Over Security

Over Security

35972 bookmarks
Custom sorting
Fake Calendly invites spoof top brands to hijack ad manager accounts
Fake Calendly invites spoof top brands to hijack ad manager accounts
An ongoing phishing campaign impersonates popular brands, such as Unilever, Disney, MasterCard, LVMH, and Uber, in Calendly-themed lures to steal Google Workspace and Facebook business account credentials.
·bleepingcomputer.com·
Fake Calendly invites spoof top brands to hijack ad manager accounts
University of Pennsylvania confirms new data breach after Oracle hack
University of Pennsylvania confirms new data breach after Oracle hack
​The University of Pennsylvania (Penn) has confirmed a new data breach after attackers stole documents containing personal information from its Oracle E-Business Suite servers in August.
·bleepingcomputer.com·
University of Pennsylvania confirms new data breach after Oracle hack
Cultura aziendale e cyber security: la lezione di Nokia per i CISO del futuro
Cultura aziendale e cyber security: la lezione di Nokia per i CISO del futuro
La cultura aziendale influenza la percezione del programma di sicurezza a tutti i livelli e spesso riflette la personalità del CISO stesso. La sfida è integrare abitudini e convinzioni di sicurezza attraverso flessibilità culturale, documentazione formale e comunicazione efficace. Ecco come
·cybersecurity360.it·
Cultura aziendale e cyber security: la lezione di Nokia per i CISO del futuro
Windows 11 KB5070311 update fixes File Explorer freezes, search issues
Windows 11 KB5070311 update fixes File Explorer freezes, search issues
​​Microsoft has released the KB5070311 preview cumulative update for Windows 11 systems, which includes 49 changes, including fixes for File Explorer freezes and search issues.
·bleepingcomputer.com·
Windows 11 KB5070311 update fixes File Explorer freezes, search issues
Kaspersky Security Bulletin 2025. Statistics
Kaspersky Security Bulletin 2025. Statistics
Kaspersky Security Bulletin contains statistics on various cyberthreats for the period from November 2024 to October 2025, which are based on anonymized data voluntarily provided by Kaspersky users via Kaspersky Security Network (KSN).
·securelist.com·
Kaspersky Security Bulletin 2025. Statistics
Gestire gli incidenti significativi: la matrice operativa per la conformità NIS 2
Gestire gli incidenti significativi: la matrice operativa per la conformità NIS 2
La sicurezza non vive nei documenti ma nei sistemi che li mettono in relazione. Ecco come passare dalla Business Impact Analysis alla notifica di un incidente significativo mediante una matrice operativa che correla impatti, tempi di continuità e livelli di servizio
·cybersecurity360.it·
Gestire gli incidenti significativi: la matrice operativa per la conformità NIS 2
Glassworm malware returns in third wave of malicious VS Code packages
Glassworm malware returns in third wave of malicious VS Code packages
The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now in its third wave, with 24 new packages added on the two platforms.
·bleepingcomputer.com·
Glassworm malware returns in third wave of malicious VS Code packages
Project Reboot
Project Reboot
A rescue themed hacking lab
·mandomat.github.io·
Project Reboot
SmartTube YouTube app for Android TV breached to push malicious update
SmartTube YouTube app for Android TV breached to push malicious update
The popular open-source SmartTube YouTube client for Android TV was compromised after an attacker gained access to the developer's signing keys, leading to a malicious update being pushed to users.
·bleepingcomputer.com·
SmartTube YouTube app for Android TV breached to push malicious update
Luci e ombre nel whistleblowing per le violazioni dell’AI Act: le 4 questioni aperte
Luci e ombre nel whistleblowing per le violazioni dell’AI Act: le 4 questioni aperte
Il debutto del sistema di whistleblowing per l’AI Act prevede un canale sicuro e crittografato gestito dall’European AI Office per la segnalazione delle violazioni della normativa sull’intelligenza artificiale. Ecco opportunità e problematiche legate alla protezione legale, attiva dal 2 agosto dell'anno prossimo
·cybersecurity360.it·
Luci e ombre nel whistleblowing per le violazioni dell’AI Act: le 4 questioni aperte
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats
Hackers impersonate IT pros with deepfakes, fake resumes, and stolen identities, turning hiring pipelines into insider threats. Huntres sLabs explains how stronger vetting and access controls help stop these threats.
·bleepingcomputer.com·
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats
ShadyPanda browser extensions amass 4.3M installs in malicious campaign
ShadyPanda browser extensions amass 4.3M installs in malicious campaign
A long-running malware operation known as "ShadyPanda" has amassed over 4.3 million installations of seemingly legitimate Chrome and Edge browser extensions that evolved into malware.
·bleepingcomputer.com·
ShadyPanda browser extensions amass 4.3M installs in malicious campaign
Il tempo delle evidenze documentali
Il tempo delle evidenze documentali
Il tempo per documentare la gestione della sicurezza non dev'essere visto come un costo ma come un investimento, motivo per cui va affrontato tenendo conto della raccolta delle evidenze documentali necessarie all'attuazione degli obiettivi strategici dell'organizzazione. Altrimenti, il rischio è che si abbiano punti ciechi
·cybersecurity360.it·
Il tempo delle evidenze documentali