Over Security
631 subscribers
29.6K photos
31K links
This is a (beta) cybersecurity news aggregator!

https://oversecurity.net
Download Telegram
Comcast turns your Xfinity WiFi into a home motion detector

Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors.

🔗️ [Bleepingcomputer] https://link.is.it/XXH7Bo
Fanlore - 144,520 breached accounts

In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.

🔗️ [Haveibeenpwned] https://link.is.it/vMtXHR
Oz Hair and Beauty - 1,988,331 breached accounts

In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.

🔗️ [Haveibeenpwned] https://link.is.it/eUueY3
Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender

A suspected ARMA cyberattack has targeted Ukraine's Asset Recovery and Management Agency as it prepares to select a manager for

🔗️ [Thecyberexpress] https://link.is.it/wHhAoi
Il problema non è il fattore umano. Perché il modello cyber va ripensato

Il nodo della cyber security non è la persona che sbaglia, ma un modello di sicurezza non allineato ai flussi di lavoro reali. Quando i processi sono complessi e poco usabili, la sicurezza viene aggirata invece di essere adottata. Ma anche la formazione deve cambiare

🔗️ [Cybersecurity360] https://link.is.it/UTdKrP
What Is PreCrime?

Learn what PreCrime is, how predictive cybersecurity works, and how organizations identify cyber threats before attacks begin.

🔗️ [Bfore] https://link.is.it/5E7EBs
UK Cybercrime Journal: Carding Tactics & Youth Money Muling

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

🔗️ [Bushidotoken] https://link.is.it/VXacRv
CISA: Medusa ransomware hit over 500 critical infrastructure orgs

The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.

🔗️ [Bleepingcomputer] https://link.is.it/RjVuhR
Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking

Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities.

🔗️ [Group-ib] https://link.is.it/0RcDZX
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers to remotely

🔗️ [Thecyberexpress] https://link.is.it/otTWyh
Windows 11 24H2 Home and Pro reach end of support in 2 months

Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months.

🔗️ [Bleepingcomputer] https://link.is.it/6gaxyQ
Quando la prassi sostituisce la procedura: la lezione per le imprese

Una recente sentenza del Tribunale di Udine mostra che l’ente produce policy e linee guida, ma l'operatività quotidiana si sviluppa attraverso relazioni organizzative differenti, costruite su rapidità decisionale, consuetudini operative e tolleranze manageriali. Ecco perché la sentenza assume rilievo per privacy, cyber security e governance

🔗️ [Cybersecurity360] https://link.is.it/MorCzM
UT San Antonio Shuts Systems, Delays Classes After Cyber Incident

UT San Antonio cyber incident response efforts have prompted the university to delay the start of fall classes by three

🔗️ [Thecyberexpress] https://link.is.it/tlPujD
Critical RCE flaw in Windows IKE Extension now actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component.

🔗️ [Bleepingcomputer] https://link.is.it/NI6ZDT
Describing attacks with crime script analysis

Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.

🔗️ [Talosintelligence] https://link.is.it/6BB9gh
La protezione dell’identità digitale e delle credenziali: il ruolo dei password manager crittografati contro le violazioni dati

Proton Pass offre un servizio di gestione delle password con crittografia end-to-end a 2,49 € al mese: ecco come funziona e come si attiva.

🔗️ [Cybersecurity360] https://link.is.it/hPLtGS
La protezione della rete domestica multipiattaforma: l’impatto dei servizi VPN a dispositivi illimitati sulla cybersecurity

Surfshark offre la VPN per dispositivi illimitati a 2,49 €, aggiungendo anche 3 mesi extra gratis: ecco come funziona l'offerta e come averla

🔗️ [Cybersecurity360] https://link.is.it/jj103U
Microsoft fixes known issue causing Windows Defender crashes

Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems.

🔗️ [Bleepingcomputer] https://link.is.it/MSqjta
Hunt Malware & Phishing Threats with ANY.RUN for Proactive Enterprise Security

Learn how ANY.RUN helps SOC teams hunt malware and phishing threats to strengthen enterprise security.

🔗️ [Any] https://link.is.it/PALKwP
Quanto è davvero hacker il nuovo GLM-5.3 open weight della Z.ai

L'azienda cinese ha reso pubblico il nuovo modello dichiarando forti capacità nel coding e nella cyber security. Ma si è preso due settimane per renderne disponibile il download dei pesi. Proviamo a scoprire quali sono i vantaggi ma anche i rischi di questo tipo di rilascio

🔗️ [Cybersecurity360] https://link.is.it/9Ezpjs
US charges Iranians for sprawling hacking campaign on government agencies, universities

The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.

🔗️ [Therecord] https://link.is.it/PsfwsM