Over Security

Over Security

35939 bookmarks
Custom sorting
[Phishing Kit] 'Israel' Outlook Web App credentials stealer
[Phishing Kit] 'Israel' Outlook Web App credentials stealer
An analysis of a phishing kit found with StalkPhish tool. This phishing kit impersonating a professional Outlook login pattern and exfiltrate credentials on an online portal (FormBuddy)... with no success.
·stalkphish.com·
[Phishing Kit] 'Israel' Outlook Web App credentials stealer
How phishing kits uses Telegram
How phishing kits uses Telegram
More and more actors uses Telegram chat groups to exfiltrate harvested data, we'll show you how we can collect informations about those actors. Let’s have a dive into one of this kits.
·stalkphish.com·
How phishing kits uses Telegram
[Phishing kit] Scammer vs Scammer - backdoored phishing kit
[Phishing kit] Scammer vs Scammer - backdoored phishing kit
Scammer world should be a hard thug life. A merciless world... with no pity... Some scammers try to steal other ones! What a shameless! During our researches we found one of those 'backdoored' phishing kit, let's have a fast dive into it.
·stalkphish.com·
[Phishing kit] Scammer vs Scammer - backdoored phishing kit
How-to use StalkPhish.io
How-to use StalkPhish.io
StalkPhish.io is a SaaS application which provides enriched data about potential phishing URL or brand impersonation use, with a REST API.
·stalkphish.com·
How-to use StalkPhish.io
Using PhishingKit-Yara-Rules with ClamAV
Using PhishingKit-Yara-Rules with ClamAV
As a reminder, the PhishingKit-Yara-Rules project is a free and open source project which provides several dozen phishing kit detection rules contained in zip…
·stalkphish.com·
Using PhishingKit-Yara-Rules with ClamAV
[Phishing kit] 'Moha' kit, targeting DEWA suppliers
[Phishing kit] 'Moha' kit, targeting DEWA suppliers
At StalkPhish we like dissecting Phishing kits, first because we create Yara rules for detection, secondly because we must continually keep up to date with new…
·stalkphish.com·
[Phishing kit] 'Moha' kit, targeting DEWA suppliers
DIVD says Zammad zero-days enabled AI-driven network breach
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
·bleepingcomputer.com·
DIVD says Zammad zero-days enabled AI-driven network breach
Over 543,000 valid credentials exposed in public GitHub repositories
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data.
·bleepingcomputer.com·
Over 543,000 valid credentials exposed in public GitHub repositories
Agenti AI, il rischio è nel perimetro: cosa insegnano gli ultimi incidenti
Agenti AI, il rischio è nel perimetro: cosa insegnano gli ultimi incidenti
Dalla fuga dalla sandbox al blocco di GPT-6.1 Astra, fra agosto e settembre si sono moltiplicati gli incidenti cyber. Ecco perché i casi degli Agenti AI di OpenAI e Anthropic costringono a spostare l’attenzione dal comportamento anomalo dei singoli modelli all'affidabilità del perimetro di training del modello
·cybersecurity360.it·
Agenti AI, il rischio è nel perimetro: cosa insegnano gli ultimi incidenti
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
·bleepingcomputer.com·
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
Oxygen Forensics, il caso USA riapre il rischio supply chain nel software critico
Oxygen Forensics, il caso USA riapre il rischio supply chain nel software critico
Il sequestro dell’infrastruttura di Oxygen Forensics non nasce, allo stato, da una compromissione tecnica del software, ma dalle contestazioni sulla proprietà societaria e sulla provenienza dello sviluppo. Il caso mostra perché supply chain, vendor risk e continuità operativa sono ormai parte della sicurezza delle tecnologie critiche
·cybersecurity360.it·
Oxygen Forensics, il caso USA riapre il rischio supply chain nel software critico
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
·bleepingcomputer.com·
Cisco warns of new SD-WAN zero-day exploited in attacks
RemusStealer: EtherHiding In Hidden Windows
RemusStealer: EtherHiding In Hidden Windows
LummaStealer is a notorious information stealer active since at least 2022 and has been covered in a previous Binary Defense blog post regarding ClickFix initial access methods, which can be f ound here. In contrast, one key difference between LummaStealer and RemusStealer in recent campaigns is that, instead of utilizing Steam or Telegram as a dead drop resolver, RemusStealer is observed to employ Ethereum smart contracts to facilitate C2 communications. Dynamic analysis within the Binary Defense malware lab revealed that recent samples of RemusStealer will attempt to reach out to eth[.]llamarpc[.]com, which is associated with Ethereum. Infection Timeline & Analysis Initial static analysis of RemusStealer revealed that the payload is written in Go, with functionality consistent of discovery tactics via the following: -GetSystemInfo -GetSystemDirectoryA When executed, the payload performed system discovery via the following: -SELECT * FROM AntiVirusProduct -SELECT * FROM Win32_VideoController -SELECT * FROM Win32_OperatingSystem These commands gather information regarding the compromised system’s operating system, detailed information on hardware specifications, settings and status information in relation to graphics/display adapters, and the current installed antivirus product. Hidden Desktops RemusStealer is observed to employ the use of hidden/alternative desktops as a means to evade detection on the compromised machine by the victim.
·binarydefense.com·
RemusStealer: EtherHiding In Hidden Windows
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls.
·bleepingcomputer.com·
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Trump inaugura l’era della “Super Intelligence”: la sicurezza dell’AI passa alle Big Tech
Trump inaugura l’era della “Super Intelligence”: la sicurezza dell’AI passa alle Big Tech
Trump ribattezza l'intelligenza artificiale «Super Intelligence» con un ordine esecutivo. Ma la sostanza cyber è nell'accordo firmato dalle Big dell'AI: quattro livelli di controlli e audit, volontari e con una supervisione indipendente. Cosa prevedono, dove sono i limiti e cosa devono fare aziende e consulenti
·cybersecurity360.it·
Trump inaugura l’era della “Super Intelligence”: la sicurezza dell’AI passa alle Big Tech
Medela - 423,947 breached accounts
Medela - 423,947 breached accounts
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact information, including names, physical addresses and phone numbers, with some records also containing associated support tickets.
·haveibeenpwned.com·
Medela - 423,947 breached accounts