Over Security

Over Security

34849 bookmarks
Custom sorting
iRhythm discloses data breach, says hackers stole patient info
iRhythm discloses data breach, says hackers stole patient info
Digital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients' personal and health information stored on third-party-hosted business applications.
·bleepingcomputer.com·
iRhythm discloses data breach, says hackers stole patient info
| dfir.ch
| dfir.ch
Technical blog by Stephan Berger (@malmoeb)
·dfir.ch·
| dfir.ch
DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
The U.S. Department of Justice announced Friday that it has seized the CFAKE.com and SOCFAKE.com websites, which allegedly hosted nonconsensual AI-generated nude images and videos of women, in what appears to be the first publicly announced domain seizure under the TAKE IT DOWN Act.
·bleepingcomputer.com·
DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
SimpleHelp bug lets hackers create rogue remote support accounts
SimpleHelp bug lets hackers create rogue remote support accounts
A vulnerability in the SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on servers using the OpenID Connect (OIDC) authentication protocol.
·bleepingcomputer.com·
SimpleHelp bug lets hackers create rogue remote support accounts
June 2026 Stealer Logs - 56,278,397 breached accounts
June 2026 Stealer Logs - 56,278,397 breached accounts
In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard. Organisations can see logs affecting their domain via the stealer logs API.
·haveibeenpwned.com·
June 2026 Stealer Logs - 56,278,397 breached accounts
OptinMonster WordPress plugin hacked in CDN supply-chain attack
OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN).
·bleepingcomputer.com·
OptinMonster WordPress plugin hacked in CDN supply-chain attack
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges.
·bleepingcomputer.com·
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
Council of Europe investigates ShinyHunters data breach claims
Council of Europe investigates ShinyHunters data breach claims
The Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend.
·bleepingcomputer.com·
Council of Europe investigates ShinyHunters data breach claims
Contratto SLA e sicurezza: come strutturare le penali nelle forniture tecnologiche
Contratto SLA e sicurezza: come strutturare le penali nelle forniture tecnologiche
Il contratto SLA è il presidio legale della sicurezza nelle forniture IT. Strutturare correttamente KPI, penali e clausole di sicurezza non è solo una questione tecnica: è la traduzione in diritto degli obblighi normativi imposti da NIS2, DORA e GDPR. Questa guida illustra come farlo in modo efficace
·cybersecurity360.it·
Contratto SLA e sicurezza: come strutturare le penali nelle forniture tecnologiche
Cybersecurity vets protest ‘dangerous’ US government ban on Anthropic’s most powerful models
Cybersecurity vets protest ‘dangerous’ US government ban on Anthropic’s most powerful models
A group made up of dozens of cybersecurity experts urged the White House to remove export control restrictions on Anthropic’s models Fable and Mythos, arguing that the order is going to limit the ability of cybersecurity defenders to secure their software and products.
·techcrunch.com·
Cybersecurity vets protest ‘dangerous’ US government ban on Anthropic’s most powerful models
FBI: Fraudsters use couriers to steal money in crypto scams
FBI: Fraudsters use couriers to steal money in crypto scams
The U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims of cryptocurrency investment scams, also known as pig butchering or romance baiting.
·bleepingcomputer.com·
FBI: Fraudsters use couriers to steal money in crypto scams
Pink Extortion infetta le imprese con una telefonata: come difendersi dal finto ransomware
Pink Extortion infetta le imprese con una telefonata: come difendersi dal finto ransomware
Il malware si mimetizza da personale IT interno, per indurre le vittime a immettere le password su pagine fasulle, in modo da accedere velocemente a SharePoint, OneDrive e altri sistemi aziendali della galassia Microsoft 365. Ecco come mitigare il rischio di Pink Extortion
·cybersecurity360.it·
Pink Extortion infetta le imprese con una telefonata: come difendersi dal finto ransomware
GreatXML e BitLocker: cosa sappiamo davvero sul presunto zero-day che aggira la cifratura di Windows
GreatXML e BitLocker: cosa sappiamo davvero sul presunto zero-day che aggira la cifratura di Windows
GreatXML è stato presentato come un exploit zero-day capace di aggirare BitLocker sfruttando WinRE e Microsoft Defender Offline Scan. Le verifiche indipendenti, però, raccontano una storia meno lineare. Tra dubbi sul PoC e assenza di una CVE, il caso riapre il dibattito sulla sicurezza del recovery path di Windows
·cybersecurity360.it·
GreatXML e BitLocker: cosa sappiamo davvero sul presunto zero-day che aggira la cifratura di Windows
Chinese hackers breach REDCap servers, steal medical research
Chinese hackers breach REDCap servers, steal medical research
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America.
·bleepingcomputer.com·
Chinese hackers breach REDCap servers, steal medical research