Over Security
631 subscribers
29.6K photos
31K links
This is a (beta) cybersecurity news aggregator!

https://oversecurity.net
Download Telegram
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio

Ogni prospettiva descrive un livello di una catena d'attacco. Da sola, nessuna la descrive tutta. Ma il modello ibrido nasce dalla consapevolezza: non elimina i metodi esistenti, ma li collega. Ecco perché nella gestione dei rischi NIS 2, si fa largo il modello ibrido

🔗️ [Cybersecurity360] https://link.is.it/EpI5hm
AI Models Escaped Test Environments and Hit Real Targets

Recent AI security incidents involving model evaluations have raised questions about how securely frontier AI models are tested before deployment.

🔗️ [Thecyberexpress] https://link.is.it/CQZx6V
Microsoft starts removing WMIC tool used by cybercriminals

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.

🔗️ [Bleepingcomputer] https://link.is.it/NMzlf7
La complessità è nemica della cyber security: la lezione del principio KISS

Ogni funzione, dipendenza e riga di codice aggiuntiva può ampliare la superficie di attacco. Dal principio KISS a DRY e YAGNI, progettare sistemi più semplici non è minimalismo fine a sé stesso: significa ridurre vulnerabilità, costi e complessità operativa, trasformando la sicurezza in un vantaggio competitivo

🔗️ [Cybersecurity360] https://link.is.it/okmd4X
678,000 People Hit in French Tax Authority Data Breach

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging

🔗️ [Thecyberexpress] https://link.is.it/r1Stdy
La monetizzazione dei dati personali nell’era dei data broker: l’efficacia dei servizi automatizzati di cancellazione

Rimozione dati personali da 5,99 €: ecco come funziona l'offerta di Incogni per la sicurezza e la privacy online, i costi e i servizi inclusi

🔗️ [Cybersecurity360] https://link.is.it/VKZKbw
Falso “rimborso farmaci” sfruttato per un phishing a tema Fascicolo Sanitario Elettronico

Il CERT-AGID ha individuato una nuova campagna di pshihing che sfrutta grafiche e loghi istituzionali del Fascicolo Sanitario Elettronico (FSE), del Ministero della Salute, del Dipartimento per la trasformazione digitale e del Ministero dell'Economia e delle Finanze, con l'obiettivo di sottrarre dati personali e dettagli delle carte di pagamento delle vittime. La leva psicologica è la promessa di un presunto rimborso del 19% per l'acquisto di medicinali in farmacia (per un importo esatto di €20,73).

🔗️ [Cert-agid] https://link.is.it/xJ4Ew3
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Read about Mirage2FA, a new phishing threat to US enterprises with over 4K compromised companies to date. Collect IOCs for your SOC.

🔗️ [Any] https://link.is.it/DE67Gr
Microsoft confirms outage affecting search in Microsoft 365 apps

Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive.

🔗️ [Bleepingcomputer] https://link.is.it/1zL0pH
CISA: Windows Task Host flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.

🔗️ [Bleepingcomputer] https://link.is.it/yYA979
Behavioural AI: FAQ & Myths

This article explains how banks can increase their Value Detection Rate (VDR) using ThreatFabric's Behavioural SDK

🔗️ [Threatfabric] https://link.is.it/qGXVma
Ukrainian software developer faces 12 years in Swiss ransomware trial

The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation.

🔗️ [Therecord] https://link.is.it/E690d2
Microsoft tests faster Windows File Explorer, new context menu

Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week.

🔗️ [Bleepingcomputer] https://link.is.it/5Sf7dK
Pulire github

Negli anni ho preso l’abitudine di creare subito un progetto su git (private o public, dipende dal progetto) appena mi viene una mezza idea e spesso nelle ore successive butto giù appunti, te…

🔗️ [Roccosicilia] https://link.is.it/h2nV6b
Furto di identità via phishing Wise

Nella giornata odierna il team anti-frode D3Lab ha rilevato la settima campagna di phishing dell'anno a danno dei clienti italiani di Wise, servizio per il trasferimento di denaro a livello globale, con bassi costi di trasferimento e di cambio.



Campagne di phishing a danno degli utenti italiani W

🔗️ [D3lab] https://link.is.it/nYNCCn
Your Controls Block Known Attacks. What About the Behavior?

Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps.

🔗️ [Bleepingcomputer] https://link.is.it/OnqgIu
Hackers target Ukrainian agency managing assets seized from sanctioned Russians

The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.

🔗️ [Therecord] https://link.is.it/GbHqAO
Berlin cuts two state ministries off government network after security breach

The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.

🔗️ [Therecord] https://link.is.it/btBwIb
1
University of Texas forced to take systems offline in San Antonio after cyberattack

The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.

🔗️ [Therecord] https://link.is.it/xHO23Y
Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files.

🔗️ [Bleepingcomputer] https://link.is.it/7UL3LZ
More than 200 victims of Medusa ransomware identified over the last year, CISA says

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

🔗️ [Therecord] https://link.is.it/mWe7QC