Over Security

Over Security

34851 bookmarks
Custom sorting
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
We recently discovered an exposed server that was used for multi-victim exploitation, staging, review, and validation. Claude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration. We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful exploits. Logs showed an automated pipeline for exploitation, hit scoring, alerting, and secret harvesting.
·thedfirreport.com·
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
In April, we observed an intrusion linked to the Atos-reported campaign where an EtherRAT was installed via a malicious MSI masquerading as a Sysinternals tool. Later in the intrusion, we observed the deployment of a new malware framework named TukTuk, first reported by Evangelos G, which, according to their analysis, is AI-generated. In addition to this, the threat actor used the RMM GoTo Resolve. Using this access, they successfully exfiltrated data to a cloud service and then deployed The Gentlemen ransomware.
·thedfirreport.com·
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
Strategic autonomy: Where you get to choose
Strategic autonomy: Where you get to choose
Stop being locked into "black box" ecosystems. Discover how Sekoia’s vendor-agnostic platform ensures data sovereignty, GDPR compliance, and technological independence.
·blog.sekoia.io·
Strategic autonomy: Where you get to choose
Why 2FA SMS is a Bad Idea in 2026
Why 2FA SMS is a Bad Idea in 2026
Relying on SMS as a 2FA method actually causes a larger problem than what it’s meant to solve. Understand why SMS authentication is insecure and which alternatives are best to protect your account.
·blog.sucuri.net·
Why 2FA SMS is a Bad Idea in 2026
WordPress DDoS Protection: How to Keep Your Site Online
WordPress DDoS Protection: How to Keep Your Site Online
A DDoS attack on WordPress can take your site offline in minutes. Learn WordPress DDoS protection best practices and how to respond when you're hit.
·blog.sucuri.net·
WordPress DDoS Protection: How to Keep Your Site Online
What is online gambling spam and what can I do about it?
What is online gambling spam and what can I do about it?
Have you ever seen casino ads that do not look legitimate at all? In this post we explain what gambling spam is and how you can protect your website.
·blog.sucuri.net·
What is online gambling spam and what can I do about it?
Vulnerability & Patch Roundup — April 2026
Vulnerability & Patch Roundup — April 2026
Discover important WordPress vulnerabilities this month and how to safeguard your site with essential security updates.
·blog.sucuri.net·
Vulnerability & Patch Roundup — April 2026
DNSSEC: The Extra Security Layer That Can Break Your Padlock
DNSSEC: The Extra Security Layer That Can Break Your Padlock
DNSSEC adds critical DNS security, but even small mistakes can cause SSL failures. Understand SC‑085v2 and how DNSSEC impacts certificate issuance.
·blog.sucuri.net·
DNSSEC: The Extra Security Layer That Can Break Your Padlock
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vertical for initial access since Q2 2025.
·blog.talosintelligence.com·
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
UAT-4356's Targeting of Cisco Firepower Devices
UAT-4356's Targeting of Cisco Firepower Devices
Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices.
·blog.talosintelligence.com·
UAT-4356's Targeting of Cisco Firepower Devices
It pays to be a forever student
It pays to be a forever student
In this newsletter, Joe discusses why understanding other disciplines can often flow back into the macro and micro of cybersecurity, especially in a world of AI.
·blog.talosintelligence.com·
It pays to be a forever student
Five defender priorities from the Talos Year in Review
Five defender priorities from the Talos Year in Review
With attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise.
·blog.talosintelligence.com·
Five defender priorities from the Talos Year in Review
AI-powered honeypots: Turning the tables on malicious AI agents
AI-powered honeypots: Turning the tables on malicious AI agents
Just as AI brings time-saving advantages to our lives, it brings similar advantages to threat actors. We can take the advantage back. This blog shows how generative AI can be used to rapidly deploy adaptive honeypot systems.
·blog.talosintelligence.com·
AI-powered honeypots: Turning the tables on malicious AI agents
Great responsibility, without great power
Great responsibility, without great power
In this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity.
·blog.talosintelligence.com·
Great responsibility, without great power
CloudZ RAT potentially steals OTP messages using Pheno plugin
CloudZ RAT potentially steals OTP messages using Pheno plugin
Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.”
·blog.talosintelligence.com·
CloudZ RAT potentially steals OTP messages using Pheno plugin
UAT-8302 and its box full of malware
UAT-8302 and its box full of malware
Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.
·blog.talosintelligence.com·
UAT-8302 and its box full of malware
Insights into the clustering and reuse of phone numbers in scam emails
Insights into the clustering and reuse of phone numbers in scam emails
Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails.
·blog.talosintelligence.com·
Insights into the clustering and reuse of phone numbers in scam emails