Over Security

Over Security

35943 bookmarks
Custom sorting
L’unica soluzione certa è non fidarsi mai
L’unica soluzione certa è non fidarsi mai
Approcciarsi per soluzioni alla sicurezza cyber non fa altro che rinviare l'inevitabile momento in cui tutta quella fiducia assumerà l'amaro sapore della delusione scoprendosi così decisamente malriposta
·cybersecurity360.it·
L’unica soluzione certa è non fidarsi mai
EU fines X $140 million over deceptive blue checkmarks
EU fines X $140 million over deceptive blue checkmarks
The European Commission has fined X €120 million ($140 million) for violating transparency obligations under the Digital Services Act (DSA).
·bleepingcomputer.com·
EU fines X $140 million over deceptive blue checkmarks
Cloudflare blames today's outage on emergency React2Shell patch
Cloudflare blames today's outage on emergency React2Shell patch
Cloudflare has blamed today's outage on the emergency patching of a critical React remote code execution vulnerability, which is now actively exploited in attacks.
·bleepingcomputer.com·
Cloudflare blames today's outage on emergency React2Shell patch
React2Shell critical flaw actively exploited in China-linked attacks
React2Shell critical flaw actively exploited in China-linked attacks
Multiple China-linked threat actors began exploiting the React2Shell vulnerability (CVE-2025-55182) affecting React and Next.js just hours after the max-severity issue was disclosed.
·bleepingcomputer.com·
React2Shell critical flaw actively exploited in China-linked attacks
Rinvio dell’AI Act: i 3 ordini di questioni della semplificazione e la vera posta in gioco
Rinvio dell’AI Act: i 3 ordini di questioni della semplificazione e la vera posta in gioco
La massima tutela dei diritti fondamentali deve andare di pari passo con la capacità del tessuto produttivo europeo di reggere la competizione globale, per evitare un eccesso di regolazione. Esenzioni e alleggerimenti possono tradursi in risparmi, ma nel lungo periodo potrebbero consolidare rapporti di dipendenza strutturale da pochi grandi fornitori. Ecco perché
·cybersecurity360.it·
Rinvio dell’AI Act: i 3 ordini di questioni della semplificazione e la vera posta in gioco
Comandare nel caos: la logica come disciplina nelle crisi digitali
Comandare nel caos: la logica come disciplina nelle crisi digitali
Incidenti informatici, data breach, attacchi ransomware. In questi momenti non basta avere tecnologie: serve un metodo di pensiero che guidi il consiglio di Amministrazione e il management a decidere sotto pressione. Ecco perché la logica diventa disciplina, guida e difesa per decidere nel pieno delle crisi digitali
·cybersecurity360.it·
Comandare nel caos: la logica come disciplina nelle crisi digitali
SMS Phishers Pivot to Points, Taxes, Fake Retailers
SMS Phishers Pivot to Points, Taxes, Fake Retailers
China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites…
·krebsonsecurity.com·
SMS Phishers Pivot to Points, Taxes, Fake Retailers
NCSC's ‘Proactive Notifications’ warns orgs of flaws in exposed devices
NCSC's ‘Proactive Notifications’ warns orgs of flaws in exposed devices
The UK's National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to inform organizations in the country of vulnerabilities present in their environment.
·bleepingcomputer.com·
NCSC's ‘Proactive Notifications’ warns orgs of flaws in exposed devices
Predator spyware uses new infection vector for zero-click attacks
Predator spyware uses new infection vector for zero-click attacks
The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed "Aladdin" that compromised specific targets when simply viewing a malicious advertisement.
·bleepingcomputer.com·
Predator spyware uses new infection vector for zero-click attacks
Socomec DIRIS Digiware M series and Easy Config, PDF XChange Editor vulnerabilities
Socomec DIRIS Digiware M series and Easy Config, PDF XChange Editor vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed an out-of-bounds read vulnerability in PDF XChange Editor, and ten vulnerabilities in Socomec DIRIS Digiware M series and Easy Config products. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.     For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets fr
·blog.talosintelligence.com·
Socomec DIRIS Digiware M series and Easy Config, PDF XChange Editor vulnerabilities
Russia blocks FaceTime and Snapchat over use in terrorist attacks
Russia blocks FaceTime and Snapchat over use in terrorist attacks
Russian telecommunications watchdog Roskomnadzor has blocked access to Apple's FaceTime video conferencing platform and the Snapchat instant messaging service, claiming they're being used to coordinate terrorist attacks.
·bleepingcomputer.com·
Russia blocks FaceTime and Snapchat over use in terrorist attacks
Your year-end infosec wrapped
Your year-end infosec wrapped
Bill explores how our biggest mistakes can be the catalysts for growth that we need. This week’s newsletter promises stories, lessons, and a fresh perspective on failure.
·blog.talosintelligence.com·
Your year-end infosec wrapped
Contractors with hacking records accused of wiping 96 govt databases
Contractors with hacking records accused of wiping 96 govt databases
U.S. prosecutors have charged two Virginia brothers arrested on Wednesday with allegedly conspiring to steal sensitive information and destroy government databases after being fired from their jobs as federal contractors.
·bleepingcomputer.com·
Contractors with hacking records accused of wiping 96 govt databases
How strong password policies secure OT systems against cyber threats
How strong password policies secure OT systems against cyber threats
OT environments rely on aging systems, shared accounts, and remote access, making weak or reused passwords a major attack vector. Specops Software explains how stronger password policies and continuous checks for compromised credentials help secure critical OT infrastructure.
·bleepingcomputer.com·
How strong password policies secure OT systems against cyber threats
Critical React, Next.js flaw lets hackers execute code on servers
Critical React, Next.js flaw lets hackers execute code on servers
A maximum severity vulnerability, dubbed 'React2Shell', in the React Server Components (RSC) 'Flight' protocol allows remote code execution without authentication in React and Next.js applications.
·bleepingcomputer.com·
Critical React, Next.js flaw lets hackers execute code on servers