Over Security

Over Security

34356 bookmarks
Custom sorting
Axios npm compromise: XOR dropper to cross-platform RAT
Axios npm compromise: XOR dropper to cross-platform RAT
Axios 1.14.1 supply chain attack torn apart. XOR dropper deobfuscated, macOS Mach-O decompiled, Windows PowerShell RAT reversed, C2 protocol mapped.
·derp.ca·
Axios npm compromise: XOR dropper to cross-platform RAT
SERPENTINE#CLOUD returns: ClickFix lure drops five RATs
SERPENTINE#CLOUD returns: ClickFix lure drops five RATs
Same operator, new delivery chain. ClickFix through Cloudflare tunnels drops five RAT families simultaneously - including Brute Ratel C4 wrapping PureHVNC.
·derp.ca·
SERPENTINE#CLOUD returns: ClickFix lure drops five RATs
TryNodeUpdate turns GitHub and BSC into a TCP control lane
TryNodeUpdate turns GitHub and BSC into a TCP control lane
A PowerShell sample installs a GitHub-hosted Node controller, uses a BNB Smart Chain contract to resolve its backend, then hands elevated Windows hosts to a native rpc.exe helper.
·derp.ca·
TryNodeUpdate turns GitHub and BSC into a TCP control lane
Urelas is old, weird, and still watching Korean card games
Urelas is old, weird, and still watching Korean card games
A fresh Urelas cluster shows thousands of March-April 2026 samples, Korean ISP command-and-control hosts, a bit-flipped MSMP config, and JPEG capture records built for Korean card-game clients.
·derp.ca·
Urelas is old, weird, and still watching Korean card games
Kyber ransomware is not just post-quantum name-dropping
Kyber ransomware is not just post-quantum name-dropping
A Rust Kyber ransomware sample uses AES-256-CTR style file encryption, Kyber1024-sized material, active X25519 arithmetic, and a fixed 0x744 trailer.
·derp.ca·
Kyber ransomware is not just post-quantum name-dropping
M3rx ransomware: inside a new leak-site actor and Go encryptor
M3rx ransomware: inside a new leak-site actor and Go encryptor
M3rx surfaced with a small leak-site burst and a Go ransomware sample using gzip+gob config data, X25519, AES-CTR file encryption, AES-GCM key wrapping, and a 0x400-byte footer.
·derp.ca·
M3rx ransomware: inside a new leak-site actor and Go encryptor
Eimeria: five layers from RAR5 to RunPE
Eimeria: five layers from RAR5 to RunPE
Five-layer delivery chain from a RAR5 archive through a signed carrier DLL side-load, AES-CBC hidden in a fake zlib DLL, IExpress extraction, AutoIt process hollowing, and a .NET C2 beacon on WebSocket.
·derp.ca·
Eimeria: five layers from RAR5 to RunPE
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
Deep-dive analysis of a trojanized Roblox executor that functions as a highly convincing lure with live DeepSeek script generation, while silently staging a Python 3.12 variant of Glove Stealer that bypasses Google Chrome's App-Bound Encryption.
·derp.ca·
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
1,509 WordPress sites feed an active SocGholish chain
1,509 WordPress sites feed an active SocGholish chain
One integrated WordPress-to-GhoLoader operation mapped to Proofpoint's TA2726 and TA569/SocGholish labels, followed by ClickFix on shared hosts.
·derp.ca·
1,509 WordPress sites feed an active SocGholish chain
About
About
·udontknow.us·
About
Direttiva CER: la resilienza diventa una funzione strategica dell’impresa
Direttiva CER: la resilienza diventa una funzione strategica dell’impresa
La direttiva CER introduce un nuovo modello europeo di resilienza che coinvolge board, security, risk management e compliance. Per i soggetti critici non si tratta solo di nuovi adempimenti, ma di ripensare la governance aziendale per gestire rischi sempre più interconnessi
·cybersecurity360.it·
Direttiva CER: la resilienza diventa una funzione strategica dell’impresa
Get your app to Mars!
Get your app to Mars!
This is a blog post about firmware updates, and I was inspired to write it by the news that NASA’s Curiosity rover on Mars has got an OTA update. The firmware image was about 21MB and took 11 days to send it over-the-air (or in this case, over-the-vacuum: Mars is currently 242 million kilometres from Earth).
·kentindell.github.io·
Get your app to Mars!
Inferring the sender of a CAN frame
Inferring the sender of a CAN frame
The latest update of the open source can2 protocol decoder is able to automatically infer the sender of a CAN frame. It uses the method of deterministic distortion of CAN signals that result in frames from a given node on the bus having consistently shortened or lengthened recessive pulses. The differences can be quite small - just 10 or 15 nanoseconds - but they can be picked up by a suitably accurate logic analyzer.
·kentindell.github.io·
Inferring the sender of a CAN frame
APTs Top the List of Most Active Threat Actors in H1 2026
APTs Top the List of Most Active Threat Actors in H1 2026
Cyble breaks down the most active threat actors in H1 2026 as APTs dominate the global threat landscape, followed by ransomware and hacktivist groups.
·cyble.com·
APTs Top the List of Most Active Threat Actors in H1 2026
No Room For Compromise: How Business Email Protection Predicts BEC Before It Starts
No Room For Compromise: How Business Email Protection Predicts BEC Before It Starts
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
·group-ib.com·
No Room For Compromise: How Business Email Protection Predicts BEC Before It Starts
TrickBot ora usa il DNS tunneling per nascondersi: come mitigare il rischio
TrickBot ora usa il DNS tunneling per nascondersi: come mitigare il rischio
Una variante dello storico malware TrickBot adotta nuove tecniche di evasione e il DNS tunneling come metodo di comunicazione con il server di comando e controllo, per consentire agli attaccanti di nascondere lo scambio di dati all’interno del normale traffico DNS. Ecco tutti i dettagli e i consigli per mitigare il rischio
·cybersecurity360.it·
TrickBot ora usa il DNS tunneling per nascondersi: come mitigare il rischio