Over Security

Over Security

35022 bookmarks
Custom sorting
Sextortion e responsabilità delle piattaforme: quando il danno diventa prevedibile
Sextortion e responsabilità delle piattaforme: quando il danno diventa prevedibile
Meta e Match citate in giudizio in due casi diversi: il contenzioso punta a qualificare i danni come esito prevedibile di scelte di prodotto, procedure e priorità aziendali. Ecco perché si contesta la responsabilità delle piattaforme digitali sul tema della progettazione e gestione del servizio, anziché sul terreno tradizionale dei “contenuti”
·cybersecurity360.it·
Sextortion e responsabilità delle piattaforme: quando il danno diventa prevedibile
La necessaria revisione periodica delle misure di sicurezza di base per la conformità alla NIS 2
La necessaria revisione periodica delle misure di sicurezza di base per la conformità alla NIS 2
La natura ciclica della sicurezza NIS 2 non è un insieme di documenti, ma un sistema vivo, destinato a evolvere nel tempo. Ecco come la revisione periodica delle procedure è lo strumento attraverso cui si esercita un vero comando, coerente con la governance del rischio e con la visione sistemica del decreto NIS
·cybersecurity360.it·
La necessaria revisione periodica delle misure di sicurezza di base per la conformità alla NIS 2
From cheats to exploits: Webrat spreading via GitHub
From cheats to exploits: Webrat spreading via GitHub
We dissect the new Webrat campaign where the Trojan spreads via GitHub repositories, masquerading as critical vulnerability exploits to target cybersecurity researchers.
·securelist.com·
From cheats to exploits: Webrat spreading via GitHub
Nissan says thousands of customers exposed in Red Hat breach
Nissan says thousands of customers exposed in Red Hat breach
Nissan Motor Co. Ltd. (Nissan) has confirmed that information of thousands of its customers has been compromised after the data breach at Red Hat in September.
·bleepingcomputer.com·
Nissan says thousands of customers exposed in Red Hat breach
New MacSync malware dropper evades macOS Gatekeeper checks
New MacSync malware dropper evades macOS Gatekeeper checks
The latest variant of the MacSync information stealer targeting macOS systems is delivered through a digitally signed, notarized Swift application.
·bleepingcomputer.com·
New MacSync malware dropper evades macOS Gatekeeper checks
CISA flags ASUS Live Update CVE, but the attack is years old
CISA flags ASUS Live Update CVE, but the attack is years old
An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. A closer look, however, shows the CVE documents a historic supply-chain attack in an End-of-Life (EoL) software product, not a new attack.
·bleepingcomputer.com·
CISA flags ASUS Live Update CVE, but the attack is years old
Interpol-led action decrypts 6 ransomware strains, arrests hundreds
Interpol-led action decrypts 6 ransomware strains, arrests hundreds
An Interpol-coordinated initiative called Operation Sentinel led to the arrest of 574 individuals and the recovery of $3 million linked to business email compromise, extortion, and ransomware incidents.
·bleepingcomputer.com·
Interpol-led action decrypts 6 ransomware strains, arrests hundreds
Device Code Phishing: la minaccia che non ruba password, ma compromette gli account utente
Device Code Phishing: la minaccia che non ruba password, ma compromette gli account utente
Il phishing del codice dispositivo provoca la compromissione dell’account, l’esfiltrazione di dati e molto altro ancora. Ecco come proteggersi dal Device Code Phishing, la forma di phishing che non ruba la password, ma si fa regalare un token OAuth dall’utente
·cybersecurity360.it·
Device Code Phishing: la minaccia che non ruba password, ma compromette gli account utente
Cyber security: com’è cambiata e cosa aspettarsi per il futuro, con uno sguardo all’AI
Cyber security: com’è cambiata e cosa aspettarsi per il futuro, con uno sguardo all’AI
In soli dieci anni, dal 2015 al 2025, la cyber security ha subito una profonda trasformazione guidata dall’evoluzione tecnologica e dalla maturazione del crimine informatico e in cui, negli ultimi tempi, sta giocando un ruolo di primo piano l’intelligenza artificiale
·cybersecurity360.it·
Cyber security: com’è cambiata e cosa aspettarsi per il futuro, con uno sguardo all’AI
Malicious npm package steals WhatsApp accounts and messages
Malicious npm package steals WhatsApp accounts and messages
A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal WhatsApp messages, collect contacts, and gain access to the account.
·bleepingcomputer.com·
Malicious npm package steals WhatsApp accounts and messages
Romanian water authority hit by ransomware attack over weekend
Romanian water authority hit by ransomware attack over weekend
Romanian Waters (Administrația Națională Apele Române), the country's water management authority, was hit by a ransomware attack over the weekend.
·bleepingcomputer.com·
Romanian water authority hit by ransomware attack over weekend
Coupang breach affecting 33.7 million users raises data protection questions
Coupang breach affecting 33.7 million users raises data protection questions
Coupang disclosed a data breach affecting 33.7 million customers after unauthorized access to personal data went undetected for nearly five months. Penta Security explains how the incident highlights insider credential abuse risks and why encrypting customer data beyond legal requirements can reduce exposure and limit damage.
·bleepingcomputer.com·
Coupang breach affecting 33.7 million users raises data protection questions
Phishing 2.0, l’era degli LLM: i rischi e come difendersi
Phishing 2.0, l’era degli LLM: i rischi e come difendersi
Con l’avvento degli LLM, le e-mail di phishing diventano più convincenti, ma modelli ibridi e semantici possano smascherare truffe generate dall’intelligenza artificiale e rafforzare la difesa delle organizzazioni. Ecco tutto quello che c’è da sapere
·cybersecurity360.it·
Phishing 2.0, l’era degli LLM: i rischi e come difendersi
Not all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374
Not all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374
An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. A closer look, however, shows the CVE documents a historic supply-chain attack in an End-of-Life (EoL) software product, not a new attack.
·bleepingcomputer.com·
Not all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374
Strategic Sourcing e governance del rischio cyber: una gestione sostenibile delle terze parti digitali
Strategic Sourcing e governance del rischio cyber: una gestione sostenibile delle terze parti digitali
I processi di sourcing strategico possono supportare la cyber security e il Third-Party Risk Management: un framework integrato per una gestione sostenibile e responsabile delle terze parti digitali. Ecco i principali riferimenti normativi europei e gli standard internazionali in materia di sicurezza e risk management, per una governance che coniuga efficacia operativa, conformità e sostenibilità
·cybersecurity360.it·
Strategic Sourcing e governance del rischio cyber: una gestione sostenibile delle terze parti digitali
Ukrainian hacker admits affiliate role in Nefilim ransomware gang
Ukrainian hacker admits affiliate role in Nefilim ransomware gang
A Ukrainian national pleaded guilty on Friday to conducting Nefilim ransomware attacks that targeted high-revenue businesses across the United States and other countries.
·bleepingcomputer.com·
Ukrainian hacker admits affiliate role in Nefilim ransomware gang
Critical RCE flaw impacts over 115,000 WatchGuard firewalls
Critical RCE flaw impacts over 115,000 WatchGuard firewalls
Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical remote code execution (RCE) vulnerability actively exploited in attacks.
·bleepingcomputer.com·
Critical RCE flaw impacts over 115,000 WatchGuard firewalls
La nuova frontiera cyber del terrorismo: ora c’è anche l’intelligenza artificiale
La nuova frontiera cyber del terrorismo: ora c’è anche l’intelligenza artificiale
Cyber security e contrasto alle organizzazioni terroristiche, che con le nuove tecnologie adesso puntano su attacchi a infrastrutture e propaganda. Come cambiano l'intelligence e le strategie di difesa. Tutte le sfide nella nuova era digitale che stiamo vivendo
·cybersecurity360.it·
La nuova frontiera cyber del terrorismo: ora c’è anche l’intelligenza artificiale