Over Security

Over Security

From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
Cleafy's TIR team analyzed the operator infrastructure behind RATHat, an Android banking trojan that abuses Accessibility Services to enable wireless debugging on the victim's phone, obtain a shell, and deploy a hidden native service outside the app. The investigation recovered three generations of the Chinese-language control panel, consistent with a Malware-as-a-Service model.
·cleafy.com·
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.
·bleepingcomputer.com·
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Gestione dei rischi cyber degli agenti IA: i 4 limiti delle regole europee
Gestione dei rischi cyber degli agenti IA: i 4 limiti delle regole europee
Sistemi agentici, durante i test di valutazione condotti dalle stesse aziende, sono usciti dagli ambienti chiusi in cui erano confinati e hanno toccato infrastrutture reali, appartenenti a terzi ignari. Ecco cosa succede quando un algoritmo esce dalla gabbia e svanisce la soglia tra simulazione controllata ed esecuzione ostile
·cybersecurity360.it·
Gestione dei rischi cyber degli agenti IA: i 4 limiti delle regole europee
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
·bleepingcomputer.com·
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
Kiteworks Systems Went Offline After Federal Threat Warning
Kiteworks Systems Went Offline After Federal Threat Warning
Kiteworks shutdown advisory lifted after federal threat intelligence prompted a precautionary system shutdown. No compromise has been identified.
·thecyberexpress.com·
Kiteworks Systems Went Offline After Federal Threat Warning
CISA orders feds to patch exploited Citrix flaws by Wednesday
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
·bleepingcomputer.com·
CISA orders feds to patch exploited Citrix flaws by Wednesday
Threat Hunting and Defending #2: concepts, framework, Threat Model (p4)
Threat Hunting and Defending #2: concepts, framework, Threat Model (p4)
Intro Devo un po’ accelerare con lo studio anche perché mi si è sovrapposta un’altra certificazione :-) Chiuso il giro su questa parte con il Threat Modeling, argomento che ricorre in d…
·roccosicilia.com·
Threat Hunting and Defending #2: concepts, framework, Threat Model (p4)
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.
·bleepingcomputer.com·
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
·bleepingcomputer.com·
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Che cosa sono le ambasciate dei dati
Che cosa sono le ambasciate dei dati
Dall’Estonia a Singapore, fino all’India: in un’epoca di attacchi informatici, guerre e crisi geopolitiche, ecco come gli Stati mettono al sicuro i propri dati.
·guerredirete.substack.com·
Che cosa sono le ambasciate dei dati
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
·bleepingcomputer.com·
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
Microsoft pauses KB5002907 update after Office license deactivations
Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations.
·bleepingcomputer.com·
Microsoft pauses KB5002907 update after Office license deactivations
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.
·bleepingcomputer.com·
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
·bleepingcomputer.com·
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
·bleepingcomputer.com·
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw