Over Security

Over Security

34849 bookmarks
Custom sorting
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months…
·krebsonsecurity.com·
Lessons Learned from CISA’s Recent GitHub Leak
Lidl discloses online shop breach after service provider hack
Lidl discloses online shop breach after service provider hack
German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider.
·bleepingcomputer.com·
Lidl discloses online shop breach after service provider hack
Oltre 15 anni di cyber attacchi russi contro l’Europa: arriva la sanzione UE
Oltre 15 anni di cyber attacchi russi contro l’Europa: arriva la sanzione UE
L'UE sanziona ufficiali dei servizi segreti russi per quindici anni di attacchi cyber contro gli Stati Membri: un'azione che non blocca le operazioni, ma crea un precedente giuridico e politico che rende più difficile negare l'attribuzione in futuro. Ecco il ruolo degli attacchi cyber russi nella guerra ibrida per destabilizzare l'UE
·cybersecurity360.it·
Oltre 15 anni di cyber attacchi russi contro l’Europa: arriva la sanzione UE
Breach at the Beach: Play the Ultimate Entra ID CTF
Breach at the Beach: Play the Ultimate Entra ID CTF
Learn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios.
·bleepingcomputer.com·
Breach at the Beach: Play the Ultimate Entra ID CTF
GigaWiper, la piattaforma malware che spia e distrugge i sistemi compromessi
GigaWiper, la piattaforma malware che spia e distrugge i sistemi compromessi
I laboratori di Threat Intelligence Microsoft hanno identificato il nuovo malware GigaWiper che, oltre alla capacità di cancellare dati, si caratterizza per la sua architettura modulare che combina funzionalità di accesso remoto, spionaggio e distruzione dei sistemi compromessi. Ecco tutti i dettagli e i consigli per difendersi
·cybersecurity360.it·
GigaWiper, la piattaforma malware che spia e distrugge i sistemi compromessi
UK charges suspects linked to Russian Coms call spoofing platform
UK charges suspects linked to Russian Coms call spoofing platform
UK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls.
·bleepingcomputer.com·
UK charges suspects linked to Russian Coms call spoofing platform
VPN veloce: con NordVPN 75% di sconto e 3 mesi extra
VPN veloce: con NordVPN 75% di sconto e 3 mesi extra
NordVPN propone un'offerta per avere per 2 anni una VPN veloce e affidabile disponibile oggi con il 75% di sconto e 3 mesi extra.
·cybersecurity360.it·
VPN veloce: con NordVPN 75% di sconto e 3 mesi extra
EU sanctions Russian GRU military hackers over cyberattacks
EU sanctions Russian GRU military hackers over cyberattacks
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe.
·bleepingcomputer.com·
EU sanctions Russian GRU military hackers over cyberattacks
US and allies warn of Russian critical infrastructure attacks
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks.
·bleepingcomputer.com·
US and allies warn of Russian critical infrastructure attacks
Le vulnerabilità delle periferiche wireless a cui (quasi) nessuno pensa
Le vulnerabilità delle periferiche wireless a cui (quasi) nessuno pensa
L'Istituto nazionale elvetico di test per la cibersicurezza NCT rivela come tastiere, mouse e cuffie senza fili possano diventare pericolose porte d'accesso per gli attaccanti. Cosa sapere e perché tenerne conto
·cybersecurity360.it·
Le vulnerabilità delle periferiche wireless a cui (quasi) nessuno pensa
Prompt injection negli atti giudiziari: quando il documento processuale diventa vettore d’attacco
Prompt injection negli atti giudiziari: quando il documento processuale diventa vettore d’attacco
Il caso Galileu vede un atto processuale, destinato alla lettura umana, diventare materiale elaborabile da strumenti automatici. Se diventasse input computazionale, potrebbe diventare payload. Ecco le conseguenze tecniche, giuridiche e deontologiche per magistrati, PA, avvocati, consulenti tecnici e fornitori di soluzioni legal-tech
·cybersecurity360.it·
Prompt injection negli atti giudiziari: quando il documento processuale diventa vettore d’attacco
Vishing Call Becomes Key Lead in Massive Odido Cyberattack
Vishing Call Becomes Key Lead in Massive Odido Cyberattack
The Odido cyberattack investigation has revealed possible involvement of Dutch nationals as police continue probing the ShinyHunters attack.
·thecyberexpress.com·
Vishing Call Becomes Key Lead in Massive Odido Cyberattack
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
OpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company's most powerful model surged over the past 48 hours.
·bleepingcomputer.com·
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
RedHook Android malware now uses Wireless ADB for shell access
RedHook Android malware now uses Wireless ADB for shell access
A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection.
·bleepingcomputer.com·
RedHook Android malware now uses Wireless ADB for shell access
È possibile decolonizzare l’intelligenza artificiale?
È possibile decolonizzare l’intelligenza artificiale?
Organizzazioni e collettivi non occidentali vogliono sfruttare le potenzialità delle intelligenze artificiali generative svincolandosi però da Big Tech. Ma devono scontrarsi con la disparità di potere
·guerredirete.substack.com·
È possibile decolonizzare l’intelligenza artificiale?
AI-Era Phishing Is Here, and it’s Not Targeting the Mailbox
AI-Era Phishing Is Here, and it’s Not Targeting the Mailbox
New PIXM data: roughly 60% of the phishing pages users actually click in 2026 arrived outside corporate email — led by ad networks, not inboxes. Why the AI era moved phishing past the mail gateway.
·pixmsecurity.com·
AI-Era Phishing Is Here, and it’s Not Targeting the Mailbox
Glendale Community College - 793,925 breached accounts
Glendale Community College - 793,925 breached accounts
In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information".
·haveibeenpwned.com·
Glendale Community College - 793,925 breached accounts
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into the code as a list of numbers.
·bleepingcomputer.com·
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
New U-Boot flaws could enable stealthy firmware attacks
New U-Boot flaws could enable stealthy firmware attacks
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware.
·bleepingcomputer.com·
New U-Boot flaws could enable stealthy firmware attacks