Over Security

Over Security

34849 bookmarks
Custom sorting
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.
·bleepingcomputer.com·
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
After the Break-In: What Attackers Do Once They're Already Inside
After the Break-In: What Attackers Do Once They're Already Inside
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware.
·bleepingcomputer.com·
After the Break-In: What Attackers Do Once They're Already Inside
Black Hat special: Rewind and revisit
Black Hat special: Rewind and revisit
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
·blog.talosintelligence.com·
Black Hat special: Rewind and revisit
Bug bounty nell’era AI: come sta cambiando la ricerca di vulnerabilità
Bug bounty nell’era AI: come sta cambiando la ricerca di vulnerabilità
La diffusione di strumenti di intelligenza artificiale generativa, che provocano un aumento esponenziale di segnalazioni a basso valore aggiunto, e i modelli AI più avanzati, che stanno iniziando a individuare vulnerabilità reali, riproducibili e sfruttabili con rapidità: due tendenze in evoluzione che ridefiniscono il ruolo del bug bounty
·cybersecurity360.it·
Bug bounty nell’era AI: come sta cambiando la ricerca di vulnerabilità
L’Italia invasa dai data center
L’Italia invasa dai data center
È possibile conciliare la crescita delle infrastrutture necessarie all’intelligenza artificiale con la tutela del territorio? Tutte le contraddizioni e le sfide di uno sviluppo ancora privo di regole chiare.
·guerredirete.it·
L’Italia invasa dai data center
Toy Ghouls’ new toy: the GenieLocker ransomware
Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
·securelist.com·
Toy Ghouls’ new toy: the GenieLocker ransomware
Polizia italiana con l’intelligenza artificiale: tutti i nodi giuridici
Polizia italiana con l’intelligenza artificiale: tutti i nodi giuridici
Il Senato dà il primo via libera allo schema di decreto sull’uso dell’intelligenza artificiale nelle attività di polizia, mentre il Garante Privacy chiede modifiche profonde su biometria, banche dati, riconoscimento facciale e garanzie di controllo previste dall’AI Act. Ecco i termini dello scontro, che preoccupano
·cybersecurity360.it·
Polizia italiana con l’intelligenza artificiale: tutti i nodi giuridici
French Attack Surge: Unpacking the Drivers Behind the Spike in Data Leak Claims Against French Targets
French Attack Surge: Unpacking the Drivers Behind the Spike in Data Leak Claims Against French Targets
Executive Summary Between October 2025 and March 2026 (Q4 2025 – Q1 2026), the analysis of activities observed within underground forums monitored by Yarix’s Cyber Threat Intelligence Team revealed a significant increase in publications related to alleged data leaks affecting French targets, with a…
·labs.yarix.com·
French Attack Surge: Unpacking the Drivers Behind the Spike in Data Leak Claims Against French Targets
Cloud repatriation: perché sovranità dei dati e compliance stanno cambiando il cloud
Cloud repatriation: perché sovranità dei dati e compliance stanno cambiando il cloud
Le organizzazioni stanno rivalutando dove collocare i propri workload, riportandone una parte dai public cloud iperscalabili verso infrastrutture on-premises, private cloud o data center in colocation. Ecco cos'è il fenomeno della cloud repatriation e cosa implica
·cybersecurity360.it·
Cloud repatriation: perché sovranità dei dati e compliance stanno cambiando il cloud
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
·bleepingcomputer.com·
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.
·bleepingcomputer.com·
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts and steal data from cloud services.
·bleepingcomputer.com·
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare