Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 128 / 237
SEC Has Not Approved Bitcoin ETFs, but Its Hacked X Account Briefly Said Otherwise https://www.coindesk.com/policy/2024/01/09/sec-twitter-compromised-chair-gensler-says-after-account-said-bitcoin-etfs-approved/
10/01/2024 08:30:47
QRCode
archive.org
thumbnail

The X account of the U.S. Securities and Exchange Commission, which is deciding whether to approve bitcoin ETFs, "was compromised," the regulator told CoinDesk.

coindesk EN 2024 SEC x Twitter account compromised hacked bitcoin
AI aides nation-state hackers but also helps US spies to find them, says NSA cyber director | TechCrunch https://techcrunch.com/2024/01/09/ai-china-nation-state-hackers-nsa-cyber-director/
09/01/2024 19:53:00
QRCode
archive.org
thumbnail

"AI, machine learning [and] deep learning is absolutely making us better at finding malicious activity," said NSA's Rob Joyce.

Avast Updates Babuk Ransomware Decryptor in Cooperation with Cisco Talos and Dutch Police https://decoded.avast.io/threatresearch/avast-updates-babuk-ransomware-decryptor-in-cooperation-with-cisco-talos-and-dutch-police/
09/01/2024 13:36:22
QRCode
archive.org
thumbnail

Avast is releasing an updated version of the Avast Babuk decryption tool, capable of restoring files encrypted by the Babuk variant called Tortilla.

avast EN 2024 Babuk decryption tool Tortilla
Netgear, Hyundai latest X accounts hacked to push crypto drainers https://www.bleepingcomputer.com/news/security/netgear-hyundai-latest-x-accounts-hacked-to-push-crypto-drainers/
09/01/2024 13:34:14
QRCode
archive.org
thumbnail

The official Netgear and Hyundai MEA Twitter/X accounts (together with over 160,000 followers) are the latest hijacked to push scams designed to infect potential victims with cryptocurrency wallet drainer malware.

bleepingcomputer EN 2024 X CryptoCurrency Drainer Hyundai Netgear Scam Twitter Wallet-Drainer
Meet Ika & Sal: The Bulletproof Hosting Duo from Hell https://krebsonsecurity.com/2024/01/meet-ika-sal-the-bulletproof-hosting-duo-from-hell/
09/01/2024 09:32:30
QRCode
archive.org

In 2020, the United States brought charges against four men accused of building a bulletproof hosting empire that once dominated the Russian cybercrime industry and supported multiple organized cybercrime groups. All four pleaded guilty to conspiracy and racketeering charges. But…

krebsonsecurity EN 2024 Bulletproof Spamdot hosting Ika Sal crime
Ransomware gang takes credit for Christmas attack on global Lutheran organization https://therecord.media/world-council-churches-lutheran-world-federation-cyberattacks
09/01/2024 09:17:05
QRCode
archive.org
thumbnail

The World Council of Churches reported an incident in December, and the Lutheran World Federation said it experienced a related incident. The Rhysida gang claimed it carried out the attack on the federation.

therecord EN 2023 WCC Lutheran Rhysida ransomware
WCC hit by ransomware attack https://oikoumene.org/news/wcc-hit-by-ransomware-attack
09/01/2024 09:16:22
QRCode
archive.org
thumbnail

The World Council of Churches (WCC) communications systems have been hacked by a ransomware group.

oikoumene EN 2023 WCC ransomware statement Rhysida
Revealed: How a secret Dutch mole aided the U.S.-Israeli Stuxnet cyberattack on Iran https://news.yahoo.com/revealed-how-a-secret-dutch-mole-aided-the-us-israeli-stuxnet-cyber-attack-on-iran-160026018.html?guccounter=1
08/01/2024 20:18:42
QRCode
archive.org
thumbnail

For years, an enduring mystery has surrounded the Stuxnet virus attack that targeted Iran’s nuclear program: How did the U.S. and Israel get their malware onto computer systems at the highly secured uranium-enrichment plant?

yahoo EN 2019 Iran Stuxnet-virus sanctions-against-Iran nuclear-program Iran’s-nuclear-program Iran Natanz Natanz centrifuges centrifuges intelligence Iran-nuclear-deal AIVD Stuxnet
Compromising Google Accounts: Malwares Exploiting Undocumented OAuth2 Functionality for session hijacking https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking
08/01/2024 16:19:25
QRCode
archive.org
thumbnail

A detailed blog on Analysis of the Global Malware Trend: Exploiting Undocumented OAuth2 Functionality to Regenerate Google Service Cookies Regardless of IP or Password Reset.

cloudsek EN 2023 OAuth2 cookie Google Accounts compromise Undocumented Functionality
Dutch man sabotaged Iranian nuclear program without Dutch government's knowledge: report https://nltimes.nl/2024/01/08/dutch-man-sabotaged-iranian-nuclear-program-without-dutch-governments-knowledge-report
08/01/2024 12:04:25
QRCode
archive.org
thumbnail

In 2008, a Dutchman played a crucial role in the United States and Israeli-led operation to sabotage Iran’s nuclear program. The then 36-year-old Erik van Sabben infiltrated an Iranian nuclear complex and released the infamous Stuxnet virus, paralyzing the country’s nuclear program. The AIVD recruited the man, but Dutch politicians knew nothing about the operation, the Volkskrant reports after investigating the sabotage for two years.

nltimes EN 2024 Stuxnet Dutchman 2008 nuclear
Multiple vulnerabilities in Lantronix EDS-MD IoT gateway for medical devices https://www.pentagrid.ch/en/blog/multiple-vulnerabilties-in-lantronix-eds-md-iot-gateway/
08/01/2024 11:41:32
QRCode
archive.org
thumbnail

The Lantronix EDS-MS is an "IoT gateway for mission critical medical devices and equipment connectivity". It is affected by multiple vulnerabilities.

pentagrid EN 2024 Lantronix EDS-MS IoT ritical medical devices helath Vulnerabilities
LastPass to enforce a 12-character requirement for master passwords https://www.scmagazine.com/news/lastpass-to-enforce-a-12-character-requirement-for-master-passwords?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
08/01/2024 11:01:45
QRCode
archive.org
thumbnail

Security pros say while the 12-character requirement by LastPass is a step in the right direction, teams still need to enforce multi-factor authentication and practice continuous monitoring.

scmagazine EN 2023 LastPass requirement password change
CVE-2023-27532 https://attackerkb.com/topics/ALUsuJioE5/cve-2023-27532/rapid7-analysis
08/01/2024 09:10:00
QRCode
archive.org
thumbnail

Veeam Backup & Replication is a data backup and replication solution. On March 7, 2023, Veeam published an advisory, along with patches, for https://nvd.nist.g…

AttackerKB EN 2023 Veeam CVE-2023-27532 analysis
ALPHV Ransomware Claims Cyberattack on US Firm Ultra Intelligence and Communications https://thecyberexpress.com/cyberattack-on-ultra-intelligence-and-communications/
07/01/2024 12:50:41
QRCode
archive.org
thumbnail

Russian-speaking BlackCat/ALPHV ransomware group has claimed to have carried out a cyberattack on Ultra Intelligence and Communications, a US-based company

thecyberexpress EN 2023 ALPHV US Ultra-Intelligence-&-Communications
L’UDC Andreas Glarner contraint de payer les frais de justice occasionnés par son «deepfake» de Sibel Arslan https://www.letemps.ch/suisse/l-udc-andreas-glarner-contraint-de-payer-les-frais-de-justice-occasionnes-par-son-deepfake-de-sibel-arslan
05/01/2024 19:28:36
QRCode
archive.org
thumbnail

Avant les élections fédérales, le conseiller national argovien avait publié sur les réseaux sociaux une vidéo générée par intelligence artificielle qui montrait l’élue verte appelant à voter pour lui. Saisie par l’écologiste bâloise, la justice donne raison à cette dernière

letemps FR CH Suisse Justice deepfake
Du nouveau dans la (l'in) sécurité de l'Internet ? https://www.bortzmeyer.org/orange-espagne-bgp.html
05/01/2024 18:47:03
QRCode
archive.org

Le 3 janvier 2024, une partie du trafic IP à destination de la filiale espagnole d'Orange n'a pas été transmis, en raison d'un problème BGP, le système dont dépend tout l'Internet. Une nouveauté, par rapport aux nombreux autres cas BGP du passé, est qu'il semble que le problème vienne du piratage d'un compte utilisé par Orange. Quelles leçons tirer de cette apparente nouveauté ?

bortzmeyer FR 2024 Orange Espagne BGP analyse incident
Three New Malicious PyPI Packages Deploy CoinMiner on Linux Devices | FortiGuard Labs https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices
05/01/2024 18:44:07
QRCode
archive.org
thumbnail

FortiGuard Labs cover the attack phases of three new PyPI packages that bear a resemblance to the culturestreak PyPI package discovered earlier this year. Learn more.

fortinet EN 2023 FortiGuard-Labs-Threat-Research Supply-chain-attack PyPI Packages CoinMiner
Bitwarden Heist - How to Break Into Password Vaults Without Using Passwords https://blog.redteam-pentesting.de/2024/bitwarden-heist/
05/01/2024 14:06:49
QRCode
archive.org
thumbnail

Sometimes, making particular security design decisions can have unexpected consequences. For security-critical software, such as password managers, this can easily lead to catastrophic failure: In this blog post, we show how Bitwarden’s Windows Hello …

redteam-pentesting.de 2024 Bitwarden Password Vaults Windows Hello
Analyzing DPRK's SpectralBlur https://objective-see.org/blog/blog_0x78.html
05/01/2024 12:38:58
QRCode
archive.org
thumbnail

In both his twitter (err, X) thread and in a subsequent posting he provided a comprehensive background and triage of the malware dubbed SpectralBlur. In terms of its capabilities he noted:

SpectralBlur is a moderately capable backdoor, that can upload/download files, run a shell, update its configuration, delete files, hibernate or sleep, based on commands issued from the C2. -Greg
He also pointed out similarities to/overlaps with the DPRK malware known as KandyKorn (that we covered in our “Mac Malware of 2024” report), while also pointing out there was differences, leading him to conclude:

We can see some similarities ... to the KandyKorn. But these feel like families developed by different folks with the same sort of requirements. -Greg

objective-see EN 2024 Analysis macOS backdoor SpectralBlur malware
Canton de Berne: Suite à une faille de sécurité dans un système informatique: plusieurs personnes prévenues identifiées et perquisitions effectuées https://www.police.be.ch/fr/start/themen/news/medienmitteilungen.html?newsID=099d36b4-274c-49fc-98e5-7da0ea68be86
05/01/2024 10:24:51
QRCode
archive.org

Suite à une faille de sécurité, l’été dernier, dans l’application «MobileIron», également utilisée par la Police cantonale bernoise, des données d’utilisatrices et d’utilisateurs avaient manifestement pu être téléchargées et consultées. Une enquête a permis d’identifier plusieurs personnes prévenues. De plus amples investigations sont en cours.

police.be.ch FR 2023 CH MobileIron CVE-2023–35078 prévenus perquisitions
page 128 / 237
4721 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio