Over Security

Over Security

35113 bookmarks
Custom sorting
ClickLock Stealer: Paste Once, Lose Everything
ClickLock Stealer: Paste Once, Lose Everything
Analysis of ClickLock, a modular macOS stealer delivered via ClickFix that uses fake dialogs, kill loops, and a GSocket backdoor to steal passwords, browser data, and crypto wallets.
·group-ib.com·
ClickLock Stealer: Paste Once, Lose Everything
Dutch police bust investment fraud ring stealing over €100 million
Dutch police bust investment fraud ring stealing over €100 million
The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims.
·bleepingcomputer.com·
Dutch police bust investment fraud ring stealing over €100 million
Zoom warns of critical account takeover vulnerability
Zoom warns of critical account takeover vulnerability
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts.
·bleepingcomputer.com·
Zoom warns of critical account takeover vulnerability
Microsoft patches bug in video game Age of Empires II
Microsoft patches bug in video game Age of Empires II
The vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.
·techcrunch.com·
Microsoft patches bug in video game Age of Empires II
​ ​AsyncAPI npm packages infected with credential-stealing malware
​ ​AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
·bleepingcomputer.com·
​ ​AsyncAPI npm packages infected with credential-stealing malware
We built a vulnerability vending machine: AI tokens in, zero-days out
We built a vulnerability vending machine: AI tokens in, zero-days out
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure.
·bleepingcomputer.com·
We built a vulnerability vending machine: AI tokens in, zero-days out
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega
Le nuove FAQ dell’ACN ribadiscono che la nomina di un CISO non esaurisce gli obblighi previsti dalla NIS2. La cyber security entra stabilmente nella governance d’impresa: le attività operative si delegano, ma responsabilità, indirizzo e supervisione restano in capo al CdA
·cybersecurity360.it·
NIS2, le nuove FAQ ACN chiariscono il ruolo del CdA: la cyber si governa, non si delega
Tre punti non negoziabili per i CISO nell’era AI agentica
Tre punti non negoziabili per i CISO nell’era AI agentica
L’era agentica sta già cambiando il modo in cui avvengono gli attacchi, il comportamento dei sistemi e le responsabilità dei team di sicurezza. Ecco i tre punti per i CISO per affrontare l'AI agentica
·cybersecurity360.it·
Tre punti non negoziabili per i CISO nell’era AI agentica
Patch Tuesday, il record che nessuno voleva: 622 CVE e un nuovo modo di fare sicurezza
Patch Tuesday, il record che nessuno voleva: 622 CVE e un nuovo modo di fare sicurezza
Il Patch Tuesday di luglio 2026 stabilisce il record assoluto nella storia di Microsoft: 622 CVE corrette, incluse due zero-day già sfruttate in attacchi reali su SharePoint e Active Directory. Eppure, nessuna delle due supera il CVSS 6. Un segnale inequivocabile: il punteggio non è più lo strumento giusto per decidere cosa patchare per primo
·cybersecurity360.it·
Patch Tuesday, il record che nessuno voleva: 622 CVE e un nuovo modo di fare sicurezza
OkoBot: new sophisticated malware framework targets cryptocurrency users
OkoBot: new sophisticated malware framework targets cryptocurrency users
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
·securelist.com·
OkoBot: new sophisticated malware framework targets cryptocurrency users
CISA warns admins to patch actively exploited SharePoint flaws
CISA warns admins to patch actively exploited SharePoint flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances.
·bleepingcomputer.com·
CISA warns admins to patch actively exploited SharePoint flaws
Come le AI agentiche impattano sulla nostra autonomia cognitiva
Come le AI agentiche impattano sulla nostra autonomia cognitiva
Le AI agentiche non si limitano a elaborare dati: possono modellare pensieri, preferenze e giudizi. Un'analisi dei rischi emergenti, delle responsabilità e delle soluzioni interdisciplinari è doverosa. E gli esperti di questo settore ci aiutano a farla
·cybersecurity360.it·
Come le AI agentiche impattano sulla nostra autonomia cognitiva
Fluke - 821,100 breached accounts
Fluke - 821,100 breached accounts
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.
·haveibeenpwned.com·
Fluke - 821,100 breached accounts