Over Security

Over Security

36125 bookmarks
Custom sorting
Owner of Empire cybercrime market gets 40 years in prison
Owner of Empire cybercrime market gets 40 years in prison
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020.
·bleepingcomputer.com·
Owner of Empire cybercrime market gets 40 years in prison
Rogue AI Agents
Rogue AI Agents
Live dashboard of incidents where AI agents went rogue: an interactive timeline plus charts by AI company, agent, technique and initial access.
·hackmageddon.com·
Rogue AI Agents
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.
·blog.talosintelligence.com·
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Cyber security e agentic AI: perché il costo dei token diventa un rischio operativo
Cyber security e agentic AI: perché il costo dei token diventa un rischio operativo
Con gli agenti AI, il costo della cybersecurity dipende sempre più dai token consumati durante analisi e investigazioni. Un budget esaurito può interrompere un'indagine proprio quando serve. Per questo capacity planning, controllo dei consumi e misurazione dei risultati diventano nuovi strumenti di governance dei SOC
·cybersecurity360.it·
Cyber security e agentic AI: perché il costo dei token diventa un rischio operativo
Privacy by design: progettare l’errore, non dipendere da utenti perfetti
Privacy by design: progettare l’errore, non dipendere da utenti perfetti
La privacy by design non può basarsi sull'infallibilità delle persone. L'errore umano deve diventare un requisito di progettazione, attraverso sistemi capaci di prevenire le condotte rischiose, limitarne le conseguenze e rilevare le anomalie. Perché la protezione dei dati non dipenda soltanto dalla diligenza degli operatori
·cybersecurity360.it·
Privacy by design: progettare l’errore, non dipendere da utenti perfetti
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.
·bleepingcomputer.com·
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
CyrusOne - 373,460 breached accounts
CyrusOne - 373,460 breached accounts
In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt. The group subsequently published data allegedly obtained from the company, which included 373k unique email addresses across records relating to users, sales leads and CyrusOne employees. The data largely consisted of corporate contact information, including names, physical addresses, phone numbers and job titles. It also included support tickets and other information related to the organisation's operations.
·haveibeenpwned.com·
CyrusOne - 373,460 breached accounts
Ransomware recovery CEO charged over secret ransom payments
Ransomware recovery CEO charged over secret ransom payments
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data.
·bleepingcomputer.com·
Ransomware recovery CEO charged over secret ransom payments
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators.
·bleepingcomputer.com·
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
Hackers hijack Google domains after breaching ccTLD registries
Hackers hijack Google domains after breaching ccTLD registries
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.
·bleepingcomputer.com·
Hackers hijack Google domains after breaching ccTLD registries
Microsoft, Adobe, Apple, and Foxit vulnerabilities
Microsoft, Adobe, Apple, and Foxit vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.  For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intellig
·blog.talosintelligence.com·
Microsoft, Adobe, Apple, and Foxit vulnerabilities
Microsoft Outlook to block MSIX attachments starting November
Microsoft Outlook to block MSIX attachments starting November
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month.
·bleepingcomputer.com·
Microsoft Outlook to block MSIX attachments starting November