Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 136 / 237
Analysis of a new macOS Trojan-Proxy https://securelist.com/trojan-proxy-for-macos/111325/
06/12/2023 14:13:42
QRCode
archive.org
thumbnail

A new macOS Trojan-Proxy is riding on cracked versions of legitimate software; it relies on DNS-over-HTTPS to obtain a C&C (command and control) address.
Illegally distributed software historically has served as a way to sneak malware onto victims’ devices. Oftentimes, users are not willing to pay for software tools they need, so they go searching the Web for a “free lunch”. They are an excellent target for cybercriminals who realize that an individual looking for a cracked app will be willing to download an installer from a questionable website and disable security on their machine, and so they will be fairly easy to trick into installing malware as well.

securelist EN 2023 MacOS Trojan Malware Trojan-Proxy Descriptions Technologies Piracy Apple
Apple Confirms Governments Using Push Notifications to Surveil Users - MacRumors https://www.macrumors.com/2023/12/06/apple-governments-surveil-push-notifications/
06/12/2023 14:12:30
QRCode
archive.org
thumbnail

Unidentified governments are surveilling smartphone users by tracking push notifications that move through Google's and Apple's servers, a US...
In a letter to the Department of Justice, Senator Ron Wyden said foreign officials were demanding the data from the tech giants to track smartphones. The traffic flowing from apps that send push notifications put the companies "in a unique position to facilitate government surveillance of how users are using particular apps," Wyden said. He asked the Department of Justice to "repeal or modify any policies" that hindered public discussions of push notification spying.

macrumors EN 2023 privacy iOS iPhone iPad Apple push surveillance
Governments spying on Apple, Google users through push notifications https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/
06/12/2023 14:11:40
QRCode
archive.org

Unidentified governments are surveilling smartphone users via their apps' push notifications, a U.S. senator warned on Wednesday.

reuters EN 2023 Apple iphone push notification surveillance iPhone US
Windows 10 gets three more years of security updates, if you can afford them | Ars Technica https://arstechnica.com/gadgets/2023/12/windows-10-gets-three-more-years-of-security-updates-if-you-can-afford-them/
06/12/2023 13:19:53
QRCode
archive.org
thumbnail

Windows 10's end-of-support date is October 14, 2025. That's the day that most Windows 10 PCs will receive their last security update and the date when most people should find a way to move to Windows 11 to ensure that they stay secure.

As it has done for other stubbornly popular versions of Windows, though, Microsoft is offering a reprieve for those who want or need to stay on Windows 10: three additional years of security updates, provided to those who can pay for the Extended Security Updates (ESU) program.

arstechnica EN 2023 win10 ESU support end-of-support Extended Security Updates Windows Windows10 Microsoft
Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution https://thehackernews.com/2023/12/atlassian-releases-critical-software.html
06/12/2023 12:04:04
QRCode
archive.org
thumbnail

Atlassian has released software fixes to address four critical flaws in its software that could lead to remote code execution.

thehackernews EN 2023 Atlassian RCE flaws Jira Confluence
Russian Hackers’ Lawsuit Reveals Weaknesses In Apple’s iOS 16 https://www.forbes.com/sites/thomasbrewster/2023/12/04/russian-hacker-lawsuit-exposes-flaws-in-apples-ios-16
05/12/2023 19:14:12
QRCode
archive.org
thumbnail

A Moscow legal battle strongly indicates that phone forensics tools used by both the FBI and FSB are exploiting security loopholes in Apple’s operating system.

forbes EN 2023 russia ukraine america forensics iphone apple ios ios-16 ios-17 oxygen
23andMe confirms hackers stole ancestry data on 6.9 million users https://techcrunch.com/2023/12/04/23andme-confirms-hackers-stole-ancestry-data-on-6-9-million-users/
05/12/2023 08:16:16
QRCode
archive.org
thumbnail

Genetic testing company 23andMe revealed that its data breach was much worse than previously reported, hitting about half of its total customers.

techcrunch EN 2023 23andme data-breach ancestry
P2Pinfect - New Variant Targets MIPS Devices https://www.cadosecurity.com/p2pinfect-new-variant-targets-mips-devices/
04/12/2023 20:36:21
QRCode
archive.org
thumbnail

Cado Security Labs has been monitoring on the rapid growth of a cross-platform botnet, named “P2Pinfect”. Here's the latest updates.

cadosecurity EN 2023 MIPS IoT routers botnet
What it means — CitrixBleed ransomware group woes grow as over 60 credit unions, hospitals, financial services and more breached in US. | by Kevin Beaumont | Dec, 2023 | DoublePulsar https://doublepulsar.com/what-it-means-citrixbleed-ransom-group-woes-grow-as-over-60-credit-unions-hospitals-47766a091d4f
04/12/2023 20:05:44
QRCode
archive.org

Credit union technology firm Trellance own Ongoing Operations LLC, and provide a platform called Fedcomp — used by double digit number of other credit unions across the United States. This Fedcomp…

doublepulsar EN 2023 CitrixBleed analysis
L’attaque contre Xplain bloque aussi la modernisation de l’IT du canton d'Argovie (update) https://www.ictjournal.ch/news/2023-12-04/lattaque-contre-xplain-bloque-aussi-la-modernisation-de-lit-du-canton-dargovie
04/12/2023 19:21:16
QRCode
archive.org
thumbnail

Le canton d'Argovie ne développe plus de projets IT en collaboration avec Xplain pour le moment. C'est ce qui ressort d'une réponse du Conseil d'Etat argovien à une intervention parlementaire. Après la découverte de la cyberattaque en juin dernier, les projets avec le prestataire Xplain ont été suspendus jusqu'à nouvel ordre, indique le Conseil d'Etat. Une task force dédiée coordonne et documente toutes les mesures pour les applications touchées par la cyberattaque.

ictjournal CH Suisse FR Xplain Argovie cyberattaque
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
04/12/2023 18:10:49
QRCode
archive.org

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), and the Israel National Cyber Directorate (INCD)—hereafter referred to as "the authoring agencies"—are disseminating this joint Cybersecurity Advisory (CSA) to highlight continued malicious cyber activity against operational technology devices by Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated Advanced Persistent Threat (APT) cyber actors.

cisa US EN 2023 FBI IRGC Iran PLC CyberAv3ngers Advisory Critical-infrastructure
Phineas Fisher, Hacktivism, and Magic Tricks https://blog.isosceles.com/phineas-fisher-hacktivism-and-magic-tricks/
03/12/2023 14:58:13
QRCode
archive.org
thumbnail

It's said that a good magician never reveals their secrets. Computer hacking is a particularly good type of magic trick, and for the most part, hackers don't reveal their secrets either. It's sometimes hard to reconcile this, because we read about hacking all the time -- in newspapers, at conferences,

isosceles EN 2023 PhineasFisher
N. Korean Hackers 'Mixing' macOS Malware Tactics to Evade Detection https://thehackernews.com/2023/11/n-korean-hackers-mixing-and-matching.html
02/12/2023 13:03:23
QRCode
archive.org
thumbnail

The North Korean threat actors behind macOS malware strains such as RustBucket and KANDYKORN have been observed "mixing and matching" different elements of the two disparate attack chains, leveraging RustBucket droppers to deliver KANDYKORN.

thehackernews EN 2023 North-Korea macOS malware KANDYKORN
The Far-Reaching Consequences of LogoFAIL https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html
02/12/2023 11:44:08
QRCode
archive.org
thumbnail

The Binarly REsearch team investigates vulnerable image parsing components across the entire UEFI firmware ecosystem and finds all major device manufacturers are impacted on both x86 and ARM-based devices.

binarly EN 2023 UEFI firmware LogoFAIL
Amazon’s Q has ‘severe hallucinations’ and leaks confidential data in public preview, employees warn https://www.platformer.news/p/amazons-q-has-severe-hallucinations?r=2d5oq
02/12/2023 11:39:50
QRCode
archive.org

Some hallucinations could ‘potentially induce cardiac incidents in Legal,’ according to internal documents

platformer EN 2023 AI Amazon Legal Q hallucinations confidential disclosure
Vidar Infostealer Steals Booking.com Credentials in Fraud Scam https://www.secureworks.com/blog/vidar-infostealer-steals-booking-com-credentials-in-fraud-scam
01/12/2023 15:21:45
QRCode
archive.org
thumbnail

Learn how a threat actor used spearphishing emails and social engineering tactics to obtain a hotel’s credentials and solicit customers’ payment information.

secureworks EN 2023 booking.com Vidar Infostealer Steals
Cyber Threats affecting "International Geneva" https://geneva.cyberpeace.ngo/
01/12/2023 11:38:04
QRCode
archive.org
thumbnail

In the heart of International Geneva, a diverse ecosystem thrives, housing 38 international organizations (IOs), 432 non-governmental organizations (NGOs), and several hundred associations active at an international level, all united by a shared mission: to make the world a place of peace and justice. NGOs are the unsung heroes, addressing armed conflicts, natural disasters, and humanitarian crises, championing human rights, and advancing the Sustainable Development Goals (SDGs). Like many other organizations, NGOs heavily rely on technology, which is critical for projecting their activities globally in real time. Yet, in today’s digital landscape, this reality brings its own set of challenges.

cyberpeace EN CH 2023 Geneva threats analysis NGOs organizations Switzerland
Qlik Sense Remote Code Execution Technical Exploitation - https://www.praetorian.com/blog/qlik-sense-technical-exploit/
01/12/2023 11:00:17
QRCode
archive.org
thumbnail

Deep technical details of how we combined HTTP request tunneling and path traversal vulnerabilities to permit unauthorized RCE in Qlik Sense.

praetorian EN 2023 exploit Qlik Sense Remote Code Execution technical details
Spyware are still having a ‘ball’ despite a decade of warnings - Binding hook https://bindinghook.com/articles-hooked-on-trends/spyware-are-still-having-a-ball-despite-a-decade-of-warnings/
01/12/2023 10:40:21
QRCode
archive.org
thumbnail
Les ministres français invités à désinstaller WhatsApp, Signal et Telegram https://www.lepoint.fr/high-tech-internet/les-ministres-francais-invites-a-desinstaller-whatsapp-signal-et-telegram-29-11-2023-2545099_47.php#11
30/11/2023 13:48:54
QRCode
archive.org
thumbnail

À partir du 8 décembre, les membres du gouvernement devront utiliser les applications de messagerie françaises Tchap ou Olvid.

lepoint FR 2023 messagerie souveraineté France WhatsApp Telegram Olvid Tchap
page 136 / 237
4723 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio