Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 120 / 214
4264 résultats taggé E*N  ✕
LastPass to enforce a 12-character requirement for master passwords https://www.scmagazine.com/news/lastpass-to-enforce-a-12-character-requirement-for-master-passwords?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
08/01/2024 11:01:45
QRCode
archive.org
thumbnail

Security pros say while the 12-character requirement by LastPass is a step in the right direction, teams still need to enforce multi-factor authentication and practice continuous monitoring.

scmagazine EN 2023 LastPass requirement password change
CVE-2023-27532 https://attackerkb.com/topics/ALUsuJioE5/cve-2023-27532/rapid7-analysis
08/01/2024 09:10:00
QRCode
archive.org
thumbnail

Veeam Backup & Replication is a data backup and replication solution. On March 7, 2023, Veeam published an advisory, along with patches, for https://nvd.nist.g…

AttackerKB EN 2023 Veeam CVE-2023-27532 analysis
ALPHV Ransomware Claims Cyberattack on US Firm Ultra Intelligence and Communications https://thecyberexpress.com/cyberattack-on-ultra-intelligence-and-communications/
07/01/2024 12:50:41
QRCode
archive.org
thumbnail

Russian-speaking BlackCat/ALPHV ransomware group has claimed to have carried out a cyberattack on Ultra Intelligence and Communications, a US-based company

thecyberexpress EN 2023 ALPHV US Ultra-Intelligence-&-Communications
Three New Malicious PyPI Packages Deploy CoinMiner on Linux Devices | FortiGuard Labs https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices
05/01/2024 18:44:07
QRCode
archive.org
thumbnail

FortiGuard Labs cover the attack phases of three new PyPI packages that bear a resemblance to the culturestreak PyPI package discovered earlier this year. Learn more.

fortinet EN 2023 FortiGuard-Labs-Threat-Research Supply-chain-attack PyPI Packages CoinMiner
Analyzing DPRK's SpectralBlur https://objective-see.org/blog/blog_0x78.html
05/01/2024 12:38:58
QRCode
archive.org
thumbnail

In both his twitter (err, X) thread and in a subsequent posting he provided a comprehensive background and triage of the malware dubbed SpectralBlur. In terms of its capabilities he noted:

SpectralBlur is a moderately capable backdoor, that can upload/download files, run a shell, update its configuration, delete files, hibernate or sleep, based on commands issued from the C2. -Greg
He also pointed out similarities to/overlaps with the DPRK malware known as KandyKorn (that we covered in our “Mac Malware of 2024” report), while also pointing out there was differences, leading him to conclude:

We can see some similarities ... to the KandyKorn. But these feel like families developed by different folks with the same sort of requirements. -Greg

objective-see EN 2024 Analysis macOS backdoor SpectralBlur malware
Ivanti warns critical EPM bug lets hackers hijack enrolled devices https://www.bleepingcomputer.com/news/security/ivanti-warns-critical-epm-bug-lets-hackers-hijack-enrolled-devices/
05/01/2024 08:53:04
QRCode
archive.org
thumbnail

Ivanti fixed a critical remote code execution (RCE) vulnerability in its Endpoint Management software (EPM) that can let unauthenticated attackers hijack enrolled devices or the core server.

bleepingcomputer EN 2024 Ivanti Ivanti-Endpoint-Manager Ivanti-EPM RCE Remote-Code-Execution CVE-2023-39336
Weak password and infostealer blamed for Orange Spain outage https://www.theregister.com/2024/01/04/orange_spain_outage_breach/
05/01/2024 08:36:11
QRCode
archive.org
thumbnail

No 2FA or special characters to prevent database takeover and BGP hijack

theregister EN 2023 Orange Spain Weak password RIPE
Exclusive: Russian hackers were inside Ukraine telecoms giant for months https://www.reuters.com/world/europe/russian-hackers-were-inside-ukraine-telecoms-giant-months-cyber-spy-chief-2024-01-04/
04/01/2024 13:28:02
QRCode
archive.org

Russian hackers were inside Ukrainian telecoms giant Kyivstar's system from at least May last year in a cyberattack that should serve as a "big warning" to the West, Ukraine's cyber spy chief told Reuters.

The hack, one of the most dramatic since Russia's full-scale invasion nearly two years ago, knocked out services provided by Ukraine's biggest telecoms operator for some 24 million users for days from Dec. 12.

reuters EN 2024 Kyivstar Russia-Ukraine-war Russia telecom
Hacker hijacks Orange Spain RIPE account to cause BGP havoc https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/
04/01/2024 10:06:52
QRCode
archive.org
thumbnail

Orange Spain suffered an internet outage today after a hacker breached the company's RIPE account to misconfigure BGP routing and an RPKI configuration.

bleepingcomputer EN 2024 BGP Border-Gateway-Protocol Information-stealing-malware IP-Address Resource-Public-Key-Infrastructure RIPE Routing-Table RPKI Spain
The State of Ransomware in the U.S.: Report and Statistics 2023 https://www.emsisoft.com/en/blog/44987/the-state-of-ransomware-in-the-u-s-report-and-statistics-2023/
03/01/2024 18:29:06
QRCode
archive.org
thumbnail

The U.S. was bombarded by financially-motivated ransomware attacks throughout 2023. This report looks at the numbers, the costs and the solution.

emsisoft EN 2024 Statistics 2023 US ransomware restrospective
Qualcomm chip vulnerability enables remote attack by voice call https://www.scmagazine.com/news/qualcomm-chip-vulnerability-enables-remote-attack-by-voice-call
03/01/2024 18:15:51
QRCode
archive.org
thumbnail

The critical bug that could lead to a remote attack via voice call is one of 26 vulnerabilities affecting hundreds of Qualcomm chipsets.

scmagazine EN 2024 critical bug Qualcomm voice-call chip vulnerability CVE-2023-33025
Cactus RANSOMWARE gang hit the Swedish retail and grocery provider Coop https://securityaffairs.com/156709/cyber-crime/cactus-ransomware-coop-sweden.html
03/01/2024 18:10:24
QRCode
archive.org
thumbnail

The Cactus ransomware group claims to have hacked Coop, one of the largest retail and grocery providers in Sweden.

securityaffairs EN 2023 Cactus ransomware Sweden coop grocery
The biggest cybersecurity and cyberattack stories of 2023 https://www.bleepingcomputer.com/news/security/the-biggest-cybersecurity-and-cyberattack-stories-of-2023/
03/01/2024 16:50:12
QRCode
archive.org
thumbnail

2023 was a big year for cybersecurity, with significant cyberattacks, data breaches, new threat groups emerging, and, of course, zero-day vulnerabilities.

bleepingcomputer EN 2023 Cyberattack Cybercrime Data-Breach Law-Enforcement Zero-Day retrospective
Porsche To Kill ICE-Powered Macan In Europe Over Cybersecurity Laws | Carscoops https://www.carscoops.com/2023/12/porsche-to-kill-ice-powered-macan-in-europe-over-cybersecurity-laws/
03/01/2024 14:10:02
QRCode
archive.org
thumbnail

Porsche's best-selling model will be discontinued from markets within the European Union in spring of 2024

carscoops EN 2023 Porche Cybersecurity regulation EU Macan Law
smith (CVE-2023-32434) https://github.com/felix-pb/kfd/blob/main/writeups/smith.md
03/01/2024 13:50:10
QRCode
archive.org

This write-up presents an exploit for a vulnerability in the XNU kernel:

  • Assigned CVE-2023-32434.

  • Fixed in iOS 16.5.1 and macOS 13.4.1.

  • Reachable from the WebContent sandbox and might have been actively exploited.
    *Note that this CVE fixed multiple integer overflows, so it is unclear whether or not the integer overflow used in my exploit was also used in-the-wild. Moreover, if it was, it might not have been exploited in the same way.
    The exploit has been successfully tested on:

  • iOS 16.3, 16.3.1, 16.4 and 16.5 (iPhone 14 Pro Max)

  • macOS 13.1 and 13.4 (MacBook Air M2 2022)

  • All code snippets shown below are from xnu-8792.81.2.

Poulin-Bélanger EN 2023 exploit analysis vulnerability github macos ios CVE-2023-32434
D-Link D-View 8 Unauthenticated Probe-Core Server Communication https://www.tenable.com/security/research/tra-2023-43
03/01/2024 12:31:36
QRCode
archive.org

A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of info

tenable EN 2023 D-Link D-View vulnerability disclosure
Downfall - A Slay the Spire Fan Expansion :: Downfall (Steam Standalone) was Breached. Please read. https://steamcommunity.com/games/1865780/announcements/detail/3865841912968681604
03/01/2024 12:26:57
QRCode
archive.org
thumbnail

UPDATE 12/29 - While there is no new alerts regarding the Steam product or risk of downloads, the Discord account remains compromised. I have reports that the account is trying to DM people and either send malware to them impersonating themselves as a developer, or trying to gain sensitive information. Do not engage with this account and absolutely do not click on any links sent.

steamcommunity EN 2023 Downfall game mod hacked breach
Serbia Stays Silent About Alleged Ransomware Attack on EPS https://balkaninsight.com/2023/12/29/serbia-stays-silent-about-alleged-ransomware-attack-on-eps/
03/01/2024 12:24:29
QRCode
archive.org

Authorities have declined to comment on the reported ransomware attack ten days on Serbia's public energy company EPS.

balkaninsight EN 2024 Serbia ransomware Critical-infrastructure energy EPS
Cyber attacks hit the Assembly of the Republic of Albania and telecom company One Albania https://securityaffairs.com/156644/security/cyber-attacks-hit-albania.html
03/01/2024 12:22:28
QRCode
archive.org
thumbnail

Cyber attacks hit the Assembly of the Republic of Albania and telecom company One Albania, a government agency reported.

securityaffairs EN 2024 Albania telecom cyberattacks
CVE-2023-46747 : Unauthenticated Remote Code Execution in F5 BIG-IP - Malware Analysis - Malware Analysis, News and Indicators https://malware.news/t/cve-2023-46747-unauthenticated-remote-code-execution-in-f5-big-ip/77207
03/01/2024 11:41:05
QRCode
archive.org
thumbnail

On 26th October, 2023 F5 released a security advisory about a critical unauthenticated remote code execution vulnerability, CVE-2023-46747, in F5’s BIG-IP configuration utility. This vulnerability could allow unauthent…

malware.news EN 2024 F5 analysis CVE-2023-46747
page 120 / 214
4848 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn