Over Security

Over Security

35892 bookmarks
Custom sorting
HPE warns of maximum severity RCE flaw in OneView software
HPE warns of maximum severity RCE flaw in OneView software
Hewlett Packard Enterprise (HPE) has patched a maximum-severity vulnerability in its HPE OneView software that enables attackers to execute arbitrary code remotely.
·bleepingcomputer.com·
HPE warns of maximum severity RCE flaw in OneView software
Microsoft: Recent Windows updates break RemoteApp connections
Microsoft: Recent Windows updates break RemoteApp connections
Microsoft has confirmed that recent Windows updates trigger RemoteApp connection failures on Windows 11 24H2/25H2 and Windows Server 2025 devices in Azure Virtual Desktop environments.
·bleepingcomputer.com·
Microsoft: Recent Windows updates break RemoteApp connections
Carte regalo a Natale, i ruoli privacy per i fornitori di gift card
Carte regalo a Natale, i ruoli privacy per i fornitori di gift card
I voucher sono un valido strumento di marketing che necessita di attenta analisi dei rapporti civilistici e normativi con il fornitore delle gift card. Abbiamo anche chiesto un “parere” all'AI: la risposta non è errata, ma decisamente superficiale e incompleta. Ecco perché e cosa prevede il GDPR per i fornitori di gift card
·cybersecurity360.it·
Carte regalo a Natale, i ruoli privacy per i fornitori di gift card
AUTOSUR - 487,226 breached accounts
AUTOSUR - 487,226 breached accounts
In March 2025, the French vehicle inspection company AUTOSUR suffered a data breach exposing over 10M customer records, though only 487k unique email addresses were present. The compromised data included names, phone numbers, physical addresses, and vehicle details such as make and model, VIN, and registration plate. AUTOSUR later issued a disclosure notice with further details.
·haveibeenpwned.com·
AUTOSUR - 487,226 breached accounts
The Botting Network - 96,320 breached accounts
The Botting Network - 96,320 breached accounts
In August 2012, the forum for making money with botting "The Botting Network" suffered a data breach that exposed 96k user records. The now defunct vBulletin forum leaked 96k email addresses, usernames, dates of birth and salted MD5 password hashes.
·haveibeenpwned.com·
The Botting Network - 96,320 breached accounts
Web Hosting Talk - 515,149 breached accounts
Web Hosting Talk - 515,149 breached accounts
In July 2016, the Web Hosting Talk forum suffered a data breach that was subsequently listed for sale. The breach of the vBulletin based forum exposed 515k user records including usernames, email addresses, IP addresses and salted MD5 password hashes.
·haveibeenpwned.com·
Web Hosting Talk - 515,149 breached accounts
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
The Zeroday Cloud hacking competition in London has awarded researchers $320,000 for demonstrating critical remote code execution vulnerabilities in components used in cloud infrastructure.
·bleepingcomputer.com·
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
Sicurezza delle API nell’adozione Zero Trust: ecco problemi e raccomandazioni
Sicurezza delle API nell’adozione Zero Trust: ecco problemi e raccomandazioni
Falle derivanti da difetti di progettazione, errori di implementazione o logiche applicative inadeguate hanno reso le API un obiettivo primario per gli attori malevoli. Ecco il ruolo fondamentale della sicurezza delle API nell'ambito delle architetture Zero Trust
·cybersecurity360.it·
Sicurezza delle API nell’adozione Zero Trust: ecco problemi e raccomandazioni
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
Amazon's AWS GuardDuty security team is warning of an ongoing crypto-mining campaign that targets its Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised credentials for Identity and Access Management (IAM).
·bleepingcomputer.com·
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
Libbiosig, Grassroot DiCoM, Smallstep step-ca vulnerabilities
Libbiosig, Grassroot DiCoM, Smallstep step-ca vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Biosig Project Libbiosig, Grassroot DiCoM, and Smallstep step-ca. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy, except for Grassroot, as the DiCoM vulnerabilities are zero-days. For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets
·blog.talosintelligence.com·
Libbiosig, Grassroot DiCoM, Smallstep step-ca vulnerabilities
WhatsApp device linking abused in account hijacking attacks
WhatsApp device linking abused in account hijacking attacks
Threat actors are abusing the legitimate device-linking feature to hijack WhatsApp accounts via pairing codes in a campaign dubbed GhostPairing.
·bleepingcomputer.com·
WhatsApp device linking abused in account hijacking attacks
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
​Cisco warned customers today of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances.
·bleepingcomputer.com·
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
Sonicwall warns of new SMA1000 zero-day exploited in attacks
Sonicwall warns of new SMA1000 zero-day exploited in attacks
SonicWall warned customers today to patch a vulnerability in the SonicWall SMA1000 Appliance Management Console (AMC) that was chained in zero-day attacks to escalate privileges.
·bleepingcomputer.com·
Sonicwall warns of new SMA1000 zero-day exploited in attacks
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
Cisco Talos is tracking the active targeting of Cisco AsyncOS Software for Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and Cisco Secure Email and Web Manager, formerly known as Cisco Content Security Management Appliance (SMA).
·blog.talosintelligence.com·
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager