto. Un efficace asset management aiuta a effettuare una classificazione strategica per proteggere solo ciò che vale davvero proteggersi. Ecco come
·cybersecurity360.it·
Asset management: dal parrucchiere al social network, come quantificare ciò che ha valore
L’Antitrust ferma Meta su WhatsApp: stop all’esclusione dei chatbot AI rivali
L’Antitrust ferma Meta su WhatsApp: stop all’esclusione dei chatbot AI rivali
Stop cautelare dell'Antitrust alle condizioni WhatsApp che avrebbero escluso chatbot AI rivali. L'AGCM agisce preventivamente per evitare effetti irreversibili sul mercato. Governare l'accesso significa governare l'evoluzione futura dell'ecosistema AI
·cybersecurity360.it·
L’Antitrust ferma Meta su WhatsApp: stop all’esclusione dei chatbot AI rivali
~/docs/browser_fingerprint
~/docs/browser_fingerprint
Analisi tecnica approfondita sul Browser Fingerprinting: dal Canvas Poisoning all'entropia hardware del WebGL. Scopri come gli attaccanti sfruttano le API stateless per il tracciamento avanzato e quali sono le strategie di difesa per esperti di cybersecurity.
·blog.lobsec.com·
~/docs/browser_fingerprint
ACN aggiorna le “specifiche di base” NIS2: cosa devono fare i soggetti interessati
ACN aggiorna le “specifiche di base” NIS2: cosa devono fare i soggetti interessati
Nella sesta riunione del Tavolo per l’attuazione della disciplina NIS è stata adottata la determinazione 379907/2025 che apporta alcuni affinamenti alla precedente determina sulle specifiche di base per adempiere ad alcuni obblighi chiave della NIS2. Sarà applicabile dal 15 gennaio 2026. Che c’è da sapere
·cybersecurity360.it·
ACN aggiorna le “specifiche di base” NIS2: cosa devono fare i soggetti interessati
Chinese state hackers use rootkit to hide ToneShell malware activity
Chinese state hackers use rootkit to hide ToneShell malware activity
A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations.
·bleepingcomputer.com·
Chinese state hackers use rootkit to hide ToneShell malware activity