Over Security

Over Security

35021 bookmarks
Custom sorting
Massive Rainbow Six Siege breach gives players billions of credits
Massive Rainbow Six Siege breach gives players billions of credits
Ubisoft's Rainbow Six Siege (R6) suffered a breach that allowed hackers to abuse internal systems to ban and unban players, manipulate in-game moderation feeds, and grant massive amounts of in-game currency and cosmetic items to accounts worldwide.
·bleepingcomputer.com·
Massive Rainbow Six Siege breach gives players billions of credits
WIRED - 2,364,431 breached accounts
WIRED - 2,364,431 breached accounts
In December 2025, 2.3M records of WIRED magazine users allegedly obtained from parent company Condé Nast were published online. The most recent data dated back to the previous September and exposed email addresses and display names, as well as, for a small number of users, their name, phone number, date of birth, gender, and geographic location or full physical address. The WIRED data allegedly represents a subset of Condé Nast brands the hacker also claims to have obtained.
·haveibeenpwned.com·
WIRED - 2,364,431 breached accounts
Vectored Exception Handling Squared
Vectored Exception Handling Squared
A detailed exploration of VEH² in Rust, showing how vectored exception handling and CPU debug registers can be used to intercept sensitive functions like AmsiScanBuffer without code patching or SetThreadContext, and where detection opportunities still exist.
·fluxsec.red·
Vectored Exception Handling Squared
Fake GrubHub emails promise tenfold return on sent cryptocurrency
Fake GrubHub emails promise tenfold return on sent cryptocurrency
Grubhub users received fraudulent messages, apparently from a company email address, promising a tenfold bitcoin payout in return for a transfer to a specified wallet.
·bleepingcomputer.com·
Fake GrubHub emails promise tenfold return on sent cryptocurrency
Trust Wallet confirms extension hack led to $7 million crypto theft
Trust Wallet confirms extension hack led to $7 million crypto theft
Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers.
·bleepingcomputer.com·
Trust Wallet confirms extension hack led to $7 million crypto theft
MongoDB warns admins to patch severe vulnerability immediately
MongoDB warns admins to patch severe vulnerability immediately
MongoDB has warned IT admins to immediately patch a high-severity memory-read vulnerability that may be exploited by unauthenticated attackers remotely.
·bleepingcomputer.com·
MongoDB warns admins to patch severe vulnerability immediately
Trust Wallet Chrome extension hack tied to millions in losses
Trust Wallet Chrome extension hack tied to millions in losses
Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers.
·bleepingcomputer.com·
Trust Wallet Chrome extension hack tied to millions in losses
Invisible Unicode Obfuscation: Beyond GlassWorm
Invisible Unicode Obfuscation: Beyond GlassWorm
A deep dive into the invisible Unicode obfuscation technique popularized by GlassWorm, extended to undocumented variants and unseen attack surfaces such as command lines and security logs.
·reggia.xyz·
Invisible Unicode Obfuscation: Beyond GlassWorm
Utair - 401,400 breached accounts
Utair - 401,400 breached accounts
In August 2020, news broke of a data breach of Russian airline Utair that dated back to the previous year. The breach contained over 400k unique email addresses along with extensive personal information including names, physical addresses, dates of birth, passport numbers and loyalty program details.
·haveibeenpwned.com·
Utair - 401,400 breached accounts
Microsoft Teams to let admins block external users via Defender portal
Microsoft Teams to let admins block external users via Defender portal
Microsoft announced that security administrators will soon be able to block external users from sending messages, calls, or meeting invitations to members of their organization via Teams.
·bleepingcomputer.com·
Microsoft Teams to let admins block external users via Defender portal
Fake MAS Windows activation domain used to spread PowerShell malware
Fake MAS Windows activation domain used to spread PowerShell malware
A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used to distribute malicious PowerShell scripts that infect Windows systems with the 'Cosmali Loader'.
·bleepingcomputer.com·
Fake MAS Windows activation domain used to spread PowerShell malware
Microsoft rolls out hardware-accelerated BitLocker in Windows 11
Microsoft rolls out hardware-accelerated BitLocker in Windows 11
Microsoft is rolling out hardware-accelerated BitLocker in Windows 11 to address growing performance and security concerns by leveraging the capabilities of system-on-a-chip and CPU.
·bleepingcomputer.com·
Microsoft rolls out hardware-accelerated BitLocker in Windows 11
FBI seizes domain storing bank credentials stolen from U.S. victims
FBI seizes domain storing bank credentials stolen from U.S. victims
The U.S. government has seized the 'web3adspanels.org' domain and the associated database used by cybercriminals to host bank login credentials stolen in account takeover attacks.
·bleepingcomputer.com·
FBI seizes domain storing bank credentials stolen from U.S. victims
MongoDB warns admins to patch severe RCE flaw immediately
MongoDB warns admins to patch severe RCE flaw immediately
MongoDB has warned IT admins to immediately patch a high-severity vulnerability that can be exploited in remote code execution (RCE) attacks targeting vulnerable servers.
·bleepingcomputer.com·
MongoDB warns admins to patch severe RCE flaw immediately
Reversing Android Native Libraries - Coper
Reversing Android Native Libraries - Coper
This blog post is part of a recent personal investigation into a malware loader known as Coper. Rather than providing a full, line-by-line dissection of the malware, the goal is to introduce a high-level approach to triaging an Android native library. An increasing number of Android malware families now rely on native libraries to hide their payloads, making reverse engineering a little bit more challenging. Nowadays, having an understanding of what is happening on native libraries is a fundamental skill that needs to be mastered, since it also represents a pivotal point to start investigating other malware families and even architecture.
·viuleeenz.github.io·
Reversing Android Native Libraries - Coper
Dall’era delle password all’autenticazione resistente al phishing: la guida NIST
Dall’era delle password all’autenticazione resistente al phishing: la guida NIST
Il NIST ha pubblicato la SP 800-63-4, una revisione che aggiorna le linee guida per l'identità digitale, dopo un processo di quasi quattro anni che ha incluso due bozze pubbliche e circa 6.000 commenti dal pubblico. Ridefinite le best practice per password e autenticazione. Ecco i punti cardine
·cybersecurity360.it·
Dall’era delle password all’autenticazione resistente al phishing: la guida NIST
Reversing Android Native Libraries - Coper Notes
Reversing Android Native Libraries - Coper Notes
This blog post is part of a recent personal investigation into a malware loader known as Coper. Rather than providing a full, line-by-line dissection of the malware, the goal is to introduce a high-level approach to triaging an Android native library. An increasing number of Android malware families now rely on native libraries to hide their payloads, making reverse engineering a little bit more challenging. Nowadays, having an understanding of what is happening on native libraries is a fundamental skill that needs to be mastered, since it also represents a pivotal point to start investigating other malware families and even architecture.
·viuleeenz.github.io·
Reversing Android Native Libraries - Coper Notes
Una poltrona per (la NIS) 2
Una poltrona per (la NIS) 2
La NIS 2 rappresenta una spinta del mercato per porre la governance della sicurezza cyber al centro dei servizi digitali, motivo per cui è necessario prenderla in considerazione oltre che come obbligo normativo cogente anche come insieme di best practicescui fare riferimento
·cybersecurity360.it·
Una poltrona per (la NIS) 2