Over Security

Over Security

34850 bookmarks
Custom sorting
NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain
NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain
La gestione dei fornitori non può essere ridotta a un elenco anagrafico o contrattuale. In ottica NIS2, la criticità di un fornitore dipende dagli asset che gestisce, dai servizi IT che supporta, dagli accessi di cui dispone e dall’impatto che una sua indisponibilità o compromissione può produrre sull’organizzazione
·cybersecurity360.it·
NIS2 e fornitori ICT: criteri per valutare criticità, dipendenze e responsabilità nella supply chain
Claude evade (di nuovo) e compromette tre aziende reali
Claude evade (di nuovo) e compromette tre aziende reali
Sembra proprio che tenere a bada i modelli IA sia complicatissimo e Anthropic sta accumulando una certa esperienza nel settore. L’azienda ha infatti rivelato che alcuni modelli della famiglia Claude sono riusciti ad accedere ai sistemi di tre organizzazioni reali durante esercitazioni di sicurezza, trasformando test che avrebbero dovuto svolgersi in ambienti controllati in vere …
·securityinfo.it·
Claude evade (di nuovo) e compromette tre aziende reali
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
What Happened Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out ...
·blog.bushidotoken.net·
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
La sfida della sovranità digitale fra cyber security e geopolitica
La sfida della sovranità digitale fra cyber security e geopolitica
Perché l'Europa non può più permettersi una sovranità di facciata. Il libro "Guerra profonda" e un avvocato ci aiutano a comprendere gli attori e gli obiettivi di questa nuova trasformazione digitale
·cybersecurity360.it·
La sfida della sovranità digitale fra cyber security e geopolitica
One Adversary: The Moment Nobody Sees
One Adversary: The Moment Nobody Sees
Map any fraud campaign against your org chart and one stage of the attack has no owner. The adversary knows exactly which one — and the most expensive fraud cases live there.
·group-ib.com·
One Adversary: The Moment Nobody Sees
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries.
·bleepingcomputer.com·
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE).
·bleepingcomputer.com·
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.
·bleepingcomputer.com·
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
77 Open VSX extensions found harvesting developer info
77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed.
·bleepingcomputer.com·
77 Open VSX extensions found harvesting developer info
Hackers steal over $130 million by exploiting bug in offline hardware wallets
Hackers steal over $130 million by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms.
·techcrunch.com·
Hackers steal over $130 million by exploiting bug in offline hardware wallets
Varonis Agent IBAC keeps AI agents within their intended boundaries
Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries.
·bleepingcomputer.com·
Varonis Agent IBAC keeps AI agents within their intended boundaries
Top Hack e violazioni di dati: ecco la classifica del 2018
Top Hack e violazioni di dati: ecco la classifica del 2018
L'anno 2018 è ormai un lontano ricordo, eppure ha stabilito un record per quanto riguarda le attività di hacking e di violazioni di dati, le più importanti degli ultimi anni.
·hackerstribe.com·
Top Hack e violazioni di dati: ecco la classifica del 2018
Revenge Porn, quando i ricatti si fanno in rete
Revenge Porn, quando i ricatti si fanno in rete
Il Revenge Porn è la pubblicazione sul web di immagini o video che ritraggono le parti intime di una persona, senza il suo consenso, per vendetta.
·hackerstribe.com·
Revenge Porn, quando i ricatti si fanno in rete
How legitimate cloud platforms enable phishers to bypass MFA
How legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
·securelist.com·
How legitimate cloud platforms enable phishers to bypass MFA
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono
Nessun sistema è immune dai guasti. Il principio del fail secure insegna a progettare applicazioni e infrastrutture che, in caso di errore, proteggano dati e asset critici senza amplificare il rischio. Un approccio che cambia il modo di concepire sicurezza, resilienza e continuità operativa
·cybersecurity360.it·
Fail securely: perché la vera sicurezza si misura quando i sistemi falliscono