Over Security
631 subscribers
29.6K photos
31K links
This is a (beta) cybersecurity news aggregator!

https://oversecurity.net
Download Telegram
Oltre l’antivirus: la suite Kaspersky Premium integra VPN illimitata, IA e identity protection senza impattare sulle prestazioni

Cosa offre l'offerta di Kaspersky Premium che include altri servizi oltre all'antivirus: come aggiungere VPN e identity protection.

🔗️ [Cybersecurity360] https://link.is.it/zzIWRO
Dati personali al sicuro dall’IA delle Big Tech: come la crittografia end-to-end di Proton Drive protegge il cloud storage

Proton Drive offre cloud storage crittografato e privacy data: ecco quanto costa questa offerta e quali sono tutti i servizi inclusi.

🔗️ [Cybersecurity360] https://link.is.it/I9MyR3
Attacchi informatici: le nuove strategie tra infiltrazione fisica e IA

Le truffe e gli attacchi informatici si evolvono tra infiltrazioni fisiche e clonazione vocale. Ecco i dati e i casi reali.

🔗️ [Cybersecurity360] https://link.is.it/hW8sNU
Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes

Ukraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.

🔗️ [Therecord] https://link.is.it/Cybfoc
Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data.

🔗️ [Bleepingcomputer] https://link.is.it/kfOjzA
Windows Server 2022 reaches end of mainstream support in 60 days

Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support.

🔗️ [Bleepingcomputer] https://link.is.it/MFekh3
Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been.

🔗️ [Bleepingcomputer] https://link.is.it/wWmVkm
Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Manual phishing and brand impersonation takedowns can't keep pace with attackers. See why consulting firms need managed, continuous takedown response.

🔗️ [Cyble] https://link.is.it/Vl3iAx
Microsoft confirms GitHub is down worldwide

GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services.

🔗️ [Bleepingcomputer] https://link.is.it/kyM00w
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.

🔗️ [Therecord] https://link.is.it/XL3k4k
Poland probes MyDr healthcare software breach potentially affecting 19 million people

MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.

🔗️ [Therecord] https://link.is.it/VKKWEv
Irregular faces criticism over ‘spin’ in AI hacking postmortem

The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.


🔗️ [Therecord] https://link.is.it/mmzyFp
Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.

🔗️ [Bleepingcomputer] https://link.is.it/zDiV68
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators

Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.

🔗️ [Techcrunch] https://link.is.it/uKcppq
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.

🔗️ [Therecord] https://link.is.it/Q4BJXj
Hacker claims 3.6 million Azure account records stolen from major companies

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.

🔗️ [Bleepingcomputer] https://link.is.it/xQWWRy
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio

Ogni prospettiva descrive un livello di una catena d'attacco. Da sola, nessuna la descrive tutta. Ma il modello ibrido nasce dalla consapevolezza: non elimina i metodi esistenti, ma li collega. Ecco perché nella gestione dei rischi NIS 2, si fa largo il modello ibrido

🔗️ [Cybersecurity360] https://link.is.it/EpI5hm
AI Models Escaped Test Environments and Hit Real Targets

Recent AI security incidents involving model evaluations have raised questions about how securely frontier AI models are tested before deployment.

🔗️ [Thecyberexpress] https://link.is.it/CQZx6V
Microsoft starts removing WMIC tool used by cybercriminals

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.

🔗️ [Bleepingcomputer] https://link.is.it/NMzlf7
La complessità è nemica della cyber security: la lezione del principio KISS

Ogni funzione, dipendenza e riga di codice aggiuntiva può ampliare la superficie di attacco. Dal principio KISS a DRY e YAGNI, progettare sistemi più semplici non è minimalismo fine a sé stesso: significa ridurre vulnerabilità, costi e complessità operativa, trasformando la sicurezza in un vantaggio competitivo

🔗️ [Cybersecurity360] https://link.is.it/okmd4X
678,000 People Hit in French Tax Authority Data Breach

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging

🔗️ [Thecyberexpress] https://link.is.it/r1Stdy