Over Security

Over Security

34850 bookmarks
Custom sorting
Patching WP2Shell in the dark using PAI
Patching WP2Shell in the dark using PAI
Will AI let me spend my time at the beach while patching a critical vulnerability in one of the most used CMS in the world? Yes it will. We recently released PAI, our AI Security Agent that acts as a Senior Security Specialist for a wide range of security tasks. For our WAAP (Web Application & API Protection) service WP2Shell was the perfect test run. WP2Shell dropped Friday night (CEST). By Saturday morning we had a virtual patch live on every WordPress site behind our WAAP: one shared rule, ab
·blog.sicuranext.com·
Patching WP2Shell in the dark using PAI
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
·bleepingcomputer.com·
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
·bleepingcomputer.com·
Microsoft shares manual fix for WSUS sync delays and timeouts
Windows LegacyHive zero-day flaw gets free, unofficial patches
Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
·bleepingcomputer.com·
Windows LegacyHive zero-day flaw gets free, unofficial patches
Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
We are presenting here our most complete analysis to date of the Pegasus spyware. This blog post builds on previous technical reports and forensic investigations by Amnesty International’s Security Lab. Significantly it also draws on previously unpublished internal NSO Group marketing material and internal technical material which was disclosed as part of a long-running civil […]
·securitylab.amnesty.org·
Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab
Estée Lauder discloses data breach via Oracle E-Business flaw
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.
·bleepingcomputer.com·
Estée Lauder discloses data breach via Oracle E-Business flaw
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol.
·bleepingcomputer.com·
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
·bleepingcomputer.com·
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
JadePuffer agentic attacks now target AI model data with ransomware
JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
·bleepingcomputer.com·
JadePuffer agentic attacks now target AI model data with ransomware
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings.
·bleepingcomputer.com·
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Suno - 55,282,226 breached accounts
Suno - 55,282,226 breached accounts
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".
·haveibeenpwned.com·
Suno - 55,282,226 breached accounts
HTB Paper Walkthrough
HTB Paper Walkthrough
A technical walkthrough of the HackTheBox Paper challenge, by Andy From Italy.
·secjuice.com·
HTB Paper Walkthrough
Mastodon OSINT: A Comprehensive Introduction
Mastodon OSINT: A Comprehensive Introduction
Part one in our series on Mastodon, focused on gathering OSINT from the platform's users, instances and network.
·secjuice.com·
Mastodon OSINT: A Comprehensive Introduction
x64dbg usage log: start debugging and modify a program
x64dbg usage log: start debugging and modify a program
Explore the comprehensive guide by fairycn on how to master x64dbg on Windows 11, from installation to advanced debugging techniques, ensuring effective program modifications and insightful CPU disassembly analysis.
·secjuice.com·
x64dbg usage log: start debugging and modify a program
Pastebin and Its Incidental OSINT
Pastebin and Its Incidental OSINT
Despite being a great OSINT tool, Pastebin remains misunderstood and underutilized.
·secjuice.com·
Pastebin and Its Incidental OSINT
Using Newly Surfaced Data Breaches for OSINT Research
Using Newly Surfaced Data Breaches for OSINT Research
Data Breach Search Engines (DBSEs) collect and organize leaked information from data breaches, enabling OSINT investigators to access it.
·secjuice.com·
Using Newly Surfaced Data Breaches for OSINT Research
HTB Outdated Walkthrough
HTB Outdated Walkthrough
This Windows Box is incredibly intriguing, featuring challenging passages and an unstable machine. Despite these difficulties, it’s an enjoyable experience with numerous exploits available.
·secjuice.com·
HTB Outdated Walkthrough
The OSINT Toolkit
The OSINT Toolkit
Half of every top OSINT tools list is already dead. The tools rot, the method doesn't. Build a repeatable workflow and treat every tool as disposable.
·secjuice.com·
The OSINT Toolkit
Telegram OSINT
Telegram OSINT
Telegram is the richest open source intel surface online. Here is how to work it in 2026, from forwarding chains to sock puppets, without getting burned.
·secjuice.com·
Telegram OSINT