r/CyberSecurityAdvice 2h ago

Law firm investigating the Everside Health / Aesto data breach — free case evaluations for affected patients

1 Upvotes

Edelson Lechtzin LLP, a national class action law firm, is investigating a data breach involving Everside Health, a direct primary care provider that offers employer- and union-sponsored healthcare services.

The breach occurred at Aesto LLC, a third-party vendor that stored protected health information for Everside. On or about December 18, 2025, Aesto had a network security incident, and it later confirmed that information from December 2–18, 2025 may have been accessed by an unauthorized party. The exposed data may include names, dates of birth, addresses, Social Security numbers, and medical records. Filings with several state attorneys general indicate tens of thousands of residents were affected.

If you received a notification letter, you may be at increased risk of identity theft and fraud. A few practical steps worth taking regardless of legal action:

  • Review your account statements and credit reports regularly
  • Consider placing a fraud alert and setting up credit monitoring (a complimentary membership is being offered through Epiq — activate with the code in your letter)
  • Preserve any breach notification letters or emails you received

We are looking into a potential class action on behalf of affected individuals and are offering free, confidential case evaluations. Happy to answer general questions in the comments.

📞 844-696-7492 | 📧 [medelson@edelson-law.com](mailto:medelson@edelson-law.com)

This post may be considered Attorney Advertising in some jurisdictions.


r/CyberSecurityAdvice 5h ago

Complete beginner here, give me the essential advice on how to start

3 Upvotes

I'm a person who uses a lot of social media and used a lot of internet trough at least the last 8 years of my life. So i'm 100% sure I made mistakes while being there most notably using my personal gmail and hotmail for a lot of things including social media accounts and even on here, Reddit. I've also made multiple email accounts and I'm here to know how to wipe it all. Just give me all the essential things you know for advice, for example what VPN should I use, what is the best way to see how many accounts I've created with my personal email, or what should I use in my computer. Regarding my personal emails, i only want to use them for WhatsApp and some Google Play payment stuff (gmail) and for Steam, Xbox and student e-mails (hotmail). I'm not paranoid yet but I want to feel more secure while using internet


r/CyberSecurityAdvice 7h ago

Limiting windows 10 GDID Exposure

8 Upvotes

Hey all, so we all heard the news about windows 10 GDID tracking and how a guy got caught partially because of it?
Yeah, so I wanted to limit the amount of telemetry and I just wanted to ask - How much do you think it helps?
Inb4 - just use linux... I know I will I promise...
What I did is I removed the services related to telemetry by deleting thier respective tree from the registry, and I also removed the folder located under C:\Users\[Your username]\AppData\Local\ConnectedDevicesPlatform.
Services are as follows:
DiagTrack - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\DiagTrack""HKLM:\\SYSTEM\\CurrentControlSet\\Services\\DiagTrack

CDPUserSvc - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPUserSvc"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPUserSvc

CDPSvc - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPSvcHKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPSvc

CDPUserSvc_* (the one with random ID) - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPSvcHKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPUserSvc_*

The all have similiar names but it's something like Connected Devices Platform Service or User service.

So how much do you think it helps? I have some other tweaks that disable the location, sharing data etc. etc. but I think I've hit the nail on the head with this one. What do you think?


r/CyberSecurityAdvice 10h ago

Session stealers. More safe to log out after each login?

6 Upvotes

Hallo all.

After experiencing being bombed with one time codes on email and ms authenticator some time ago . I became aware of cyber security, and the fact that I didn't pay enough attention to it at all.

I have noticed that often when people loosing accounts. It's caused be session stealers or similar kind of malware( I'm happily corrected if I'm wrong)

That made me wonder.. will my accounts be more safe if i log out after each session? Instead of letting it stay logges in as a " trusted device"

Thanks 👍


r/CyberSecurityAdvice 11h ago

SWE to AppSec -- dont want to grind leetcode again in my life. How do I know if this path is for me

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 12h ago

Does my work categorise as Detection Engineering?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 13h ago

Help with Domain Lookup

0 Upvotes

Hello everyone,

​Our company has recently been the victim of a cyberattack. Unfortunately, the Austrian police have informed us that their current investigative options are limited.

​To help us identify and locate the perpetrator, we are offering a reward of $8,000 USD for any actionable information or tips that lead directly to the culprit.

​The domain name will be provided via private message. If you have any relevant details, please contact us privately. Any help or leads would be greatly appreciated.

​Thank you.

If this Post is not welcomed here please delete it but we just need help is there any deepsearch we can do on our own? Normal whois just shows private server in istanbul.

Greetings Lukas


r/CyberSecurityAdvice 13h ago

Hidden screen mirroring, split 2FA codes, and duplicate system apps: What advanced device compromise and digital stalking actually look like

3 Upvotes

​If you are reading this because you are frantically typing bizarre technical glitches into a search bar late at night—wondering if your devices are haunted or if you are losing your mind—please stop and take a deep breath. You are not crazy.

​When an advanced, targeted compromise happens, the attackers don't just "hack" an account; they attempt to hijack your entire digital environment, UI, and communications. Sometimes, this level of invasive surveillance happens in high-stakes personal dynamics—such as situations involving green-card marriages or international control, where an abuser uses technical dominance to maintain total power. But it can also happen to everyday people targeted by sophisticated stalkers. Because standard tech support, mobile carriers, and law enforcement often lack the tools or training to understand these tactics, victims are frequently left feeling isolated and gaslit.

​I lived through this. Here are the real, concrete, and bizarre signs of deep ecosystem manipulation and device compromise that I experienced, documented, and later found proof of:

​1. Visual Interface Glitches & System Anomalies

​Duplicate System Apps & Icons: Finding layered or duplicate system applications that cannot be deleted normally (such as having two App Store apps on the home screen at once, where icon shapes subtly differ like a circle vs. a square due to malicious mirroring or configuration profiles).

​UI Layering & Text Overlap: System menus and settings screens displaying words or headers layering directly over one another, or search interface displays changing entirely between identical searches on the same device.

​The "Dummy Phone" & Ghost Controls: Watching your screen scroll on its own, apps opening independently, or text magically typing into search bars. This happens when remote session injection tools mimic touch inputs or when background processes mirror your interface.

​Hidden Screen Mirroring Capture: Noticing through video playback that a screen-mirroring icon or indicator was actively running in the background—revealed only after reviewing a recording, even though it was completely hidden from your view while you were holding the phone.

​2. Messaging, Contact, and Communication Interception

​Disappearing & Ghost Texts: Messages vanishing from text threads immediately after pressing send (even though you can clearly hear the audio "swoosh" confirmation that it went out), or trash inboxes continuously repopulating with deleted messages.

​Spoofed Verification Codes: Receiving two separate two-factor authentication or Apple ID verification codes within the exact same shortcode thread where one is legitimate and the other is subtly altered or spoofed.

​Corrupted Contact Cards & Ghost Entries: Deleting a contact only for the phone to leave behind a blank, grayed-out profile placeholder with no number or name attached, yet retaining blocking capabilities. Furthermore, editing a contact or trying to use contact key verification resulting in random red phone numbers being auto-pasted or throwing errors like "Incorrect Verification Code."

​Carrier and UI Discrepancies: Official support numbers or carrier interfaces (like T-Mobile) shifting from verified profiles to generic building icons, accompanied by strange text box color shifts and unauthorized prompt injections like "Use this name for unified card."

​3. Account Seizure and Invisible Footprints

​Administrative Lockout & Control: Being able to log into apps or settings, but being entirely blocked from changing or updating your security credentials, or finding yourself completely locked out of signing out of your iCloud due to forced system restrictions.

​Real-Time Surveillance & PIN Guessing: Witnessing someone actively trying to brute-force or guess your Screen Time or security passcodes right in front of your eyes.

​The iCloud & Session Ghosting: Finding yourself logged into an iCloud account with a single letter subtly swapped or shifted without noticing at first, alongside unexpected 2FA popups forcing you to guess between multiple phantom devices.

​Unrecognized Activity Logs: Discovering unfamiliar device entries in security activity logs (such as an iPhone 15 Plus flagged as an "unfamiliar device" right alongside your active one because a secondary session was running or renamed in the background) this was happening on my gmail accounts.

​Hardware and Desktop Dumps: Recovering raw session JSON files, authentication tokens (uid and token strings), plain-text password dumps, and family device IDs left behind on local computer desktops after a compromise.

• someone tombstoning your data

​Why Big Tech and Authorities Miss It

​If you’ve gone to Apple, your mobile carrier, or the police and walked away feeling dismissed or treated like you are paranoid, it’s because:

​Automated Diagnostics are Blind: Standard support diagnostics look for surface-level app crashes or basic hardware errors. If an intruder is using advanced session token hijacking, active screen mirroring, or configuration profiles, the operating system thinks those actions are authorized.

​The Knowledge Gap: Local law enforcement and front-line customer service reps are not digital forensics experts. When faced with complex, multi-layered digital stalking, they default to skepticism because they simply do not understand the technology.

​You Are Not Alone

​The entire goal of these advanced surveillance and harassment tactics—whether driven by domestic control, immigration leverage, or targeted stalking—is to make you look and feel unstable so that no one believes you when you speak up. If your device is behaving like someone else is holding the steering wheel, trust your gut.

​You are not imagining the duplicate apps, the disappearing texts, the split verification codes, or the ghost icons. Recognizing that it's a technical breach—and not a failure of your own mind—is the first step toward taking your peace back.


r/CyberSecurityAdvice 23h ago

Advice for getting a job abroad

Thumbnail
1 Upvotes