Over Security

Over Security

34848 bookmarks
Custom sorting
Recently patched PaperCut zero-days used in data theft attacks
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
·bleepingcomputer.com·
Recently patched PaperCut zero-days used in data theft attacks
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Nei servizi di ascolto e segnalazione per soggetti vulnerabili, il “pulsante di aiuto” sui siti web degli Enti del terzo settore non è una pagina di contatti. Ecco il perimetro giuridico del problema, le 4 posizioni soggettive coinvolte e il rapporto fra anonimato e possibilità concreta di prestare aiuto
·cybersecurity360.it·
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Questel - 1,226,209 breached accounts
Questel - 1,226,209 breached accounts
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
·haveibeenpwned.com·
Questel - 1,226,209 breached accounts
Vulnerability & Patch Roundup — August 2026
Vulnerability & Patch Roundup — August 2026
Discover important WordPress vulnerabilities in August 2026 and how to safeguard your site with essential security updates.
·blog.sucuri.net·
Vulnerability & Patch Roundup — August 2026
Cronos blockchain restarts after $74 million Tectonic exploit
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million.
·bleepingcomputer.com·
Cronos blockchain restarts after $74 million Tectonic exploit
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.
·bleepingcomputer.com·
Microsoft warns of TerminalFix attacks deploying reverse tunnels
OpenAI confirms ChatGPT outage as users report errors
OpenAI confirms ChatGPT outage as users report errors
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks.
·bleepingcomputer.com·
OpenAI confirms ChatGPT outage as users report errors
How AI could make it harder for governments to use hacking tools
How AI could make it harder for governments to use hacking tools
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.
·techcrunch.com·
How AI could make it harder for governments to use hacking tools
Cyber attacco agli aeroporti britannici: a rischio i dati dei passeggeri in transito
Cyber attacco agli aeroporti britannici: a rischio i dati dei passeggeri in transito
Non risultano esposti dati bancari o di pagamento: il cyber attacco possono diventare una fonte preziosa di intelligence non avrebbe compromesso la sicurezza dei voli né le operazioni aeroportuali. Ma proprio questo dimostra come sistemi periferici possano diventare una fonte preziosa di intelligence. Ecco qual è il vero rischio cyber
·cybersecurity360.it·
Cyber attacco agli aeroporti britannici: a rischio i dati dei passeggeri in transito
Chinese Fire Ant hackers turn Cisco routers into spying platforms
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history.
·bleepingcomputer.com·
Chinese Fire Ant hackers turn Cisco routers into spying platforms
File servers are here to stay. Here’s how to manage them securely
File servers are here to stay. Here’s how to manage them securely
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access.
·bleepingcomputer.com·
File servers are here to stay. Here’s how to manage them securely
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site.
·bleepingcomputer.com·
Berlin confirms data theft after Rhysida ransomware attack claims
Reward hacking: i confini incerti degli agenti AI autonomi nella sicurezza
Reward hacking: i confini incerti degli agenti AI autonomi nella sicurezza
Nel caso Hugging Face, gli agenti AI hanno trattato il confine dell'ambiente di test come un ostacolo tra loro e il punteggio massimo. Ecco i precedenti e il fenomeno del Reward hacking nell'era degli agenti AI, pronti a trattare ogni confine, tecnico o procedurale, come un elemento dell'ambiente da aggirare per massimizzare il punteggio
·cybersecurity360.it·
Reward hacking: i confini incerti degli agenti AI autonomi nella sicurezza
Ecco il Polo Italiano per il Cyber e lo Spazio. Ma ora si deve fare sistema
Ecco il Polo Italiano per il Cyber e lo Spazio. Ma ora si deve fare sistema
Il direttore del PICS, Luigi Martino, spiega quali sono i cinque pilastri su cui si fonda il neonato organismo, come l'Italia può valorizzare quello che già esiste nel settore e i nodi da sciogliere per trasformare questa visione in realtà
·cybersecurity360.it·
Ecco il Polo Italiano per il Cyber e lo Spazio. Ma ora si deve fare sistema
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update.
·bleepingcomputer.com·
Microsoft says Windows 11 KB5120998 update resets mouse settings
Shadow IT e organizzazione reale: cosa succede quando la procedura non governa più
Shadow IT e organizzazione reale: cosa succede quando la procedura non governa più
La recente sentenza del Tribunale di Udine non riguarda solo l'uso di WhatsApp nei rapporti di lavoro o una controversia disciplinare nata da una comunicazione attraverso un canale improprio, ma la progressiva perdita di coincidenza tra organizzazione formale e quella realmente operante. Ecco cosa mette in luce il provvedimento
·cybersecurity360.it·
Shadow IT e organizzazione reale: cosa succede quando la procedura non governa più
ValleyRAT masquerading as adware
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
·securelist.com·
ValleyRAT masquerading as adware