Over Security

Over Security

33710 bookmarks
Custom sorting
Google Chrome adds session cookie theft protection for all users
Google Chrome adds session cookie theft protection for all users
Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers.
·bleepingcomputer.com·
Google Chrome adds session cookie theft protection for all users
US charges Google security engineer with Polymarket insider trading
US charges Google security engineer with Polymarket insider trading
A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market.
·bleepingcomputer.com·
US charges Google security engineer with Polymarket insider trading
Charter Communications data breach affects 4.9 million accounts
Charter Communications data breach affects 4.9 million accounts
The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned.
·bleepingcomputer.com·
Charter Communications data breach affects 4.9 million accounts
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.
·securelist.com·
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
A likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools.
·bleepingcomputer.com·
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
BTMOB Android malware service generates custom phishing payloads
BTMOB Android malware service generates custom phishing payloads
An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures.
·bleepingcomputer.com·
BTMOB Android malware service generates custom phishing payloads
Charter - 4,851,517 breached accounts
Charter - 4,851,517 breached accounts
In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
·haveibeenpwned.com·
Charter - 4,851,517 breached accounts
FBI warns of fake FIFA websites running World Cup fraud schemes
FBI warns of fake FIFA websites running World Cup fraud schemes
The FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and hospitality packages, and push other fraud related to the event.
·bleepingcomputer.com·
FBI warns of fake FIFA websites running World Cup fraud schemes
Less panic patching, more precision
Less panic patching, more precision
In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.
·blog.talosintelligence.com·
Less panic patching, more precision
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
·bleepingcomputer.com·
Hackers exploit FortiClient EMS flaw to push infostealer malware
Interview #11 NoName057(16)
Interview #11 NoName057(16)
The following interview, which we publish in full, was conducted in May 2026 by me, fastfire. The pro-Russia hacktivist collective NoName057(16) (often referred to as NoName) emerged in March 2022 following the Russian invasion of Ukraine. The group primarily conducts disruptive Distributed Denial-of-Service (DDoS) campaigns against government and private sector entities in NATO member states
·deepdarkcti.com·
Interview #11 NoName057(16)
Il 78% delle aziende ha già subito o sospetta incidenti legati all’IA
Il 78% delle aziende ha già subito o sospetta incidenti legati all’IA
A leggere il nuovo “2026 Cloud Security Report” realizzato da Check Point insieme a Cybersecurity Insiders, sembra proprio che l’adozione dell’intelligenza artificiale nelle aziende stia crescendo più rapidamente della capacità delle organizzazioni di proteggerla. Il report, basato sulle risposte di 1.042 professionisti IT e cybersecurity provenienti da organizzazioni di tutto il mondo, mostra un quadro …
·securityinfo.it·
Il 78% delle aziende ha già subito o sospetta incidenti legati all’IA
New Gogs zero-day flaw lets hackers get remote code execution
New Gogs zero-day flaw lets hackers get remote code execution
An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.
·bleepingcomputer.com·
New Gogs zero-day flaw lets hackers get remote code execution
How SIEM helps MSPs reduce noise and stop threats faster
How SIEM helps MSPs reduce noise and stop threats faster
MSPs don't lack security data. They struggle to separate real threats from alert noise. Kaseya explains how SIEM helps MSPs improve visibility, reduce fatigue, and respond faster.
·bleepingcomputer.com·
How SIEM helps MSPs reduce noise and stop threats faster
NIS2, adottati i modelli comuni per la notifica di incidenti cyber: cosa cambia per le aziende
NIS2, adottati i modelli comuni per la notifica di incidenti cyber: cosa cambia per le aziende
Il Gruppo di Cooperazione NIS ha approvato template standardizzati per la segnalazione degli incidenti informatici. Un passo concreto verso la semplificazione degli obblighi NIS2, con importanti implicazioni pratiche per i soggetti essenziali e importanti che stanno completando il percorso di conformità
·cybersecurity360.it·
NIS2, adottati i modelli comuni per la notifica di incidenti cyber: cosa cambia per le aziende