Over Security

Over Security

31461 bookmarks
Custom sorting
Data breach at fintech firm Figure affects nearly 1 million accounts
Data breach at fintech firm Figure affects nearly 1 million accounts
Hackers have stolen the personal and contact information of nearly 1 million accounts after breaching the systems of Figure Technology Solutions, a self-described blockchain-native financial technology company.
·bleepingcomputer.com·
Data breach at fintech firm Figure affects nearly 1 million accounts
Microsoft says bug causes Copilot to summarize confidential emails
Microsoft says bug causes Copilot to summarize confidential emails
Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies that organizations rely on to protect sensitive information.
·bleepingcomputer.com·
Microsoft says bug causes Copilot to summarize confidential emails
1-15 February 2026 Cyber Attacks Timeline
1-15 February 2026 Cyber Attacks Timeline
In the first half of February 2026 I collected 96 events (6.4 events/day) with a threat landscape dominated by malware with 33%, (it was 38% in the second half of last month, once again ahead of ra…
·hackmageddon.com·
1-15 February 2026 Cyber Attacks Timeline
Data breach di Odido: quando il social engineering batte qualsiasi firewall
Data breach di Odido: quando il social engineering batte qualsiasi firewall
L’operatore telefonico Odido è rimasto vittima di un importate data breach: 6,2 milioni di clienti esposti, Salesforce come vettore, e autenticazione MFA bypassata. Un caso di violazione dati che è un manuale di social engineering che ogni CISO dovrebbe studiare
·cybersecurity360.it·
Data breach di Odido: quando il social engineering batte qualsiasi firewall
Deepfake su X, l’autorità irlandese apre l’indagine: la prova del fuoco per il DSA
Deepfake su X, l’autorità irlandese apre l’indagine: la prova del fuoco per il DSA
L’autorità per la protezione dati di Dublino apre un procedimento su X per la diffusione virale di immagini sintetiche non consensuali. Un procedimento che riapre il dibattito sulla moderazione dei contenuti, sulla tenuta del principio di privacy by design e sull’effettiva capacità del DSA di incidere sui rischi sistemici delle piattaforme
·cybersecurity360.it·
Deepfake su X, l’autorità irlandese apre l’indagine: la prova del fuoco per il DSA
“Good enough” emulation: Fuzzing a single thread to uncover vulnerabilities
“Good enough” emulation: Fuzzing a single thread to uncover vulnerabilities
A Talos researcher used targeted emulation of the Socomec DIRIS M-70 gateway’s Modbus thread to uncover six patched vulnerabilities, showcasing efficient tools and methods for IoT security testing.
·blog.talosintelligence.com·
“Good enough” emulation: Fuzzing a single thread to uncover vulnerabilities
Glendale man gets 5 years in prison for role in darknet drug ring
Glendale man gets 5 years in prison for role in darknet drug ring
​A Glendale man was sentenced to nearly five years in federal prison for his role in a darknet drug trafficking operation that sold cocaine, methamphetamine, MDMA, and ketamine to customers across the United States.
·bleepingcomputer.com·
Glendale man gets 5 years in prison for role in darknet drug ring
La privacy by design del whistleblowing e come realizzarla
La privacy by design del whistleblowing e come realizzarla
Due delibere dell'Autorità nazionale anticorruzione, rafforzate ora dal parere del Garante della privacy, stabiliscono le regole per i canali di segnalazione anonima. La sicurezza digitale del segnalante è un obbligo non di facciata
·cybersecurity360.it·
La privacy by design del whistleblowing e come realizzarla
Figure - 967,178 breached accounts
Figure - 967,178 breached accounts
In February 2026, data obtained from the fintech lending platform Figure was publicly posted online. The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access.
·haveibeenpwned.com·
Figure - 967,178 breached accounts
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites
A Spanish court has granted precautionary measures against NordVPN and ProtonVPN, ordering the two popular VPN providers to block 16 websites that facilitate piracy of football matches.
·bleepingcomputer.com·
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites
Spain orders NordVPN and ProtonVPN to block LaLiga stream piracy
Spain orders NordVPN and ProtonVPN to block LaLiga stream piracy
A Spanish court has granted precautionary measures against NordVPN and ProtonVPN, ordering the two popular VPN providers to block 16 websites that facilitate piracy of football matches.
·bleepingcomputer.com·
Spain orders NordVPN and ProtonVPN to block LaLiga stream piracy
Flaws in popular VSCode extensions expose developers to attacks
Flaws in popular VSCode extensions expose developers to attacks
Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely.
·bleepingcomputer.com·
Flaws in popular VSCode extensions expose developers to attacks
Chinese hackers exploiting Dell zero-day flaw since mid-2024
Chinese hackers exploiting Dell zero-day flaw since mid-2024
A suspected Chinese state-backed hacking group has been quietly exploiting a critical Dell security flaw in zero-day attacks that started in mid-2024.
·bleepingcomputer.com·
Chinese hackers exploiting Dell zero-day flaw since mid-2024
针对叙利亚军人的复合式攻击活动分析
针对叙利亚军人的复合式攻击活动分析
此次针对向叙利亚军人的复合式攻击具有迷惑性强,破坏性大,难以追踪的特点,一旦感染,甚至威胁到受害者及其家人的生命财产安全。
·secrss.com·
针对叙利亚军人的复合式攻击活动分析
Microsoft Teams outage affects users in United States, Europe
Microsoft Teams outage affects users in United States, Europe
​Microsoft is working to resolve an ongoing outage affecting Microsoft Teams users, causing delays and preventing some from accessing the service.
·bleepingcomputer.com·
Microsoft Teams outage affects users in United States, Europe
What 5 Million Apps Revealed About Secrets in JavaScript
What 5 Million Apps Revealed About Secrets in JavaScript
Leaked API keys are nothing new, but the scale of the problem in front-end code has been largely a mystery - until now. Intruder's research team built a new secrets detection method and scanned 5 million applications specifically looking for secrets hidden in JavaScript bundles. Here's what we learned.
·bleepingcomputer.com·
What 5 Million Apps Revealed About Secrets in JavaScript
Il malware che ruba password e ambienti delle IA locali
Il malware che ruba password e ambienti delle IA locali
Hudson Rock è un’azienda specializzata in sicurezza informatica che si è imbattuta (probabilmente) per prima in un’interessante evoluzione nel mondo degli infostealer. Per la prima volta, infatti, è stato trovato un malware che prende di mira non soltanto l’identità “umana”, ma anche l’identità operativa di un assistente software. Il payload, infatti, ha esfiltrato l’intero ambiente …
·securityinfo.it·
Il malware che ruba password e ambienti delle IA locali