Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 139 / 223
4446 résultats taggé E*N  ✕
CacheWarp https://cachewarpattack.com/#faq
14/11/2023 21:30:19
QRCode
archive.org

CacheWarp is a new software fault attack on AMD SEV-ES and SEV-SNP. It allows attackers to hijack control flow, break into encrypted VMs, and perform privilege escalation inside the VM.

cachewarpattack EN 2023 CPU attack CacheWarp AMD SEV-ES SEV-SNP
Google researchers discover 'Reptar,’ a new CPU vulnerability https://cloud.google.com/blog/products/identity-security/google-researchers-discover-reptar-a-new-cpu-vulnerability?hl=en
14/11/2023 21:23:12
QRCode
archive.org
thumbnail

A new CPU vulnerability, ‘Reptar,’ found by Google researchers, has been patched by Google and Intel. Here’s what you need to know.
...
The impact of this vulnerability is demonstrated when exploited by an attacker in a multi-tenant virtualized environment, as the exploit on a guest machine causes the host machine to crash resulting in a Denial of Service to other guest machines running on the same host. Additionally, the vulnerability could potentially lead to information disclosure or privilege escalation.

cloud.google.com EN 2023 CVE-2023-23583 CPU Reptar CPU Intel
District of Puerto Rico | Russian and Moldovan National Pleads Guilty to Operating Illegal Botnet Proxy Service that Infected Tens of Thousands of Internet-Connected Devices Around the World | United States Department of Justice https://www.justice.gov/usao-pr/pr/russian-and-moldovan-national-pleads-guilty-operating-illegal-botnet-proxy-service
14/11/2023 21:13:13
QRCode
archive.org
thumbnail

A Russian and Moldovan national pled guilty to three counts of violating 18 U.S.C. § 1030(a)(5)(A) Fraud and Related Activity in Connection with Computers.

The FBI today revealed US law enforcement’s dismantlement of a botnet proxy network and its infrastructure associated with the IPStorm malware.

According to online reports, the botnet infrastructure had infected Windows systems then further expanded to infect Linux, Mac, and Android devices, victimizing computers and other electronic devices around the world, including in Asia, Europe, North America and South America.

justice.gov EN 2023 IPStorm botnet proxy arrested
Microsoft Patch Tuesday November 2023 https://isc.sans.edu/diary/30400
14/11/2023 19:49:55
QRCode
archive.org
thumbnail

Today, Microsoft released patches for 64 different vulnerabilities in Microsoft products, 14 vulnerabilities in Chromium affecting Microsoft Edge, and five vulnerabilities affecting Microsoft's Linux distribution, Mariner. Three of these vulnerabilities are already being exploited, and three have been made public before the release of the patches.

isc.sans.edu EN 2023 Microsoft Patch patch-tuesday November2023
Reptar https://lock.cmpxchg8b.com/reptar.html
14/11/2023 18:56:31
QRCode
archive.org

We have a CPU mystery! We found a way to cause some processors to enter a glitch state where the normal rules don’t apply, but what does that mean…?

If you’re interested what can go wrong inside modern CPUs, read on!

cmpxchg8b EN CPU 2023 Intel IceLake
The $2,000 Phones that Let Anyone Make Robocalls https://www.404media.co/buy-fraud-phone-russiancoms-robocalls/
14/11/2023 15:33:46
QRCode
archive.org
thumbnail

Videos collected by 404 Media over months give a peep inside the world of spoofing numbers, automated call scripts, and a specific seller of the phones.

404media EN 2023 vishing robocalls phone scammers
Child sexual abuse online: effective measures, no mass surveillance https://www.europarl.europa.eu/news/en/press-room/20231110IPR10118/child-sexual-abuse-online-effective-measures-no-mass-surveillance
14/11/2023 15:32:29
QRCode
archive.org
thumbnail

On Tuesday, the Civil Liberties Committee adopted its position on new measures to protect children online by preventing and stopping child sexual abuse.

europarl.europa.eu EN European Parliament Civil Liberties Committee CSAM
Nothing new, still broken, insecure by default since then: Python's e-mail libraries and certificate verification https://www.pentagrid.ch/en/blog/python-mail-libraries-certificate-verification/
14/11/2023 11:15:01
QRCode
archive.org
thumbnail

Python’s e-mail libraries smtplib, imaplib, and poplib do not verify server certificates unless a proper SSL context is passed to the API. This leads to security problems.

pentagrid EN Python e-mail libraries smtplib imaplib poplib SSL insecure analysis
GameOver(lay) - Local Privilege Escalation in Ubuntu Kernel https://blog.projectdiscovery.io/gameover-lay-local-privilege-escalation-in-ubuntu-kernel/#:~:text=GameOver%20,of%20Ubuntu%20users
14/11/2023 10:33:20
QRCode
archive.org
thumbnail

GameOver(lay) encompasses two significant vulnerabilities within the Ubuntu kernel, CVE-2023-2640, and CVE-2023-32629, each carrying a high-severity rating with CVSS scores of 7.8. These vulnerabilities pose a critical threat, potentially affecting around 40% of Ubuntu users. The vulnerability lies within the OverlayFS module of the Ubuntu kernel, enabling a

projectdiscovery EN 2023 Ubuntu kernel CVE-2023-2640 CVE-2023-32629
Malaysian Police Dismantle “BulletProftLink” Phishing Operation https://www.infosecurity-magazine.com/news/malaysian-police-bulletproftlink/
13/11/2023 19:19:29
QRCode
archive.org
thumbnail

Several arrested and servers seized

infosecurity-magazine EN 2023 BulletProftLink Dismantle phishing-as-a-service police Malaysia
Bitter Pill: Third-Party Pharmaceutical Vendor Linked to Pharmacy and Health Clinic Cyberattack https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack
13/11/2023 18:39:40
QRCode
archive.org
thumbnail

Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.

huntress EN 2023 Pharmaceutical Vendor Health Clinic Cyberattack IoCs
Ivanti EPMM CVE-2023-39335/39337 https://www.ivanti.com/blog/ivanti-epmm-cve-2023-39335-39337
13/11/2023 15:32:06
QRCode
archive.org
thumbnail

We have discovered two new vulnerabilities in Ivanti Endpoint Manager Mobile. We are reporting these vulnerabilities as CVE-2023-39335 and CVE-2023-39337.

ivanti EN 2023 EPMM CVE-2023-39335 CVE-2023-39337
Here’s How Violent Extremists Are Exploiting Generative AI Tools https://www.wired.com/story/generative-ai-terrorism-content/
13/11/2023 06:46:10
QRCode
archive.org
thumbnail

Experts are finding thousands of examples of AI-created content every week that could allow terrorist groups and other violent extremists to bypass automated detection systems.
#algorithms #censorship #content #disinformation #israel-hamas #moderation #terrorism #war

wired EN 2023 content censorship moderation war israel-hamas algorithms terrorism disinformation
DP World: Australian ports to remain closed as AFP investigates cybersecurity breach https://www.smh.com.au/national/ports-to-remain-closed-as-afp-investigates-cybersecurity-breach-20231111-p5ej9i.html
12/11/2023 01:45:34
QRCode
archive.org
thumbnail

DP World: Australian ports to remain closed as AFP investigates cybersecurity breach"

smh EN 2023 cybersecurity breach Australia DPWorld
Boeing breach: LockBit leaks 50 GB of data https://cybernews.com/news/boeing-data-leak-lockbit-ransomware/
11/11/2023 12:10:19
QRCode
archive.org

The Boeing Company, a jetliner manufacturer and US defense contractor, had the company’s data leaked by the LockBit ransomware gang. So far, around 50 gigabytes of compressed data was uploaded LockBit's dark web blog.

LockBit has allegedly started leaking data that the gang stole from Boeing in late October. The Cybernews research team noted there's around of 50 GB of supposedly Boeing's data. Bulk of the data appears to be various backups.

cybernews EN LockBit Boeing DataLeak ransomware
Apple neglects to patch multiple critical vulnerabilities in macOS https://www.intego.com/mac-security-blog/apple-neglects-to-patch-multiple-critical-vulnerabilities-in-macos/
11/11/2023 10:46:44
QRCode
archive.org
thumbnail

Apple is neglecting to patch high-severity vulnerabilities in open-source components of macOS Sonoma, including curl and LibreSSL.

intego EN 2023 Apple patch high-severity macOS Sonoma curl open-source
CVE-2023-38548 https://attackerkb.com/topics/UPt5tpYK2Y/cve-2023-38548/rapid7-analysis?
10/11/2023 21:28:37
QRCode
archive.org
thumbnail

On November 6, 2023, Veeam published an advisory for several vulnerabilities affecting Veeam ONE, an IT monitoring and analytics platform for enterprises. One …

attackerkb CVE-2023-38548 EN 2023 VeeamONE Veeam vulnerability
Detecting “Effluence”, an Unauthenticated Confluence Web Shell https://www.aon.com/cyber-solutions/aon_cyber_labs/detecting-effluence-an-unauthenticated-confluence-web-shell/
10/11/2023 11:09:13
QRCode
archive.org
thumbnail

Discovering Effluence, a unique web shell accessible on every page of an infected Confluence

aon EN 2023 Effluence Confluence webshell CVE-2023-22515
ICBC hit by ransomware impacting global trades https://www.theregister.com/2023/11/10/icbc_ransomware/
10/11/2023 11:06:21
QRCode
archive.org
thumbnail

China's largest bank, ICBC, was hit by ransomware that resulted in disruption of financial services (FS) systems on Thursday Beijing time, according to a notice on its website

theregister EN 2023 ICBC Bank China
Dozens of npm Packages Caught Attempting to Deploy Reverse Shell https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/
10/11/2023 10:17:03
QRCode
archive.org
thumbnail

On October 27, Phylum’s automated risk detection platform began alerting us to a series of suspicious publications on npm. Over the course of the following few days, we discovered a campaign involving at least 48 different publications. These packages, deceptively named to appear legitimate, contained obfuscated JavaScript designed to

phylum EN 2023 npm Reverse Shell Supply-chain-attack
page 139 / 223
5036 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn