Over Security

Over Security

35988 bookmarks
Custom sorting
A practical Cisco NDO multi-site use case: config deploy
A practical Cisco NDO multi-site use case: config deploy
At this stage, we can build the configuration: ./build-nac-data.py If everything runs successfully, the script completes silently (“no news is good news”), creating or updating files under nac-data and site-* directories.
·adainese.it·
A practical Cisco NDO multi-site use case: config deploy
Japanese beer giant Asahi says data breach hit 1.5 million people
Japanese beer giant Asahi says data breach hit 1.5 million people
Asahi Group Holdings, Japan's largest beer producer, has finished the investigation into the September cyberattack and found that the incident has impacted up to 1.9 million individuals.
·bleepingcomputer.com·
Japanese beer giant Asahi says data breach hit 1.5 million people
Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison
Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison
A 44-year-old man was sentenced to seven years and four months in prison for operating an "evil twin" WiFi network to steal the data of unsuspecting travelers at various airports across Australia.
·bleepingcomputer.com·
Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison
Microsoft: Windows updates make password login option invisible
Microsoft: Windows updates make password login option invisible
Microsoft warned users that Windows 11 updates released since August may cause the password sign-in option to disappear from the lock screen options, even though the button remains functional.
·bleepingcomputer.com·
Microsoft: Windows updates make password login option invisible
Public GitLab repositories exposed more than 17,000 secrets
Public GitLab repositories exposed more than 17,000 secrets
After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains.
·bleepingcomputer.com·
Public GitLab repositories exposed more than 17,000 secrets
French Football Federation discloses data breach after cyberattack
French Football Federation discloses data breach after cyberattack
The French Football Federation (FFF) disclosed a data breach on Friday after attackers used a compromised account to gain access to administrative management software used by football clubs.
·bleepingcomputer.com·
French Football Federation discloses data breach after cyberattack
Il nuovo strumento di whistleblowing per l’AI Act: cos’è e come funziona
Il nuovo strumento di whistleblowing per l’AI Act: cos’è e come funziona
La Commissione UE lancia il sistema di whistleblowing per l'AI Act: un canale sicuro e crittografato gestito dall'European AI Office per segnalare violazioni della normativa sull'intelligenza artificiale. La protezione legale sarà attiva dal 2 agosto 2026. Ecco tutto quello che c’è da sapere
·cybersecurity360.it·
Il nuovo strumento di whistleblowing per l’AI Act: cos’è e come funziona
GreyNoise launches free scanner to check if you're part of a botnet
GreyNoise launches free scanner to check if you're part of a botnet
GreyNoise Labs has launched a free tool called GreyNoise IP Check that lets users check if their IP address has been observed in malicious scanning operations, like botnet and residential proxy networks.
·bleepingcomputer.com·
GreyNoise launches free scanner to check if you're part of a botnet
Malicious LLMs empower inexperienced hackers with advanced tools
Malicious LLMs empower inexperienced hackers with advanced tools
Unrestricted large language models (LLMs) like WormGPT 4 and KawaiiGPT are improving their capabilities to generate malicious code, delivering functional scripts for ransomware encryptors and lateral movement.
·bleepingcomputer.com·
Malicious LLMs empower inexperienced hackers with advanced tools
La trappola di Chat Control: minori tutelati, cittadini sorvegliati
La trappola di Chat Control: minori tutelati, cittadini sorvegliati
Via libera europeo a Chat Control tra dubbi e astensioni. Eliminata la scansione obbligatoria delle conversazioni, ma l'impianto normativo mina crittografia e privacy. Le soluzioni privacy-first esistono, eppure prevale il modello della sorveglianza. Facciamo il punto
·cybersecurity360.it·
La trappola di Chat Control: minori tutelati, cittadini sorvegliati
Dal ragionamento all’accountability: la logica come prova documentata
Dal ragionamento all’accountability: la logica come prova documentata
Il ragionamento logico diventa prova scritta e i sillogismi possono trasformarsi in tracce di responsabilità capaci di proteggere, convincere, legittimare. Ecco come la logica operativa della protezione digitale diventa uno strumento operativo
·cybersecurity360.it·
Dal ragionamento all’accountability: la logica come prova documentata
Tomiris wreaks Havoc: New tools and techniques of the APT group
Tomiris wreaks Havoc: New tools and techniques of the APT group
Kaspersky discloses new tools and techniques discovered in 2025 Tomiris activities: multi-language reverse shells, Havoc and AdaptixC2 open-source frameworks, communications via Discord and Telegram.
·securelist.com·
Tomiris wreaks Havoc: New tools and techniques of the APT group
Deepfake e chatbot, serve educazione finanziaria per difendersi: i dati del Crif
Deepfake e chatbot, serve educazione finanziaria per difendersi: i dati del Crif
Deepfake e chatbot ingannevoli sono reati in grado di provocare l'erosione della fiducia nel campo dei servizi finanziari. Ecco perché, secondo il Crif e i nostri esperti, l’educazione finanziaria rappresenta un moltiplicatore di protezione
·cybersecurity360.it·
Deepfake e chatbot, serve educazione finanziaria per difendersi: i dati del Crif
OpenAI discloses API customer data breach via Mixpanel vendor hack
OpenAI discloses API customer data breach via Mixpanel vendor hack
OpenAI is notifying some ChatGPT API customers that limited identifying information was exposed following a breach at its third-party analytics provider Mixpanel.
·bleepingcomputer.com·
OpenAI discloses API customer data breach via Mixpanel vendor hack
Indipendenza delle Autorità privacy: le tre direttrici di riforma per un Garante più resiliente
Indipendenza delle Autorità privacy: le tre direttrici di riforma per un Garante più resiliente
Tre assi di intervento mirano a rafforzare l’architettura istituzionale del Garante italiano, in piena conformità con il GDPR e con gli standard europei. Ecco come assicurare l'indipendenza delle Autorità privacy e una governance resistente di fronte a crisi reputazionali, tra previsioni europee, fragilità nazionali e riforme per la resilienza istituzionale
·cybersecurity360.it·
Indipendenza delle Autorità privacy: le tre direttrici di riforma per un Garante più resiliente
L’AI accelera la risposta agli incidenti: la sfida crescente nei SOC
L’AI accelera la risposta agli incidenti: la sfida crescente nei SOC
Nel cuore dei Security Operations Center, la pressione degli attacchi informatici è diventata travolgente, ma i LLM, pur non sostituendo il processo di Incident Response (IR), lo rafforzano. Ecco il ruolo dell'AI e la sfida crescente nei SOC
·cybersecurity360.it·
L’AI accelera la risposta agli incidenti: la sfida crescente nei SOC
China Software Developer Network - 6,414,990 breached accounts
China Software Developer Network - 6,414,990 breached accounts
In 2011, the China Software Developer Network (CSDN) suffered a data breach that exposed over 6M user records. The data included email addresses alongside usernames and plain text passwords.
·haveibeenpwned.com·
China Software Developer Network - 6,414,990 breached accounts
New ShadowV2 botnet malware used AWS outage as a test opportunity
New ShadowV2 botnet malware used AWS outage as a test opportunity
A new Mirai-based botnet malware named 'ShadowV2' has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities.
·bleepingcomputer.com·
New ShadowV2 botnet malware used AWS outage as a test opportunity