Over Security

Over Security

35764 bookmarks
Custom sorting
Happy 16th Birthday, KrebsOnSecurity.com!
Happy 16th Birthday, KrebsOnSecurity.com!
KrebsOnSecurity.com celebrates its 16th anniversary today! A huge "thank you" to all of our readers -- newcomers, long-timers and drive-by critics alike. Your engagement this past year here has been tremendous and truly a salve on a handful of dark…
·krebsonsecurity.com·
Happy 16th Birthday, KrebsOnSecurity.com!
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
A Lithuanian national has been arrested for his alleged involvement in infecting 2.8 million systems with clipboard-stealing malware disguised as the KMSAuto tool for illegally activating Windows and Office software.
·bleepingcomputer.com·
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
Romanian energy provider hit by Gentlemen ransomware attack
Romanian energy provider hit by Gentlemen ransomware attack
A ransomware attack hit Oltenia Energy Complex (Complexul Energetic Oltenia), Romania's largest coal-based energy producer, on the second day of Christmas, taking down its IT infrastructure.
·bleepingcomputer.com·
Romanian energy provider hit by Gentlemen ransomware attack
ChatGPT finally rolls out Thinking time toggle on mobile
ChatGPT finally rolls out Thinking time toggle on mobile
OpenAI is rolling out an update to ChatGPT on mobile that finally allows you to select the Thinking time toggle, also called "juice" of the model.
·bleepingcomputer.com·
ChatGPT finally rolls out Thinking time toggle on mobile
The Real-World Attacks Behind OWASP Agentic AI Top 10
The Real-World Attacks Behind OWASP Agentic AI Top 10
OWASP's new Agentic AI Top 10 highlights real-world attacks already targeting autonomous AI systems, from goal hijacking to malicious MCP servers. Koi Security breaks down real-world incidents behind multiple categories, including two cases cited by OWASP, showing how agent tools and runtime behavior are being abused.
·bleepingcomputer.com·
The Real-World Attacks Behind OWASP Agentic AI Top 10
Former Coinbase support agent arrested for helping hackers
Former Coinbase support agent arrested for helping hackers
A former Coinbase customer service agent was arrested in India for helping hackers earlier this year steal sensitive customer information from a company database.
·bleepingcomputer.com·
Former Coinbase support agent arrested for helping hackers
5 Ways MSSPs Can Win Clients in 2026
5 Ways MSSPs Can Win Clients in 2026
Learn how TI Feeds improve detection, reduce MTTR, enable threat hunting, strengthen reporting, and drive long-term client retention.
·any.run·
5 Ways MSSPs Can Win Clients in 2026
Korean Air data breach exposes data of thousands of employees
Korean Air data breach exposes data of thousands of employees
Korean Air experienced a data breach affecting thousands of employees after Korean Air Catering & Duty-Free (KC&D), its in-flight catering supplier and former subsidiary, was recently hacked.
·bleepingcomputer.com·
Korean Air data breach exposes data of thousands of employees
Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks
Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks
Fortinet has warned customers that threat actors are still actively exploiting a critical FortiOS vulnerability that allows them to bypass two-factor authentication (2FA) when targeting vulnerable FortiGate firewalls.
·bleepingcomputer.com·
Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks
MongoBleed, la vulnerabilità in MongoDB è già sfruttata in rete: aggiornamento urgente
MongoBleed, la vulnerabilità in MongoDB è già sfruttata in rete: aggiornamento urgente
Disponibile in rete l’exploit per la vulnerabilità MongoBleed identificata in MongoDB: lo sfruttamento attivo potrebbe consentire l’accesso non controllato a zone di memoria riservate. La falla di sicurezza è già stata risolta dal vendor, per cui è urgente applicare il prima possibile la patch
·cybersecurity360.it·
MongoBleed, la vulnerabilità in MongoDB è già sfruttata in rete: aggiornamento urgente
You’ve been targeted by government spyware. Now what?
You’ve been targeted by government spyware. Now what?
Tech companies are increasingly warning their customers that they have been targeted by governments with advanced government spyware, such as NSO's Pegasus or Paragon's Graphite. What happens after receiving a threat notification?
·techcrunch.com·
You’ve been targeted by government spyware. Now what?
Manipolazione dei prompt: la bassa soglia di accesso apre il vaso di Pandora
Manipolazione dei prompt: la bassa soglia di accesso apre il vaso di Pandora
Il prompt hacking o prompt injection ricorda i famigerati attacchi SQL injection dei primi anni 2000. Abbiamo già visto tattiche simili in passato. Ecco cosa rende questa minaccia particolarmente difficile da affrontare
·cybersecurity360.it·
Manipolazione dei prompt: la bassa soglia di accesso apre il vaso di Pandora
Quando un’entità finanziaria è anche un fornitore ICT: gli impatti su GDPR, DORA, NIS2
Quando un’entità finanziaria è anche un fornitore ICT: gli impatti su GDPR, DORA, NIS2
Un’azienda, titolare di un trattamento, potrebbe nominare un proprio fornitore come responsabile del trattamento oppure operare come responsabile del trattamento per conto di uno o più clienti. O ancora agire come titolare e responsabile. Ecco che cosa accade, dal punto di vista della conformità normativa, qualora un’entità finanziaria ricopra anche il ruolo di fornitore ICT
·cybersecurity360.it·
Quando un’entità finanziaria è anche un fornitore ICT: gli impatti su GDPR, DORA, NIS2
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web.
·bleepingcomputer.com·
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
Hacker claims to leak WIRED database with 2.3 million records
Hacker claims to leak WIRED database with 2.3 million records
A hacker claims to have breached Condé Nast and leaked an alleged WIRED database containing more than 2.3 million subscriber records, while also warning that they plan to release up to 40 million additional records for other Condé Nast properties.
·bleepingcomputer.com·
Hacker claims to leak WIRED database with 2.3 million records
Massive Rainbow Six Siege breach gives players billions of credits
Massive Rainbow Six Siege breach gives players billions of credits
Ubisoft's Rainbow Six Siege (R6) suffered a breach that allowed hackers to abuse internal systems to ban and unban players, manipulate in-game moderation feeds, and grant massive amounts of in-game currency and cosmetic items to accounts worldwide.
·bleepingcomputer.com·
Massive Rainbow Six Siege breach gives players billions of credits
WIRED - 2,364,431 breached accounts
WIRED - 2,364,431 breached accounts
In December 2025, 2.3M records of WIRED magazine users allegedly obtained from parent company Condé Nast were published online. The most recent data dated back to the previous September and exposed email addresses and display names, as well as, for a small number of users, their name, phone number, date of birth, gender, and geographic location or full physical address. The WIRED data allegedly represents a subset of Condé Nast brands the hacker also claims to have obtained.
·haveibeenpwned.com·
WIRED - 2,364,431 breached accounts
Vectored Exception Handling Squared
Vectored Exception Handling Squared
A detailed exploration of VEH² in Rust, showing how vectored exception handling and CPU debug registers can be used to intercept sensitive functions like AmsiScanBuffer without code patching or SetThreadContext, and where detection opportunities still exist.
·fluxsec.red·
Vectored Exception Handling Squared
Fake GrubHub emails promise tenfold return on sent cryptocurrency
Fake GrubHub emails promise tenfold return on sent cryptocurrency
Grubhub users received fraudulent messages, apparently from a company email address, promising a tenfold bitcoin payout in return for a transfer to a specified wallet.
·bleepingcomputer.com·
Fake GrubHub emails promise tenfold return on sent cryptocurrency