Over Security
631 subscribers
29.6K photos
31K links
This is a (beta) cybersecurity news aggregator!

https://oversecurity.net
Download Telegram
Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Manual phishing and brand impersonation takedowns can't keep pace with attackers. See why consulting firms need managed, continuous takedown response.

🔗️ [Cyble] https://link.is.it/Vl3iAx
Microsoft confirms GitHub is down worldwide

GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services.

🔗️ [Bleepingcomputer] https://link.is.it/kyM00w
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.

🔗️ [Therecord] https://link.is.it/XL3k4k
Poland probes MyDr healthcare software breach potentially affecting 19 million people

MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.

🔗️ [Therecord] https://link.is.it/VKKWEv
Irregular faces criticism over ‘spin’ in AI hacking postmortem

The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.


🔗️ [Therecord] https://link.is.it/mmzyFp
Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.

🔗️ [Bleepingcomputer] https://link.is.it/zDiV68
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators

Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.

🔗️ [Techcrunch] https://link.is.it/uKcppq
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.

🔗️ [Therecord] https://link.is.it/Q4BJXj
Hacker claims 3.6 million Azure account records stolen from major companies

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.

🔗️ [Bleepingcomputer] https://link.is.it/xQWWRy
Gestione dei rischi NIS 2: il modello ibrido che collega servizi, informazioni, tecnologie e scenari di rischio

Ogni prospettiva descrive un livello di una catena d'attacco. Da sola, nessuna la descrive tutta. Ma il modello ibrido nasce dalla consapevolezza: non elimina i metodi esistenti, ma li collega. Ecco perché nella gestione dei rischi NIS 2, si fa largo il modello ibrido

🔗️ [Cybersecurity360] https://link.is.it/EpI5hm
AI Models Escaped Test Environments and Hit Real Targets

Recent AI security incidents involving model evaluations have raised questions about how securely frontier AI models are tested before deployment.

🔗️ [Thecyberexpress] https://link.is.it/CQZx6V
Microsoft starts removing WMIC tool used by cybercriminals

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.

🔗️ [Bleepingcomputer] https://link.is.it/NMzlf7
La complessità è nemica della cyber security: la lezione del principio KISS

Ogni funzione, dipendenza e riga di codice aggiuntiva può ampliare la superficie di attacco. Dal principio KISS a DRY e YAGNI, progettare sistemi più semplici non è minimalismo fine a sé stesso: significa ridurre vulnerabilità, costi e complessità operativa, trasformando la sicurezza in un vantaggio competitivo

🔗️ [Cybersecurity360] https://link.is.it/okmd4X
678,000 People Hit in French Tax Authority Data Breach

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging

🔗️ [Thecyberexpress] https://link.is.it/r1Stdy
La monetizzazione dei dati personali nell’era dei data broker: l’efficacia dei servizi automatizzati di cancellazione

Rimozione dati personali da 5,99 €: ecco come funziona l'offerta di Incogni per la sicurezza e la privacy online, i costi e i servizi inclusi

🔗️ [Cybersecurity360] https://link.is.it/VKZKbw
Falso “rimborso farmaci” sfruttato per un phishing a tema Fascicolo Sanitario Elettronico

Il CERT-AGID ha individuato una nuova campagna di pshihing che sfrutta grafiche e loghi istituzionali del Fascicolo Sanitario Elettronico (FSE), del Ministero della Salute, del Dipartimento per la trasformazione digitale e del Ministero dell'Economia e delle Finanze, con l'obiettivo di sottrarre dati personali e dettagli delle carte di pagamento delle vittime. La leva psicologica è la promessa di un presunto rimborso del 19% per l'acquisto di medicinali in farmacia (per un importo esatto di €20,73).

🔗️ [Cert-agid] https://link.is.it/xJ4Ew3
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Read about Mirage2FA, a new phishing threat to US enterprises with over 4K compromised companies to date. Collect IOCs for your SOC.

🔗️ [Any] https://link.is.it/DE67Gr
Microsoft confirms outage affecting search in Microsoft 365 apps

Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive.

🔗️ [Bleepingcomputer] https://link.is.it/1zL0pH
CISA: Windows Task Host flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.

🔗️ [Bleepingcomputer] https://link.is.it/yYA979
Behavioural AI: FAQ & Myths

This article explains how banks can increase their Value Detection Rate (VDR) using ThreatFabric's Behavioural SDK

🔗️ [Threatfabric] https://link.is.it/qGXVma
Ukrainian software developer faces 12 years in Swiss ransomware trial

The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation.

🔗️ [Therecord] https://link.is.it/E690d2