Over Security

Over Security

31463 bookmarks
Custom sorting
NFCShare Android Trojan: NFC card data theft via malicious APK
NFCShare Android Trojan: NFC card data theft via malicious APK
An Android trojan distributed via a Deutsche Bank phishing campaign pretends to be “Support Nexi,” prompts victims to tap their payment card and enter the PIN, then exfiltrates NFC data over a WebSocket. We attribute this cluster as NFCShare and provide technical details and IOCs.
·d3lab.net·
NFCShare Android Trojan: NFC card data theft via malicious APK
ACN: nel secondo semestre del 2025 qualcosa ha finalmente iniziato a funzionare
ACN: nel secondo semestre del 2025 qualcosa ha finalmente iniziato a funzionare
Non siamo affatto più sicuri, ma un po’ meno disordinati nella capacità di rilevazione e triage. Ecco i dati di Acn del secondo semestre del 2025 da cui si evince che gli eventi aumentano, mentre diminuiscono gli incidenti con impatto confermato
·cybersecurity360.it·
ACN: nel secondo semestre del 2025 qualcosa ha finalmente iniziato a funzionare
Initial access hackers switch to Tsundere Bot for ransomware attacks
Initial access hackers switch to Tsundere Bot for ransomware attacks
A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks.
·bleepingcomputer.com·
Initial access hackers switch to Tsundere Bot for ransomware attacks
Cyberattack on Polish energy grid impacted around 30 facilities
Cyberattack on Polish energy grid impacted around 30 facilities
The coordinated attack on Poland's power grid in late December targeted multiple distributed energy resource (DER) sites across the country, including combined heat and power (CHP) facilities and wind and solar dispatch systems.
·bleepingcomputer.com·
Cyberattack on Polish energy grid impacted around 30 facilities
Who Operates the Badbox 2.0 Botnet?
Who Operates the Badbox 2.0 Botnet?
The cybercriminals in control of Kimwolf -- a disruptive botnet that has infected more than 2 million devices -- recently shared a screenshot indicating they'd compromised the control panel for Badbox 2.0, a vast China-based botnet powered by malicious software…
·krebsonsecurity.com·
Who Operates the Badbox 2.0 Botnet?
eScan confirms update server breached to push malicious update
eScan confirms update server breached to push malicious update
MicroWorld Technologies, the maker of the eScan antivirus product, has confirmed that one of its update servers was breached and used to distribute an unauthorized update later analyzed as malicious to a small subset of customers earlier this month.
·bleepingcomputer.com·
eScan confirms update server breached to push malicious update
Viral Moltbot AI assistant raises concerns over data security
Viral Moltbot AI assistant raises concerns over data security
Security researchers are warning of insecure deployments in enterprise environments of the Moltbot (formerly Clawdbot) AI assistant, which can lead to leaking API keys, OAuth tokens, conversation history, and credentials.
·bleepingcomputer.com·
Viral Moltbot AI assistant raises concerns over data security
New sandbox escape flaw exposes n8n instances to RCE attacks
New sandbox escape flaw exposes n8n instances to RCE attacks
Two vulnerabilities in the n8n workflow automation platform could allow attackers to fully compromise affected instances, access sensitive data, and execute arbitrary code on the underlying host.
·bleepingcomputer.com·
New sandbox escape flaw exposes n8n instances to RCE attacks
FBI seizes RAMP cybercrime forum used by ransomware gangs
FBI seizes RAMP cybercrime forum used by ransomware gangs
The FBI has seized the notorious RAMP cybercrime forum, a platform used to advertise a wide range of malware and hacking services, and one of the few remaining forums that openly allowed the promotion of ransomware operations.
·bleepingcomputer.com·
FBI seizes RAMP cybercrime forum used by ransomware gangs
Empire cybercrime market owner pleads guilty to drug conspiracy
Empire cybercrime market owner pleads guilty to drug conspiracy
​A Virginia man who co-created Empire Market, one of the largest dark web marketplaces at the time, pleaded guilty Monday to federal drug conspiracy charges for facilitating $430 million in illegal transactions from 2018 to 2020.
·bleepingcomputer.com·
Empire cybercrime market owner pleads guilty to drug conspiracy
AI Is Rewriting Compliance Controls and CISOs Must Take Notice
AI Is Rewriting Compliance Controls and CISOs Must Take Notice
AI agents are now executing regulated actions, reshaping how compliance controls actually work. Token Security explains why CISOs must rethink identity, access, and auditability as AI becomes a digital employee.
·bleepingcomputer.com·
AI Is Rewriting Compliance Controls and CISOs Must Take Notice
SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws
SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws
SolarWinds has released security updates to patch critical authentication bypass and remote command execution vulnerabilities in its Web Help Desk IT help desk software.
·bleepingcomputer.com·
SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws
Grok sotto indagine UE: dall’algoritmo al danno sistemico
Grok sotto indagine UE: dall’algoritmo al danno sistemico
Con l’apertura di un’indagine formale contro X, la Commissione UE intende verificare se l’integrazione di Grok, il sistema di AI generativa sviluppato dal gruppo di Elon Musk, abbia rispettato gli obblighi europei di valutazione e mitigazione dei rischi sistemici previsti dal DSA. Ecco i possibili impatti
·cybersecurity360.it·
Grok sotto indagine UE: dall’algoritmo al danno sistemico
Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation
Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation
A malicious campaign is actively targeting exposed LLM (Large Language Model) service endpoints to commercialize unauthorized access to AI infrastructure.
·bleepingcomputer.com·
Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation
Slovakian man pleads guilty to operating darknet marketplace
Slovakian man pleads guilty to operating darknet marketplace
A Slovakian national admitted on Tuesday to helping operate a darknet marketplace that sold narcotics, cybercrime tools and services, fake government IDs, and stolen personal information for more than two years.
·bleepingcomputer.com·
Slovakian man pleads guilty to operating darknet marketplace
New WhatsApp lockdown feature protects high-risk users from hackers
New WhatsApp lockdown feature protects high-risk users from hackers
Meta has started rolling out a new WhatsApp lockdown-style security feature designed to protect journalists, public figures, and other high-risk individuals from sophisticated threats, including spyware attacks.
·bleepingcomputer.com·
New WhatsApp lockdown feature protects high-risk users from hackers
Sicurezza degli agenti LLM: serve un framework unificato
Sicurezza degli agenti LLM: serve un framework unificato
A differenza dei chatbot statici, gli agenti LLM interagiscono con strumenti esterni, dati e servizi, creando nuovi modelli di minacce. Ecco come superare la frammentazione delle pratiche standard attraverso una visione d'insieme
·cybersecurity360.it·
Sicurezza degli agenti LLM: serve un framework unificato
Data protection day: nell’era dell’AI agentica serve una disciplina di resilienza
Data protection day: nell’era dell’AI agentica serve una disciplina di resilienza
Le identità compromesse sono spesso la strada principale per accedere ai dati sensibili. Resilienza significa rilevare precocemente gli accessi anomali, limitare il raggio d’azione dell’attacco e ripristinare con sicurezza quando i controlli di identità vengono aggirati. Ma nell'era dell'Agentic AI, il Data Protection Day 2026 non deve essere una giornata di esercizio retorico. Ecco perché
·cybersecurity360.it·
Data protection day: nell’era dell’AI agentica serve una disciplina di resilienza
Cyber security: sta tornando il grande rimescolamento
Cyber security: sta tornando il grande rimescolamento
La pandemia ci aveva regalato il fenomeno delle dimissioni di massa. Poi questa dinamica si è trasformata e adesso si assiste - soprattutto nella cyber security - alla ripresa in grande stile del great reshuffle: ovvero si cerca un nuovo impiego che dia equilibrio tra lavoro e vita privata. E il settore si interroga
·cybersecurity360.it·
Cyber security: sta tornando il grande rimescolamento
Perché le aziende faticano a integrare l’intelligenza artificiale
Perché le aziende faticano a integrare l’intelligenza artificiale
L’adozione dell’AI nel mondo business è inferiore alle aspettative, tra scetticismo sui risultati e incertezze sui costi. Più il tempo passa, più aumenta il rischio che questo stallo faccia esplodere la bolla.
·guerredirete.it·
Perché le aziende faticano a integrare l’intelligenza artificiale
OpenAI's ChatGPT ad costs are on par with live NFL broadcasts
OpenAI's ChatGPT ad costs are on par with live NFL broadcasts
OpenAI plans to begin rolling out ads on ChatGPT in the United States if you have a free or $8 Go subscription, but the catch is that the ads could be very expensive for advertisers.
·bleepingcomputer.com·
OpenAI's ChatGPT ad costs are on par with live NFL broadcasts
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices running vulnerable firmware versions.
·bleepingcomputer.com·
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready