Over Security

Over Security

31463 bookmarks
Custom sorting
Ingram Micro says ransomware attack affected 42,000 people
Ingram Micro says ransomware attack affected 42,000 people
​Information technology giant Ingram Micro has revealed that a ransomware attack on its systems in July 2025 led to a data breach affecting over 42,000 individuals.
·bleepingcomputer.com·
Ingram Micro says ransomware attack affected 42,000 people
Il caso OVHcloud e l’illusione della sovranità dei dati
Il caso OVHcloud e l’illusione della sovranità dei dati
Il caso OVHcloud mostra come la geografia normativa non coincida più con la geografia fisica dei server: un banco di prova della maturità del diritto internazionale e del diritto dell’UE nel governare la dimensione extraterritoriale del potere di accesso ai dati
·cybersecurity360.it·
Il caso OVHcloud e l’illusione della sovranità dei dati
New OpenAI leak hints at upcoming ChatGPT features
New OpenAI leak hints at upcoming ChatGPT features
OpenAI is internally testing a new update for ChatGPT, at least on the web. It'll begin rolling out in the coming weeks.
·bleepingcomputer.com·
New OpenAI leak hints at upcoming ChatGPT features
Pass'Sport - 6,366,133 breached accounts
Pass'Sport - 6,366,133 breached accounts
In December 2025, data from France's Pass'Sport program was posted to a popular hacking forum. Initially misattributed to CAF (the French family allowance fund), the data contained 6.5M unique email addresses affecting 3.5M households. The data also included names, phone numbers, genders and physical addresses. The Ministry of Sports subsequently released a statement acknowledging the incident.
·haveibeenpwned.com·
Pass'Sport - 6,366,133 breached accounts
Google Chrome tests Gemini-powered AI "Skills"
Google Chrome tests Gemini-powered AI "Skills"
Google is testing "Skills" for Gemini in Chrome, which will allow AI in Chrome to perform tasks automatically, and it could challenge Perplexity Comet or Edge's Copilot mode.
·bleepingcomputer.com·
Google Chrome tests Gemini-powered AI "Skills"
Microsoft releases OOB Windows updates to fix shutdown, Cloud PC bugs
Microsoft releases OOB Windows updates to fix shutdown, Cloud PC bugs
Microsoft has released multiple emergency, out-of-band updates for Windows 10, Windows 11, and Windows Server to fix two issues caused by the January Patch Tuesday updates.
·bleepingcomputer.com·
Microsoft releases OOB Windows updates to fix shutdown, Cloud PC bugs
Pagination with Cisco ACI
Pagination with Cisco ACI
When dealing with a large number of records, pagination becomes necessary. By default, Cisco ACI pagination allows you to retrieve up to 500 objects. A maximum value is not explicitly documented ; however, it is not recommended to go beyond this limit in order to avoid overloading the APIC.
·adainese.it·
Pagination with Cisco ACI
Malicious GhostPoster browser extensions found with 840,000 installs
Malicious GhostPoster browser extensions found with 840,000 installs
Another set of 17 malicious extensions linked to the GhostPoster campaign has been discovered in Chrome, Firefox, and Edge stores, where they accumulated a total of 840,000 installations.
·bleepingcomputer.com·
Malicious GhostPoster browser extensions found with 840,000 installs
Credential-stealing Chrome extensions target enterprise HR platforms
Credential-stealing Chrome extensions target enterprise HR platforms
Malicious Chrome extensions on the Chrome Web Store masquerading as productivity and security tools for enterprise HR and ERP platforms were discovered stealing authentication credentials or blocking management pages used to respond to security incidents.
·bleepingcomputer.com·
Credential-stealing Chrome extensions target enterprise HR platforms
Introducing System Call Integrity Layer
Introducing System Call Integrity Layer
A thought experiment proposing a System Call Integrity Layer (SCIL) for Windows that lets user-mode EDRs mediate selected syscalls via Alt Syscalls, reducing reliance on ntdll hooking and improving visibility into evasive malware.
·fluxsec.red·
Introducing System Call Integrity Layer
OpenAI says its new ChatGPT ads won't influence answers
OpenAI says its new ChatGPT ads won't influence answers
OpenAI has confirmed ChatGPT is getting ads in the coming weeks, but it promises that ads won't influence answers generated by ChatGPT.
·bleepingcomputer.com·
OpenAI says its new ChatGPT ads won't influence answers
Supreme Court hacker posted stolen government data on Instagram
Supreme Court hacker posted stolen government data on Instagram
Nicholas Moore pleaded guilty to stealing victims’ information from the Supreme Court and other federal government agencies, and then posting it on his Instagram @ihackthegovernment.
·techcrunch.com·
Supreme Court hacker posted stolen government data on Instagram
StealC hackers hacked as researchers hijack malware control panels
StealC hackers hacked as researchers hijack malware control panels
A cross-site scripting (XSS) flaw in the web-based control panel used by operators of the StealC info-stealing malware allowed researchers to observe active sessions and gather intelligence on the attackers' hardware.
·bleepingcomputer.com·
StealC hackers hacked as researchers hijack malware control panels
Black Basta boss makes it onto Interpol's 'Red Notice' list
Black Basta boss makes it onto Interpol's 'Red Notice' list
The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol.
·bleepingcomputer.com·
Black Basta boss makes it onto Interpol's 'Red Notice' list
China-linked hackers exploited Sitecore zero-day for initial access
China-linked hackers exploited Sitecore zero-day for initial access
An advanced threat actor tracked as UAT-8837 and believed to be linked to China has been focusing on critical infrastructure systems in North America, gaining access by exploiting both known and zero-day vulnerabilities.
·bleepingcomputer.com·
China-linked hackers exploited Sitecore zero-day for initial access
Crittografia post quantum nel settore finanziario: centrale la sicurezza della supply chain
Crittografia post quantum nel settore finanziario: centrale la sicurezza della supply chain
La rotta del G7 Cyber non prevede nuovi obblighi regolatori, ma offre un quadro di riferimento condiviso: una roadmap per autorità, istituzioni finanziarie e fornitori tecnologici, declinata in sei fasi principali della transizione alla crittografia post quantum in cui al centro c'è la sicurezza della supply chain
·cybersecurity360.it·
Crittografia post quantum nel settore finanziario: centrale la sicurezza della supply chain
Magecart e web skimming, così evolvono le truffe sugli e-commerce: come difendersi
Magecart e web skimming, così evolvono le truffe sugli e-commerce: come difendersi
È stata identificata una nuova campagna di web skimming basata su Magecart che non colpisce il server in modo tradizionale ma punta direttamente al browser dell’utente durante la fase di pagamento, intercettando i dati nel momento esatto in cui vengono inseriti. Ecco tutti i dettagli e come mitigare i rischi
·cybersecurity360.it·
Magecart e web skimming, così evolvono le truffe sugli e-commerce: come difendersi
Verizon starts issuing $20 credits after nationwide outage
Verizon starts issuing $20 credits after nationwide outage
Verizon has begun sending text messages with instructions on how to redeem a $20 account credit for last week's nationwide wireless outage.
·bleepingcomputer.com·
Verizon starts issuing $20 credits after nationwide outage