Over Security

Over Security

34848 bookmarks
Custom sorting
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
·blog.talosintelligence.com·
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
·blog.talosintelligence.com·
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Critical Zimbra RCE flaw now actively exploited in attacks
Critical Zimbra RCE flaw now actively exploited in attacks
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS).
·bleepingcomputer.com·
Critical Zimbra RCE flaw now actively exploited in attacks
One Adversary: Fraud Is a Network, Not a Payment
One Adversary: Fraud Is a Network, Not a Payment
Payment was authorised. The transaction was, technically, legitimate. It was also part of a $187 million criminal network, and the payment was the worst place to fight it.
·group-ib.com·
One Adversary: Fraud Is a Network, Not a Payment
Zero Trust nei sistemi OT: dalla teoria all’applicazione, ecco le 5 aree di rischio prioritarie
Zero Trust nei sistemi OT: dalla teoria all’applicazione, ecco le 5 aree di rischio prioritarie
L'applicazione agli ambienti di Operational Technology non è affatto immediata. Partendo da un caso applicativo nel settore elettrico, ecco un approccio mission-focused all’adozione dello Zero Trust nell'ambito OT, nel contesto normativo europeo (NIS2) e tecnico
·cybersecurity360.it·
Zero Trust nei sistemi OT: dalla teoria all’applicazione, ecco le 5 aree di rischio prioritarie
Microsoft says August Windows updates may cause gaming issues
Microsoft says August Windows updates may cause gaming issues
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems.
·bleepingcomputer.com·
Microsoft says August Windows updates may cause gaming issues
BTMOB Exposed: Inside a Fraud-as-a-Service Platform with 1400+ live servers
BTMOB Exposed: Inside a Fraud-as-a-Service Platform with 1400+ live servers
The Trail In February 2023, cryptocurrency payment processor Freewallet froze roughly $75,000 in accumulated earnings from a customer in Syria. The company demanded KYC verification. That moment of financial friction cracked the operational security that a threat actor known as EVLF had maintained for approximately eight years, and gave
·blog.quimerax.com·
BTMOB Exposed: Inside a Fraud-as-a-Service Platform with 1400+ live servers
OpenAI confirms ChatGPT is down as logins and signups fail
OpenAI confirms ChatGPT is down as logins and signups fail
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations.
·bleepingcomputer.com·
OpenAI confirms ChatGPT is down as logins and signups fail
Rogue ransomware affiliate poses as recovery firm to steal payments
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.
·bleepingcomputer.com·
Rogue ransomware affiliate poses as recovery firm to steal payments
Sakura Internet hack exposes data of up to 1.36 million accounts
Sakura Internet hack exposes data of up to 1.36 million accounts
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored.
·bleepingcomputer.com·
Sakura Internet hack exposes data of up to 1.36 million accounts
Rogue ransomware affiliate poses as data recovery firm to steal payments
Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.
·bleepingcomputer.com·
Rogue ransomware affiliate poses as data recovery firm to steal payments
Researchers say OpenAI revoked their access to limited cyber program
Researchers say OpenAI revoked their access to limited cyber program
Multiple cybersecurity researchers said they suddenly lost access to OpenAI’s Trusted Access for Cyber (TAC) program, which offers models with fewer guardrails for vetted users.
·techcrunch.com·
Researchers say OpenAI revoked their access to limited cyber program
US charges Iranian hackers over $3.4 billion intellectual property theft
US charges Iranian hackers over $3.4 billion intellectual property theft
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations.
·bleepingcomputer.com·
US charges Iranian hackers over $3.4 billion intellectual property theft
Password spraying attacks surge 155x as hackers exploit MFA gaps
Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected.
·bleepingcomputer.com·
Password spraying attacks surge 155x as hackers exploit MFA gaps
Quanto è davvero hacker il nuovo GLM-5.3 open weight della Z.ai
Quanto è davvero hacker il nuovo GLM-5.3 open weight della Z.ai
L'azienda cinese ha rilasciato il nuovo modello dichiarando forti capacità nel coding e nella cyber security. Ma si è preso due settimane per renderlo eseguibile anche su infrastrutture di terzi. Proviamo a scoprire quali sono i suoi effettivi vantaggi ma anche i suoi rischi
·cybersecurity360.it·
Quanto è davvero hacker il nuovo GLM-5.3 open weight della Z.ai