Over Security

Over Security

34848 bookmarks
Custom sorting
Coder's registry infrastructure compromised to push malicious modules
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
·bleepingcomputer.com·
Coder's registry infrastructure compromised to push malicious modules
HPE patches critical ArubaOS-CX remote code execution flaw
HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution.
·bleepingcomputer.com·
HPE patches critical ArubaOS-CX remote code execution flaw
The story behind the intelligence
The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
·blog.talosintelligence.com·
The story behind the intelligence
Bugpocalypse: perché l’apocalisse AI è in ritardo
Bugpocalypse: perché l’apocalisse AI è in ritardo
L'impatto dell'IA sulla cybersecurity: perché la bugpocalypse è in ritardo e come i CISO possono proteggere le reti aziendali.
·cybersecurity360.it·
Bugpocalypse: perché l’apocalisse AI è in ritardo
Critical Elementor Pro flaw exploited to take over WordPress sites
Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
·bleepingcomputer.com·
Critical Elementor Pro flaw exploited to take over WordPress sites
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover.
·bleepingcomputer.com·
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Email aziendali, metadati e controlli difensivi: l’utilizzabilità della prova digitale
Email aziendali, metadati e controlli difensivi: l’utilizzabilità della prova digitale
Una recente sentenza del tribunale di Pisa offre spunti interpretativi interessanti e una soluzione condivisibile sul piano operativo, anche se soggetta a possibili interventi di riforma nei successivi gradi di giudizio, dovendosi confrontare con regole, giurisprudenza e principi espressi dal Garante Privacy. Quando l'email vale come prova digitale
·cybersecurity360.it·
Email aziendali, metadati e controlli difensivi: l’utilizzabilità della prova digitale
ClickFix evolve con TerminalFix: il falso CAPTCHA diventa una porta verso la rete aziendale
ClickFix evolve con TerminalFix: il falso CAPTCHA diventa una porta verso la rete aziendale
Un falso CAPTCHA convince la vittima a eseguire PowerShell, ma è solo l’inizio. Con TerminalFix, ClickFix evolve in una catena multistadio che effettua ricognizione dell’ambiente Active Directory e crea un reverse tunnel, trasformando l’endpoint compromesso in un potenziale punto di accesso alla rete aziendale
·cybersecurity360.it·
ClickFix evolve con TerminalFix: il falso CAPTCHA diventa una porta verso la rete aziendale
Analisi Tecnica del Kit MaoMao PhaaS: Tattiche AiTM ed Evasione Avanzata
Analisi Tecnica del Kit MaoMao PhaaS: Tattiche AiTM ed Evasione Avanzata
L'analisi del codice sorgente client-side di una recente campagna di phishing ha rivelato l'impiego del kit MaoMao, una piattaforma avanzata di Phishing-as-a-Service (PhaaS). Il malware opera come reverse proxy in scenari Adversary-in-the-Middle (AiTM) per bypassare l'MFA.
·blog.lobsec.com·
Analisi Tecnica del Kit MaoMao PhaaS: Tattiche AiTM ed Evasione Avanzata
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday.
·bleepingcomputer.com·
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
How I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope's official prayer app, with a single GET request. Reported January 3rd. Still live six months later. Nobody has ever responded.
·bobdahacker.com·
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails