Over Security

Over Security

One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion
One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion
A real-world ClickFix intrusion observed from both sandbox and endpoint telemetry, revealing the complete attack path from a compromised WordPress site to a blocked GULoader execution, including a full process creation call stack from the Windows Run dialog to the kernel. Preamble In April 2026, we responded to an endpoint detection alert triggered by a rundll32.exe execution with anomalous arguments on a corporate workstation. The investigation traced the execution back to a compromised Euro
·blog.sicuranext.com·
One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion
Berkadia - 305,216 breached accounts
Berkadia - 305,216 breached accounts
In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data.
·haveibeenpwned.com·
Berkadia - 305,216 breached accounts
Infinite Campus - 137,123 breached accounts
Infinite Campus - 137,123 breached accounts
In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications, advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".
·haveibeenpwned.com·
Infinite Campus - 137,123 breached accounts
Smart Glasses Can Record You – And Detecting Them Isn’t So Simple
Smart Glasses Can Record You – And Detecting Them Isn’t So Simple
Smart glasses with camera are becoming more common, fitting into everyday life. They look like normal sunglasses — but they can record video, capture audio, and take photos at any moment.
·mobile-hacker.com·
Smart Glasses Can Record You – And Detecting Them Isn’t So Simple
FBI disrupts massive AI-powered phishing service using a million URLs
FBI disrupts massive AI-powered phishing service using a million URLs
In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.
·bleepingcomputer.com·
FBI disrupts massive AI-powered phishing service using a million URLs
Ex-school district employee jailed for hacks on former employer
Ex-school district employee jailed for hacks on former employer
A former  IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages.
·bleepingcomputer.com·
Ex-school district employee jailed for hacks on former employer
Governo Usa ordina ad Anthropic il ritiro di Fable 5 e Mythos 5: ecco l’impatto della dogana cognitiva
Governo Usa ordina ad Anthropic il ritiro di Fable 5 e Mythos 5: ecco l’impatto della dogana cognitiva
In un'operazione di recall, senza precedenti dei modelli di AI, Anthropic è costretta a ritirare Fable 5 e Mythos 5, di cui il primo è stato violato in 24 ore. Il suo jailbreak aveva esposto sue istruzioni segrete, mostrando la fragilità dei sistemi di sicurezza proprietari di fronte ad attacchi agentici distribuiti. In gioco la sicurezza nazionale
·cybersecurity360.it·
Governo Usa ordina ad Anthropic il ritiro di Fable 5 e Mythos 5: ecco l’impatto della dogana cognitiva
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
The US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes the basis, calling the cited jailbreak narrow and the capability widely available elsewhere.
·bleepingcomputer.com·
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
Quando la sicurezza cyber sorprende (ed è un male)
Quando la sicurezza cyber sorprende (ed è un male)
Nel momento in cui ci si sorprende ancora di fronte ad una sicurezza cyber ben gestita, forse il problema non è tanto l'inconsapevolezza dei più ma una vera e propria sfiducia diffusa. Indizio rivelatore di un cammino ancora lungo da fare di cyberawareness.
·cybersecurity360.it·
Quando la sicurezza cyber sorprende (ed è un male)
Maine disables data breach notification portal after fake disclosures
Maine disables data breach notification portal after fake disclosures
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future.
·bleepingcomputer.com·
Maine disables data breach notification portal after fake disclosures
phpBB forum fixes auth bypass bug lurking for a decade
phpBB forum fixes auth bypass bug lurking for a decade
A 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators.
·bleepingcomputer.com·
phpBB forum fixes auth bypass bug lurking for a decade
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
GitHub access sales, leaked repositories, and stolen API keys can all become supply-chain attack footholds. Flare explores how underground forums expose early signals tied to software supply-chain risk.
·bleepingcomputer.com·
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
Microsoft fixes Windows update failures linked to WUSA installer
Microsoft fixes Windows update failures linked to WUSA installer
Microsoft has fixed a known issue that caused Windows updates released since May 2025 to fail when installed via the Windows Update Standalone Installer (WUSA) from a network share.
·bleepingcomputer.com·
Microsoft fixes Windows update failures linked to WUSA installer