Over Security

Over Security

Dindoor - The Technical Analysis of an Iranian Backdoor
Dindoor - The Technical Analysis of an Iranian Backdoor
Dindoor is a backdoor that abuses the Deno runtime to execute malware within a target environment. Rather than shipping its own interpreter, Dindoor relies on Deno, a legitimate and widely used JavaScript and TypeScript runtime, and will install that runtime on the victim machine on demand if it is not already present. Few of its individual components are novel; what makes Dindoor effective is the combination of a signed third-party runtime performing execution, base64 encoding at every stage, and an environment check that must pass before the backdoor establishes persistence. After initial staging, the loader confirms whether the Deno runtime is present on the victim machine and, if it is not, downloads it from deno.land via curl.exe. What does not change between builds is the behavior beneath the encoding, and that is where detection must focus: deno.exe launching with a lengthy base64 argument on a host with no developer profile curl.exe reaching out to deno.land on a machine with no legitimate reason to install a JavaScript runtime a Run key directing wscript.exe to a VBScript within a subdirectory of AppData\Local a `Win32_VideoController` WMI query originating from a PowerShell process spawned by cmd.exe Binary Defense researchers developed hypothesis-based threat hunting queries around these patterns, targeting the fixed structure of Dindoor's execution chain rather than the encoded contents that change with each build. By adopting a mainstream developer runtime as its execution engine, MuddyWater gains a legitimate signed binary, a network destination few organizations have reason to block, and a script format that most detection content was never written to address.
·binarydefense.com·
Dindoor - The Technical Analysis of an Iranian Backdoor
New Zealand Moves to Ban Social Media for Under-16s
New Zealand Moves to Ban Social Media for Under-16s
New Zealand’s social media ban for under-16s will require platforms to verify users, assess child safety risks and face penalties for non-compliance.
·thecyberexpress.com·
New Zealand Moves to Ban Social Media for Under-16s
Senator asks US government watchdog to review how feds use hacking tools
Senator asks US government watchdog to review how feds use hacking tools
Senator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans.
·techcrunch.com·
Senator asks US government watchdog to review how feds use hacking tools
Alabama launches investigation into OpenAI’s hack of Hugging Face
Alabama launches investigation into OpenAI’s hack of Hugging Face
Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident.
·techcrunch.com·
Alabama launches investigation into OpenAI’s hack of Hugging Face
UK Cybercrime Journal: ACRO Breach Report
UK Cybercrime Journal: ACRO Breach Report
What Happened On 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO...
·blog.bushidotoken.net·
UK Cybercrime Journal: ACRO Breach Report
Golf Canada - 568,972 breached accounts
Golf Canada - 568,972 breached accounts
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
·haveibeenpwned.com·
Golf Canada - 568,972 breached accounts
NIUS - 6,090 breached accounts
NIUS - 6,090 breached accounts
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).
·haveibeenpwned.com·
NIUS - 6,090 breached accounts
Carhartt - 12,933,413 breached accounts
Carhartt - 12,933,413 breached accounts
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.
·haveibeenpwned.com·
Carhartt - 12,933,413 breached accounts
The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact
The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact
We examine how modern hacktivism has evolved into a tool of global hybrid warfare, analyzing crowdsourced attack tactics, media-driven propaganda, and real-world impacts across Ukraine, the Middle East, European Union, and NATO nations.
·flashpoint.io·
The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact