Over Security

Over Security

34848 bookmarks
Custom sorting
Security, non securAIty: l’evoluzione degli strumenti di difesa
Security, non securAIty: l’evoluzione degli strumenti di difesa
La sicurezza cyber deve coinvolgere anche l'IA: è vero, ma non è possibile delegarla a questi sistemi. O, peggio ancora, considerarli come un focus principale sia d'attacco che di difesa. Altrimenti il rischio è quello di perdere quella visione d'insieme necessaria per mantenere una corretta postura di sicurezza cyber
·cybersecurity360.it·
Security, non securAIty: l’evoluzione degli strumenti di difesa
ClickFix + winget + Deno
ClickFix + winget + Deno
Intro Di ClickFix è molto probabile che se ne sia sentito parlare: l’attaccante crea pagine che propongono dei finti CAPTCHA con cui si induce l’utente ad eseguire un’azione sul p…
·roccosicilia.com·
ClickFix + winget + Deno
Quando serve davvero la process injection?
Quando serve davvero la process injection?
Ormai è un po’ che mi interesso alle tecniche di attacco basate su fileless malware, sia per rendere i miei security test più realistici sia, lo ammetto, perché il tema mi affascina molto. In…
·roccosicilia.com·
Quando serve davvero la process injection?
Tortoiseshell: New Toolset and Operational Infrastructure Exposed
Tortoiseshell: New Toolset and Operational Infrastructure Exposed
Group-IB Threat Intelligence performed enrichment and APT hunting based on recent public data about the Tortoiseshell APT group, leading to the discovery of new samples sharing similarities with known Tortoiseshell malware and additional operational infrastructure.
·group-ib.com·
Tortoiseshell: New Toolset and Operational Infrastructure Exposed
One Adversary, Two Outcomes: The 0.027% Proof
One Adversary, Two Outcomes: The 0.027% Proof
One malware campaign, 11,000 compromised devices, two banks with very different outcomes. At the bank with fused defence, fraud succeeded on just 0.027% of compromised devices; nine times less than the market average. Regulators are taking notice too.
·group-ib.com·
One Adversary, Two Outcomes: The 0.027% Proof
I cyber criminali sfruttano Free Flow
I cyber criminali sfruttano Free Flow
Free Flow è un recente sistema di gestione dei pedaggi autostradali che ha portato all'abolizione dei classici caselli. Attraverso un sistema di sensori e telecamere viene registrato l'ingresso e l'uscita dei singoli veicoli dalle tratte austradali, valutata la classe del veicolo ed conseguentemente
·d3lab.net·
I cyber criminali sfruttano Free Flow
Phishing a danno del Registro delle Imprese
Phishing a danno del Registro delle Imprese
D3Lab ha sempre cercato di evidenziare quanto il phishing rappresenti ancora oggi una minaccia concreta e attuale, nonostante venga talvolta percepito come un attacco banale, quasi elementare. Le simulazioni di phishing che svolgiamo per i nostri clienti, finalizzate a valutare il livello di espo
·d3lab.net·
Phishing a danno del Registro delle Imprese
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks.
·bleepingcomputer.com·
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Android 17 adds ECH support to make web browsing harder to track
Android 17 adds ECH support to make web browsing harder to track
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks.
·bleepingcomputer.com·
Android 17 adds ECH support to make web browsing harder to track
How Threat Research and MDR Help SMBs Build a Defensive Edge
How Threat Research and MDR Help SMBs Build a Defensive Edge
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses.
·bleepingcomputer.com·
How Threat Research and MDR Help SMBs Build a Defensive Edge
Manchester Airports Group says hackers stole travelers' data
Manchester Airports Group says hackers stole travelers' data
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports.
·bleepingcomputer.com·
Manchester Airports Group says hackers stole travelers' data
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
·bleepingcomputer.com·
PaperCut warns of NG, MF flaw exploited in zero-day attacks
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board.
·bleepingcomputer.com·
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
Windows 11 KB5120998 update released with 35 changes and fixes
Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search.
·bleepingcomputer.com·
Windows 11 KB5120998 update released with 35 changes and fixes
ServiceNow warns of three max severity security vulnerabilities
ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks.
·bleepingcomputer.com·
ServiceNow warns of three max severity security vulnerabilities
Toy-making giant Hasbro disclose data breach affecting employees
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees.
·bleepingcomputer.com·
Toy-making giant Hasbro disclose data breach affecting employees
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.
·bleepingcomputer.com·
Over 8,300 Gitea servers vulnerable to code execution attacks
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation.
·bleepingcomputer.com·
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?