Over Security

Over Security

Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
·bleepingcomputer.com·
Hackers push malicious Virtualizor update in BGP hijacking attack
Novocure data breach affects more than 1,400 cancer patients
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.
·bleepingcomputer.com·
Novocure data breach affects more than 1,400 cancer patients
Why Even the Best Edge Security Still Misses High-Risk Sessions
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions.
·bleepingcomputer.com·
Why Even the Best Edge Security Still Misses High-Risk Sessions
Il tuo nuovo sviluppatore lavora per Pyongyang: i rischi dell’onboarding remoto
Il tuo nuovo sviluppatore lavora per Pyongyang: i rischi dell’onboarding remoto
Un attaccante non deve violare la rete se può farsi assumere come sviluppatore, ricevere un laptop aziendale e ottenere credenziali valide. Le infiltrazioni di lavoratori IT nordcoreani mostrano il punto cieco dell’onboarding remoto: la cybersecurity autentica dispositivi e accessi, ma troppo spesso presume l’identità della persona
·cybersecurity360.it·
Il tuo nuovo sviluppatore lavora per Pyongyang: i rischi dell’onboarding remoto
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.
·bleepingcomputer.com·
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
I migliori wallet per criptovalute nel 2026: guida tecnica completa
I migliori wallet per criptovalute nel 2026: guida tecnica completa
Guida tecnica ai migliori wallet crypto del 2026: confronto tra Rabby, Rainbow, Phantom, Trust Wallet ed Exodus, più hardware wallet e soluzioni multisig, con link ufficiali e best practice di sicurezza.
·hackerstribe.com·
I migliori wallet per criptovalute nel 2026: guida tecnica completa
Gli Stack perfetti per siti web e landing page nel 2026
Gli Stack perfetti per siti web e landing page nel 2026
Guida tecnica agli stack più usati per costruire landing page nel 2026: Astro, Next.js, SvelteKit, Nuxt, Eleventy e htmx, con librerie UI, CMS headless e analytics open source, tutti con link ai repository GitHub ufficiali.
·hackerstribe.com·
Gli Stack perfetti per siti web e landing page nel 2026
Meta paga 17 miliardi e vince: la sicurezza dei minori online e il paradosso dell’age assurance
Meta paga 17 miliardi e vince: la sicurezza dei minori online e il paradosso dell’age assurance
Per verificare l'età degli utenti servono informazioni sufficienti a distinguere adulti e minorenni. Il caso Meta apre così una questione destinata ad andare oltre i social: come applicare l’age assurance senza trasformarla in un'infrastruttura capace di identificare e classificare tutti
·cybersecurity360.it·
Meta paga 17 miliardi e vince: la sicurezza dei minori online e il paradosso dell’age assurance
Colleferro, Bulgaria e Lipsia: cosa c’è davvero dietro gli attacchi con droni, sabotaggi e disinformazione
Colleferro, Bulgaria e Lipsia: cosa c’è davvero dietro gli attacchi con droni, sabotaggi e disinformazione
Una delle piste da verificare è l'ipotesi di un possibile sabotaggio di matrice russa. Ecco il fil rouge che lega una serie di eventi analoghi verificatisi nelle stesse settimane a Colleferro in Italia, in Bulgaria, a Lipsia in Germania e in Francia
·cybersecurity360.it·
Colleferro, Bulgaria e Lipsia: cosa c’è davvero dietro gli attacchi con droni, sabotaggi e disinformazione
Recently patched PaperCut zero-days used in data theft attacks
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
·bleepingcomputer.com·
Recently patched PaperCut zero-days used in data theft attacks
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Nei servizi di ascolto e segnalazione per soggetti vulnerabili, il “pulsante di aiuto” sui siti web degli Enti del terzo settore non è una pagina di contatti. Ecco il perimetro giuridico del problema, le 4 posizioni soggettive coinvolte e il rapporto fra anonimato e possibilità concreta di prestare aiuto
·cybersecurity360.it·
Terzo settore e GDPR: il “pulsante di aiuto” sui siti Web non è una semplice pagina di contatto
Questel - 1,226,209 breached accounts
Questel - 1,226,209 breached accounts
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
·haveibeenpwned.com·
Questel - 1,226,209 breached accounts
Vulnerability & Patch Roundup — August 2026
Vulnerability & Patch Roundup — August 2026
Discover important WordPress vulnerabilities in August 2026 and how to safeguard your site with essential security updates.
·blog.sucuri.net·
Vulnerability & Patch Roundup — August 2026
Cronos blockchain restarts after $74 million Tectonic exploit
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million.
·bleepingcomputer.com·
Cronos blockchain restarts after $74 million Tectonic exploit
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.
·bleepingcomputer.com·
Microsoft warns of TerminalFix attacks deploying reverse tunnels
OpenAI confirms ChatGPT outage as users report errors
OpenAI confirms ChatGPT outage as users report errors
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks.
·bleepingcomputer.com·
OpenAI confirms ChatGPT outage as users report errors
How AI could make it harder for governments to use hacking tools
How AI could make it harder for governments to use hacking tools
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.
·techcrunch.com·
How AI could make it harder for governments to use hacking tools