Categoria : Security

image_pdfimage_print

Google Threat Intelligence Group (GTIG) ha pubblicato l’analisi di STOCKSTAY, una backdoor modulare in .NET sviluppata dal gruppo russo Turla almeno dal dicembre 2022 e impiegata in operazioni dal 2023 per attività di spionaggio contro organizzazioni governative e militari in Ucraina. Il dettaglio che rende la ricerca rilevante per il pubblico italiano è esplicito nel ..

Leggi tutto

The Texas Parks and Wildlife Department (TPWD) reported that the personal information of more than three million Texas hunting and fishing license customers may have been affected by a recent data breech.  According to a notification on the department’s website, the Texas Cyber Command recently detected a cybersecurity incident involving the TPWD license system vendor that ..

Leggi tutto

Researchers at Wiz have disclosed a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that could allow attackers to steal developers’ cloud credentials by luring them into opening a booby-trapped code repository. Amazon Q Developer is an AI-powered coding assistant that offers developers features such as code suggestions, automated refactoring, and ..

Leggi tutto

Il data breach Trenitalia, comunicato il 26 giugno, espone i dati di contatto e di viaggio di una parte dei passeggeri. La principale compagnia ferroviaria italiana ha inviato ai clienti interessati una email con oggetto “Comunicazione di violazione dei dati personali ai sensi dell’art. 34 del Regolamento UE 679/2016”, attribuendo l’accesso non autorizzato ai database ..

Leggi tutto

The demand for executive and senior security leadership in the corporate sector has never been more competitive or more consequential. Organizations across a wide range of industries are increasingly turning to candidates with backgrounds in government, military, and law enforcement to fill their most critical security leadership roles. These candidates bring real-world experience in threat ..

Leggi tutto

Cybersecurity is entering a phase in which the pace of artificial intelligence advancement is outpacing traditional defense models. Anthropic’s recent Mythos announcement underscored a truth cybersecurity leaders can’t ignore: security models cannot keep pace with the speed of AI acceleration.  The message, echoed across the industry, is stark — AI-enabled vulnerability may soon outpace defenders’ ..

Leggi tutto

After Iranian-linked threat actor Handala claimed to have hacked California Water Service (Cal Water), an organization spokesperson stated the company was investigating the claims. Recently, the Cal Water spokesperson reached out to Security magazine with an update on its investigation.  The spokesperson stated, “As a critical infrastructure company, California Water Service takes cybersecurity and the security ..

Leggi tutto

A recent report by Omega Systems analyzed cybersecurity incidents within healthcare organizations. The report found that 85% of healthcare practices experienced at least one operational disruption caused by a third-party or “vendor-of-a-vendor” failure in the past 12 months. Despite this, 70% of leaders say they are confident in their vendors’ cybersecurity posture. The report also ..

Leggi tutto

The investigation conducted by California Water Service (Cal Water) into the recent cyberattack claimed by the Iranian hacker group Handala found no evidence of activity in the water utility’s operational technology (OT) environment. Handala, which claims to be a hacktivist collective but is widely believed to be a front for Iranian government hacking operations, said ..

Leggi tutto