Over Security

Over Security

34848 bookmarks
Custom sorting
Strategia nazionale per la resilienza dei soggetti critici: la fine del confine tra minacce fisiche e digitali
Strategia nazionale per la resilienza dei soggetti critici: la fine del confine tra minacce fisiche e digitali
Il documento è rilevante perché riconosce formalmente che quel problema è più complesso, interconnesso e urgente di quanto la postura regolatoria italiana abbia storicamente riflesso. Ecco i punti salienti, i vantaggi e criticità della Strategia nazionale per la resilienza dei soggetti critici
·cybersecurity360.it·
Strategia nazionale per la resilienza dei soggetti critici: la fine del confine tra minacce fisiche e digitali
New attack turned Microsoft 365 Copilot into 1-click data theft tool
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
·bleepingcomputer.com·
New attack turned Microsoft 365 Copilot into 1-click data theft tool
Infinite Campus data breach affects 137,000 school staff accounts
Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March.
·bleepingcomputer.com·
Infinite Campus data breach affects 137,000 school staff accounts
L’uso dell’AI Generativa come supporto alla conformità normativa
L’uso dell’AI Generativa come supporto alla conformità normativa
Implementare, gestire e verificare la conformità normativa, con impatti sul sistema informativo e sulla sicurezza, può essere molto oneroso. Un aiuto per lo svolgimento delle attività può derivare dall’uso degli strumenti di AI generativa che, anche nella loro versione gratuita, consentono l’esecuzione di operazioni complesse
·cybersecurity360.it·
L’uso dell’AI Generativa come supporto alla conformità normativa
Webinar: How behavioral AI stops phishing and account takeovers
Webinar: How behavioral AI stops phishing and account takeovers
Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and accelerate response times.
·bleepingcomputer.com·
Webinar: How behavioral AI stops phishing and account takeovers
One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion
One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion
A real-world ClickFix intrusion observed from both sandbox and endpoint telemetry, revealing the complete attack path from a compromised WordPress site to a blocked GULoader execution, including a full process creation call stack from the Windows Run dialog to the kernel. Preamble In April 2026, we responded to an endpoint detection alert triggered by a rundll32.exe execution with anomalous arguments on a corporate workstation. The investigation traced the execution back to a compromised Euro
·blog.sicuranext.com·
One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion
Berkadia - 305,216 breached accounts
Berkadia - 305,216 breached accounts
In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data.
·haveibeenpwned.com·
Berkadia - 305,216 breached accounts
Infinite Campus - 137,123 breached accounts
Infinite Campus - 137,123 breached accounts
In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications, advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".
·haveibeenpwned.com·
Infinite Campus - 137,123 breached accounts
Smart Glasses Can Record You – And Detecting Them Isn’t So Simple
Smart Glasses Can Record You – And Detecting Them Isn’t So Simple
Smart glasses with camera are becoming more common, fitting into everyday life. They look like normal sunglasses — but they can record video, capture audio, and take photos at any moment.
·mobile-hacker.com·
Smart Glasses Can Record You – And Detecting Them Isn’t So Simple
FBI disrupts massive AI-powered phishing service using a million URLs
FBI disrupts massive AI-powered phishing service using a million URLs
In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.
·bleepingcomputer.com·
FBI disrupts massive AI-powered phishing service using a million URLs
Ex-school district employee jailed for hacks on former employer
Ex-school district employee jailed for hacks on former employer
A former  IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages.
·bleepingcomputer.com·
Ex-school district employee jailed for hacks on former employer
Governo Usa ordina ad Anthropic il ritiro di Fable 5 e Mythos 5: ecco l’impatto della dogana cognitiva
Governo Usa ordina ad Anthropic il ritiro di Fable 5 e Mythos 5: ecco l’impatto della dogana cognitiva
In un'operazione di recall, senza precedenti dei modelli di AI, Anthropic è costretta a ritirare Fable 5 e Mythos 5, di cui il primo è stato violato in 24 ore. Il suo jailbreak aveva esposto sue istruzioni segrete, mostrando la fragilità dei sistemi di sicurezza proprietari di fronte ad attacchi agentici distribuiti. In gioco la sicurezza nazionale
·cybersecurity360.it·
Governo Usa ordina ad Anthropic il ritiro di Fable 5 e Mythos 5: ecco l’impatto della dogana cognitiva
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
The US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes the basis, calling the cited jailbreak narrow and the capability widely available elsewhere.
·bleepingcomputer.com·
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
Quando la sicurezza cyber sorprende (ed è un male)
Quando la sicurezza cyber sorprende (ed è un male)
Nel momento in cui ci si sorprende ancora di fronte ad una sicurezza cyber ben gestita, forse il problema non è tanto l'inconsapevolezza dei più ma una vera e propria sfiducia diffusa. Indizio rivelatore di un cammino ancora lungo da fare di cyberawareness.
·cybersecurity360.it·
Quando la sicurezza cyber sorprende (ed è un male)
Maine disables data breach notification portal after fake disclosures
Maine disables data breach notification portal after fake disclosures
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future.
·bleepingcomputer.com·
Maine disables data breach notification portal after fake disclosures
phpBB forum fixes auth bypass bug lurking for a decade
phpBB forum fixes auth bypass bug lurking for a decade
A 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators.
·bleepingcomputer.com·
phpBB forum fixes auth bypass bug lurking for a decade