Over Security

Over Security

36006 bookmarks
Custom sorting
GreyNoise launches free scanner to check if you're part of a botnet
GreyNoise launches free scanner to check if you're part of a botnet
GreyNoise Labs has launched a free tool called GreyNoise IP Check that lets users check if their IP address has been observed in malicious scanning operations, like botnet and residential proxy networks.
·bleepingcomputer.com·
GreyNoise launches free scanner to check if you're part of a botnet
Malicious LLMs empower inexperienced hackers with advanced tools
Malicious LLMs empower inexperienced hackers with advanced tools
Unrestricted large language models (LLMs) like WormGPT 4 and KawaiiGPT are improving their capabilities to generate malicious code, delivering functional scripts for ransomware encryptors and lateral movement.
·bleepingcomputer.com·
Malicious LLMs empower inexperienced hackers with advanced tools
La trappola di Chat Control: minori tutelati, cittadini sorvegliati
La trappola di Chat Control: minori tutelati, cittadini sorvegliati
Via libera europeo a Chat Control tra dubbi e astensioni. Eliminata la scansione obbligatoria delle conversazioni, ma l'impianto normativo mina crittografia e privacy. Le soluzioni privacy-first esistono, eppure prevale il modello della sorveglianza. Facciamo il punto
·cybersecurity360.it·
La trappola di Chat Control: minori tutelati, cittadini sorvegliati
Dal ragionamento all’accountability: la logica come prova documentata
Dal ragionamento all’accountability: la logica come prova documentata
Il ragionamento logico diventa prova scritta e i sillogismi possono trasformarsi in tracce di responsabilità capaci di proteggere, convincere, legittimare. Ecco come la logica operativa della protezione digitale diventa uno strumento operativo
·cybersecurity360.it·
Dal ragionamento all’accountability: la logica come prova documentata
Tomiris wreaks Havoc: New tools and techniques of the APT group
Tomiris wreaks Havoc: New tools and techniques of the APT group
Kaspersky discloses new tools and techniques discovered in 2025 Tomiris activities: multi-language reverse shells, Havoc and AdaptixC2 open-source frameworks, communications via Discord and Telegram.
·securelist.com·
Tomiris wreaks Havoc: New tools and techniques of the APT group
Deepfake e chatbot, serve educazione finanziaria per difendersi: i dati del Crif
Deepfake e chatbot, serve educazione finanziaria per difendersi: i dati del Crif
Deepfake e chatbot ingannevoli sono reati in grado di provocare l'erosione della fiducia nel campo dei servizi finanziari. Ecco perché, secondo il Crif e i nostri esperti, l’educazione finanziaria rappresenta un moltiplicatore di protezione
·cybersecurity360.it·
Deepfake e chatbot, serve educazione finanziaria per difendersi: i dati del Crif
OpenAI discloses API customer data breach via Mixpanel vendor hack
OpenAI discloses API customer data breach via Mixpanel vendor hack
OpenAI is notifying some ChatGPT API customers that limited identifying information was exposed following a breach at its third-party analytics provider Mixpanel.
·bleepingcomputer.com·
OpenAI discloses API customer data breach via Mixpanel vendor hack
Indipendenza delle Autorità privacy: le tre direttrici di riforma per un Garante più resiliente
Indipendenza delle Autorità privacy: le tre direttrici di riforma per un Garante più resiliente
Tre assi di intervento mirano a rafforzare l’architettura istituzionale del Garante italiano, in piena conformità con il GDPR e con gli standard europei. Ecco come assicurare l'indipendenza delle Autorità privacy e una governance resistente di fronte a crisi reputazionali, tra previsioni europee, fragilità nazionali e riforme per la resilienza istituzionale
·cybersecurity360.it·
Indipendenza delle Autorità privacy: le tre direttrici di riforma per un Garante più resiliente
L’AI accelera la risposta agli incidenti: la sfida crescente nei SOC
L’AI accelera la risposta agli incidenti: la sfida crescente nei SOC
Nel cuore dei Security Operations Center, la pressione degli attacchi informatici è diventata travolgente, ma i LLM, pur non sostituendo il processo di Incident Response (IR), lo rafforzano. Ecco il ruolo dell'AI e la sfida crescente nei SOC
·cybersecurity360.it·
L’AI accelera la risposta agli incidenti: la sfida crescente nei SOC
China Software Developer Network - 6,414,990 breached accounts
China Software Developer Network - 6,414,990 breached accounts
In 2011, the China Software Developer Network (CSDN) suffered a data breach that exposed over 6M user records. The data included email addresses alongside usernames and plain text passwords.
·haveibeenpwned.com·
China Software Developer Network - 6,414,990 breached accounts
New ShadowV2 botnet malware used AWS outage as a test opportunity
New ShadowV2 botnet malware used AWS outage as a test opportunity
A new Mirai-based botnet malware named 'ShadowV2' has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities.
·bleepingcomputer.com·
New ShadowV2 botnet malware used AWS outage as a test opportunity
NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025
NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025
The NordVPN Black Friday Deal is now live, and you can get the best discount available: 77% off that applies automatically when you follow our link. If you've been waiting for the right moment to upgrade your online security, privacy, and streaming freedom, this is the one VPN deals this Black Friday.
·bleepingcomputer.com·
NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025
Popular Forge library gets fix for signature verification bypass flaw
Popular Forge library gets fix for signature verification bypass flaw
A vulnerability in the 'node-forge' package, a popular JavaScript cryptography library, could be exploited to bypass signature verifications by crafting data that appears valid.
·bleepingcomputer.com·
Popular Forge library gets fix for signature verification bypass flaw
Dell ControlVault, Lasso, GL.iNet vulnerabilities
Dell ControlVault, Lasso, GL.iNet vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed five vulnerabilities in Dell ControlVault 3 firmware and its associated Windows software, four vulnerabilities in Entr'ouvert Lasso, and one vulnerability in GL.iNet Slate AX. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.     For Snort coverage that can detect the exploitation of these vulnerabilities,
·blog.talosintelligence.com·
Dell ControlVault, Lasso, GL.iNet vulnerabilities
Comcast to pay $1.5M fine for vendor breach affecting 270K customers
Comcast to pay $1.5M fine for vendor breach affecting 270K customers
Comcast will pay a $1.5 million fine to settle a Federal Communications Commission investigation into a February 2024 vendor data breach that exposed the personal information of nearly 275,000 customers.
·bleepingcomputer.com·
Comcast to pay $1.5M fine for vendor breach affecting 270K customers
Multiple London councils' IT systems disrupted by cyberattack
Multiple London councils' IT systems disrupted by cyberattack
The Royal Borough of Kensington and Chelsea (RBKC) and the Westminster City Council (WCC) announced that they are experiencing service disruptions following a cybersecurity issue.
·bleepingcomputer.com·
Multiple London councils' IT systems disrupted by cyberattack
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
A prolific cybercriminal group that calls itself "Scattered LAPSUS$ Hunters" made headlines regularly this year by stealing data from and publicly mass extorting dozens of major corporations. But the tables seem to have turned somewhat for "Rey," the moniker chosen…
·krebsonsecurity.com·
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
Care that you share
Care that you share
This holiday season, as teams run lean and cyber threats rise, being open with what — and how — you share can protect both information and relationships.
·blog.talosintelligence.com·
Care that you share
Sentinelle digitali: ai whistleblower la vigilanza sull’etica dell’IA in azienda
Sentinelle digitali: ai whistleblower la vigilanza sull’etica dell’IA in azienda
L'Europa alza la posta sulla trasparenza e l'etica dell’intelligenza artificiale, attivando un nuovo strumento protetto di segnalazione (whistleblowing) specificamente dedicato alle violazioni dell'AI Act e che trasforma gli insider da figure marginali a elementi centrali della governance europea. Ecco perché
·cybersecurity360.it·
Sentinelle digitali: ai whistleblower la vigilanza sull’etica dell’IA in azienda