Over Security

Over Security

31461 bookmarks
Custom sorting
Auto aziendali e monitoraggio dei lavoratori: il Garante privacy dice stop
Auto aziendali e monitoraggio dei lavoratori: il Garante privacy dice stop
Inflitta una sanzione di 120mila euro a una società del settore agricolo facente parte di un gruppo multinazionale con la capogruppo svizzera, per trattamento illecito di dati personali consistente nell’aver installato sui veicoli aziendali un dispositivo di monitoraggio di cinque dipendenti dotati di tale benefit. Vediamo meglio
·cybersecurity360.it·
Auto aziendali e monitoraggio dei lavoratori: il Garante privacy dice stop
Please Don’t Feed the Scattered Lapsus Shiny Hunters
Please Don’t Feed the Scattered Lapsus Shiny Hunters
A prolific data ransom gang that calls itself Scattered Lapsus Shiny Hunters (SLSH) has a distinctive playbook when it seeks to extort payment from victim firms: Harassing, threatening and even swatting executives and their families, all while notifying journalists and…
·krebsonsecurity.com·
Please Don’t Feed the Scattered Lapsus Shiny Hunters
Abusato il sistema di update eScan per inviare malware multistage
Abusato il sistema di update eScan per inviare malware multistage
Gli attacchi alla supply chain continuano a mietere vittime illustri e, stavolta, si tratta addirittura di un’azienda specializzata in sicurezza informatica. A esser stata abusata, infatti, è stata l’infrastruttura di eScan Antivirus che ha subito una compromissione diretta dei server di distribuzione, trasformando uno strumento di difesa in un efficace veicolo di infezione globale. Secondo …
·securityinfo.it·
Abusato il sistema di update eScan per inviare malware multistage
CTM360 Report Warns of Global Surge in Fake High-Yield Investment Scams
CTM360 Report Warns of Global Surge in Fake High-Yield Investment Scams
Fake high-yield investment platforms are surging worldwide, promising "guaranteed" returns that mask classic Ponzi schemes.CTM360 explains how HYIP scams scale through social media, recycled templates, and referral abuse.
·bleepingcomputer.com·
CTM360 Report Warns of Global Surge in Fake High-Yield Investment Scams
Notepad++ update feature hijacked by Chinese state hackers for months
Notepad++ update feature hijacked by Chinese state hackers for months
Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year, the developer states in an official announcement today.
·bleepingcomputer.com·
Notepad++ update feature hijacked by Chinese state hackers for months
Privacy Benchmark Cisco 2026: cosa dice e perché il confronto con le PMI italiane è aperto
Privacy Benchmark Cisco 2026: cosa dice e perché il confronto con le PMI italiane è aperto
Investire in privacy genera ritorni economici concreti e rafforza la fiducia nell’uso dei dati e dell’intelligenza artificiale: sono le evidenze del Cisco Data and Privacy Benchmark Study 2026. Ecco come leggere questi dati nel contesto italiano dominato da PMI che spesso vivono la compliance solo come un costo crescente
·cybersecurity360.it·
Privacy Benchmark Cisco 2026: cosa dice e perché il confronto con le PMI italiane è aperto
Panera Bread breach impacts 5.1 million accounts, not 14 million customers
Panera Bread breach impacts 5.1 million accounts, not 14 million customers
The data breach notification service Have I Been Pwned says that a data breach at the U.S. food chain Panera Bread affected 5.1 million accounts, not 14 million customers as previously reported.
·bleepingcomputer.com·
Panera Bread breach impacts 5.1 million accounts, not 14 million customers
Microsoft fixes bug causing password sign-in option to disappear
Microsoft fixes bug causing password sign-in option to disappear
Microsoft has fixed a known issue that was causing the password sign-in option to disappear from the lock screen options after installing Windows 11 updates released since August 2025.
·bleepingcomputer.com·
Microsoft fixes bug causing password sign-in option to disappear
Rischio cyber: il ruolo degli amministratori nella NIS 2, fra obblighi e responsabilità
Rischio cyber: il ruolo degli amministratori nella NIS 2, fra obblighi e responsabilità
La circolare Assonime 23/2025 analizza il nuovo quadro di governance della cyber sicurezza, sottolineando come gli obblighi introdotti dalla normativa NIS 2 abbiano un impatto diretto sull’organizzazione interna delle aziende e sul ruolo degli amministratori
·cybersecurity360.it·
Rischio cyber: il ruolo degli amministratori nella NIS 2, fra obblighi e responsabilità
Data Privacy Framework, i controlli obbligatori per i trasferimenti dati: ecco le nuove FAQ
Data Privacy Framework, i controlli obbligatori per i trasferimenti dati: ecco le nuove FAQ
L’EDPB ha pubblicato la versione 2.0 delle FAQ sul Data Privacy Framework, chiarendo responsabilità, obblighi e verifiche necessarie per i trasferimenti di dati personali verso aziende USA. Il DPF resta uno strumento utile, ma non sostituisce la compliance GDPR e i controlli sulla supply chain digitale
·cybersecurity360.it·
Data Privacy Framework, i controlli obbligatori per i trasferimenti dati: ecco le nuove FAQ
Designing a GitLab CI/CD pipeline for IaC
Designing a GitLab CI/CD pipeline for IaC
Our CI/CD process is defined in GitLab through the .gitlab-ci.yml file, which resides in the root of our repository. As mentioned earlier, a pipeline is triggered on every commit to validate the code.
·adainese.it·
Designing a GitLab CI/CD pipeline for IaC
NationStates confirms data breach, shuts down game site
NationStates confirms data breach, shuts down game site
NationStates, a multiplayer browser-based game, has confirmed a data breach after taking its website offline earlier this week to investigate a security incident.
·bleepingcomputer.com·
NationStates confirms data breach, shuts down game site
Digital Forensics nell’Industrial Internet of Things (IIoT): opportunità, limiti, prospettive
Digital Forensics nell’Industrial Internet of Things (IIoT): opportunità, limiti, prospettive
L'IIoT ha ridisegnato il panorama industriale, ma ha anche ampliato la superficie di attacco, introducendo rischi fisici senza precedenti. Ecco le sfide e le opportunità della digital forensics applicata ai dispositivi dell'Industrial Internet of Things, uno dei pilastri della quarta rivoluzione industriale
·cybersecurity360.it·
Digital Forensics nell’Industrial Internet of Things (IIoT): opportunità, limiti, prospettive
IDS, IPS ed analisi del traffico
IDS, IPS ed analisi del traffico
Qualche giorno fa ho parlato di traffic sniffing, argomento che mi avrebbe portato a parlare di Intrusion Detection/Prevention System e ad una ulteriore evoluzione del lab e dei test che potrò/potr…
·roccosicilia.com·
IDS, IPS ed analisi del traffico
Vulnerability & Patch Roundup — January 2026
Vulnerability & Patch Roundup — January 2026
Learn about the latest WordPress vulnerabilities and essential updates to protect your website from automated attacks.
·blog.sucuri.net·
Vulnerability & Patch Roundup — January 2026
OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough
OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough
OpenAI has confirmed that it's retiring ChatGPT's most popular model called GPT-4o and several other models, including GPT-5 Instant, GPT-5 Thinking, GPT-4.1, GPT-4.1 mini, and o4-mini.
·bleepingcomputer.com·
OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough
U.S. convicts ex-Google engineer for sending AI tech data to China
U.S. convicts ex-Google engineer for sending AI tech data to China
A U.S. federal jury has convicted Linwei Ding, a former software engineer at Google, for stealing AI supercomputer data from his employer and secretly sharing it with Chinese tech firms.
·bleepingcomputer.com·
U.S. convicts ex-Google engineer for sending AI tech data to China
Cloud storage payment scam floods inboxes with fake renewals
Cloud storage payment scam floods inboxes with fake renewals
Over the past few months, a large-scale cloud storage subscription scam campaign has been targeting users worldwide with repeated emails falsely warning recipients that their photos, files, and accounts are about to be blocked or deleted due to an alleged payment failure.
·bleepingcomputer.com·
Cloud storage payment scam floods inboxes with fake renewals
Mandiant details how ShinyHunters abuse SSO to steal cloud data
Mandiant details how ShinyHunters abuse SSO to steal cloud data
Mandiant says a wave of recent ShinyHunters SaaS data-theft attacks is being fueled by targeted voice phishing (vishing) attacks and company-branded phishing sites that steal single sign-on (SSO) credentials and multi-factor authentication (MFA) codes.
·bleepingcomputer.com·
Mandiant details how ShinyHunters abuse SSO to steal cloud data
Researcher reveals evidence of private Instagram profiles leaking photos
Researcher reveals evidence of private Instagram profiles leaking photos
A researcher has released detailed evidence showing some Instagram private accounts exposed photo links to unauthenticated visitors. The issue was later fixed, but Meta closed the report as not applicable and did not respond to multiple requests for comment.
·bleepingcomputer.com·
Researcher reveals evidence of private Instagram profiles leaking photos
Researcher reveals evidence of Instagram private profiles leaking photos
Researcher reveals evidence of Instagram private profiles leaking photos
A researcher has released detailed evidence showing some Instagram private accounts exposed photo links to unauthenticated visitors. The issue was later fixed, but Meta closed the report as not applicable and did not respond to multiple requests for comment.
·bleepingcomputer.com·
Researcher reveals evidence of Instagram private profiles leaking photos
Panera Bread - 5,112,502 breached accounts
Panera Bread - 5,112,502 breached accounts
In January 2026, Panera Bread suffered a data breach that exposed 14M records. After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses. Panera Bread subsequently confirmed that "the data involved is contact information" and that authorities were notified.
·haveibeenpwned.com·
Panera Bread - 5,112,502 breached accounts