Over Security

Over Security

34601 bookmarks
Custom sorting
Target's dev server offline after hackers claim to steal source code
Target's dev server offline after hackers claim to steal source code
Hackers are claiming to be selling internal source code belonging to Target Corporation, after publishing what appears to be a sample of stolen code repositories on a public software development platform. After BleepingComputer notified Target, the files were taken offline and the retailer's developer Git server was inaccessible.
·bleepingcomputer.com·
Target's dev server offline after hackers claim to steal source code
Hidden Telegram proxy links can reveal your IP address in one click
Hidden Telegram proxy links can reveal your IP address in one click
A single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add warnings to proxy links after researchers demonstrated that such one-click interactions could reveal a Telegram user's real IP address.
·bleepingcomputer.com·
Hidden Telegram proxy links can reveal your IP address in one click
Microsoft is retiring the Lens scanner app for iOS, Android
Microsoft is retiring the Lens scanner app for iOS, Android
Microsoft has started retiring the Microsoft Lens PDF scanner app for Android and iOS devices on Friday, January 9th, with plans to remove it from app stores next month.
·bleepingcomputer.com·
Microsoft is retiring the Lens scanner app for iOS, Android
Spanish energy giant Endesa discloses data breach affecting customers
Spanish energy giant Endesa discloses data breach affecting customers
Spanish energy provider Endesa and its Energía XXI operator are notifying customers that hackers accessed the company's systems and accessed contract-related information, which includes personal details.
·bleepingcomputer.com·
Spanish energy giant Endesa discloses data breach affecting customers
Cos’è la guerra cognitiva e qual è la posizione della NATO
Cos’è la guerra cognitiva e qual è la posizione della NATO
Il paradigma della sicurezza globale è al centro di un cambiamento sostanziale. La NATO ha formalizzato la guerra cognitiva come nuova frontiera per la superiorità strategica. Cosa è la guerra cognitiva e quali sono i rischi che la caratterizzano
·cybersecurity360.it·
Cos’è la guerra cognitiva e qual è la posizione della NATO
Raccolta dati e AI, come informare correttamente gli interessati: le raccomandazioni
Raccolta dati e AI, come informare correttamente gli interessati: le raccomandazioni
La CNIL chiarisce come informare gli utenti/interessati quando si utilizzano sistemi di intelligenza artificiale, rendendo note delle linee guida molto operative e altrettanto dettagliate circa gli obblighi di trasparenza quando si raccolgono dati con l’AI. Il tutto in perfetta linea con i dettami del GDPR. Vediamo meglio
·cybersecurity360.it·
Raccolta dati e AI, come informare correttamente gli interessati: le raccomandazioni
Prevent cloud data leaks with Microsoft 365 access reviews
Prevent cloud data leaks with Microsoft 365 access reviews
Microsoft 365 has made file sharing effortless, but that convenience often leaves organizations with little visibility into who can access sensitive data. Tenfold explains how access reviews for shared cloud content can help organizations regain visibility, reduce unnecessary permissions, and prevent data leaks in Microsoft 365.
·bleepingcomputer.com·
Prevent cloud data leaks with Microsoft 365 access reviews
Il caso OVH, quando il Canada sfida la sovranità digitale UE: i rischi per i nostri dati
Il caso OVH, quando il Canada sfida la sovranità digitale UE: i rischi per i nostri dati
Un tribunale canadese ha ordinato a OVHcloud di consegnare dati di clienti archiviati in Europa, creando un conflitto con il diritto francese e mettendo alla prova la sovranità digitale europea. Un caso in cui non è la geografia dei server a determinare la giurisdizione, ma chi è giuridicamente responsabile e può accedervi
·cybersecurity360.it·
Il caso OVH, quando il Canada sfida la sovranità digitale UE: i rischi per i nostri dati
Gestire il rischio cyber dei sistemi di AI: le prime indicazioni operative del NIST
Gestire il rischio cyber dei sistemi di AI: le prime indicazioni operative del NIST
L’intelligenza artificiale è ormai parte integrante dei sistemi e delle decisioni delle organizzazioni. Il suo impatto sulla cyber security non può essere affrontato come un tema tecnico isolato, ma come una questione di governo. È questo l’obiettivo del Cyber AI Profile del NIST. Ecco i punti salienti
·cybersecurity360.it·
Gestire il rischio cyber dei sistemi di AI: le prime indicazioni operative del NIST
CERT-AGID 3-9 gennaio: phishing e malware aprono il 2026
CERT-AGID 3-9 gennaio: phishing e malware aprono il 2026
Settantatrè campagne rilevate in Italia nella prima settimana dell’anno, con smishing INPS e finte sanzioni PagoPA. Oltre a una nuova vulnerabilità critica in n8n.
·securityinfo.it·
CERT-AGID 3-9 gennaio: phishing e malware aprono il 2026
California bans data broker reselling health data of millions
California bans data broker reselling health data of millions
The California Privacy Protection Agency (CalPrivacy) has taken action against the  Datamasters marketing firm that sold the health and personal data of millions of users without being registered as a data broker.
·bleepingcomputer.com·
California bans data broker reselling health data of millions
Instagram denies breach amid claims of 17 million account data leak
Instagram denies breach amid claims of 17 million account data leak
Instagram says it fixed a bug that allowed threat actors to mass-request password reset emails, amid claims that data from more than 17 million Instagram accounts was scraped and leaked online.
·bleepingcomputer.com·
Instagram denies breach amid claims of 17 million account data leak
Instagram - 6,215,150 breached accounts
Instagram - 6,215,150 breached accounts
In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum. The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated email address, and some also contained a phone number. The scraped data appears to be unrelated to password reset requests initiated on the platform, despite coinciding in timeframe. There is no evidence that passwords or other sensitive data were compromised.
·haveibeenpwned.com·
Instagram - 6,215,150 breached accounts
Filtering Cisco API Output
Filtering Cisco API Output
Previously, we created a simple script to print a table of CDP neighbors for all interfaces in the fabric. While writing it, we realized it could be optimized. To optimize the script, we need to change the way we retrieve data.
·adainese.it·
Filtering Cisco API Output
Info Sec Unplugged – CISO e vCISO
Info Sec Unplugged – CISO e vCISO
Le ultime due puntate del podcast, che in realtà sono la prima e la seconda parte di una unica registrazione, sono tornate su un tema che sia io che Andrea, nonostante il nostro percorso profession…
·roccosicilia.com·
Info Sec Unplugged – CISO e vCISO
Detecting Vectored Exception Handling Squared in an EDR
Detecting Vectored Exception Handling Squared in an EDR
A deep Windows internals walkthrough: detecting Vectored Exception Handling Squared (VEH²) by reading DR0-DR3 from thread context in kernel mode, resolving target modules, and raising high-fidelity alerts in Sanctum EDR (Rust).
·fluxsec.red·
Detecting Vectored Exception Handling Squared in an EDR
Microsoft is retiring 'Send to Kindle' in Word
Microsoft is retiring 'Send to Kindle' in Word
Microsoft is retiring a feature that allowed you to send your documents to Kindle straight from Microsoft Word.
·bleepingcomputer.com·
Microsoft is retiring 'Send to Kindle' in Word
Spain arrests 34 suspects linked to Black Axe cyber crime
Spain arrests 34 suspects linked to Black Axe cyber crime
Authorities in Spain have arrested 34 individuals allegedly part of a criminal network involved in cyber fraud and believed to be connected to the Black Axe group responsible for illicit activities across Europe.
·bleepingcomputer.com·
Spain arrests 34 suspects linked to Black Axe cyber crime
BreachForums (2025) - 324,449 breached accounts
BreachForums (2025) - 324,449 breached accounts
In October 2025, a reincarnation of the hacking forum BreachForums, which had previously been shut down multiple times, was taken offline by a coalition of law enforcement agencies. In the months leading up to the takedown, the site itself suffered a data breach that exposed 324k unique email addresses, usernames, and Argon2 password hashes.
·haveibeenpwned.com·
BreachForums (2025) - 324,449 breached accounts
Ireland recalls almost 13,000 passports over missing 'IRL' code
Ireland recalls almost 13,000 passports over missing 'IRL' code
Ireland's Department of Foreign Affairs has recalled nearly 13,000 passports after a software update caused a printing defect. The printing error makes the documents non-compliant with international travel standards and potentially unreadable at automated border gates.
·bleepingcomputer.com·
Ireland recalls almost 13,000 passports over missing 'IRL' code