Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 141 / 213
4249 résultats taggé E*N  ✕
Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868) https://www.mandiant.com/resources/blog/unc4841-post-barracuda-zero-day-remediation
29/08/2023 21:02:01
QRCode
archive.org
thumbnail

UNC4841 has continued operations despite Barracuda ESG zero-day remediation efforts.

mandiant EN 2023 UNC4841 Barracuda ESG 0-day CVE-2023-2868
Attacks on Citrix NetScaler systems linked to ransomware actor https://www.bleepingcomputer.com/news/security/attacks-on-citrix-netscaler-systems-linked-to-ransomware-actor/
29/08/2023 08:39:56
QRCode
archive.org
thumbnail

A threat actor believed to be tied to the FIN8 hacking group exploits the CVE-2023-3519 remote code execution flaw to compromise unpatched Citrix NetScaler systems in domain-wide attacks.

bleepingcomputer EN 2023 CVE-2023-3519 Citrix FIN8 Citrix-ADC Citrix-Gateway Code-Injection Ransomware Remote-Code-Execution
Adversary On The Defense: ANTIBOT.PW https://inquest.net/blog/adversary-on-the-defense-antibot-pw/
28/08/2023 20:55:37
QRCode
archive.org
thumbnail

Discover the lifecycle of a commercial web traffic filtering service originating from a GitHub project and how it found success within phishing operations, including how it evolved into a commercial platform offering under new branding.

inquest EN 2023 analysis ANTIBOT.PW phishing
GTA 6 Hacker Found To Be Teen With Amazon Fire Stick In Small Town Hotel Room https://hackaday.com/2023/08/26/gta-6-hacker-found-to-be-teen-with-amazon-fire-stick-in-small-town-hotel-room/
28/08/2023 11:59:45
QRCode
archive.org
thumbnail

International cybercrime, as portrayed by the movies and mass media, is a high-stakes game of shadowy government agencies and state-sponsored hacking groups. Hollywood casting will wheel out a charact...

hackaday EN Lapsus$ Teen Amazon Fire Stick
Lapsus$: Court finds teenagers carried out hacking spree https://www.bbc.com/news/technology-66549159
28/08/2023 11:21:33
QRCode
archive.org
thumbnail

The 18 year old leaked clips of the unreleased Grand Theft Auto 6 game while on police bail.

BBC EN 2023 Lapsus$ teenagers GTA6
Security advisory: malicious crate rustdecimal https://blog.rust-lang.org/2022/05/10/malicious-crate-rustdecimal.html
28/08/2023 06:42:31
QRCode
archive.org
thumbnail

The Rust Security Response WG and the crates.io team were notified on 2022-05-02 of the existence of the malicious crate rustdecimal, which contained malware. The crate name was intentionally similar to the name of the popular rust_decimal crate, hoping that potential victims would misspell its name (an attack called "typosquattin

rust-lang EN 2022 malicious crate rustdecimal
Poland investigates cyber-attack on rail network - BBC News https://www.bbc.com/news/world-europe-66630260
27/08/2023 16:10:23
QRCode
archive.org
thumbnail

olish intelligence services are investigating a hacking attack on the country's railways, Polish media say.

Hackers broke into railway frequencies to disrupt traffic in the north-west of the country overnight, the Polish Press Agency (PAP) reported on Saturday.

The signals were interspersed with recording of Russia's national anthem and a speech by President Vladimir Putin, the report says.

BBC 2023 EN Poland rail network cyber-attack
Met Police admits details of officers at risk of exposure after warrant card supplier was hacked https://news.sky.com/story/met-police-admits-details-of-officers-at-risk-of-exposure-after-warrant-card-supplier-was-hacked-12948602
27/08/2023 00:56:36
QRCode
archive.org
thumbnail

The security breach took place when cybercriminals successfully breached the IT systems of a contractor in charge of producing warrant cards and staff passes.

sky EN 2023 police breached
CVE-2023-36844 And Friends: RCE In Juniper Devices https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/
26/08/2023 12:55:18
QRCode
archive.org
thumbnail

As part of our Continuous Automated Red Teaming and Attack Surface Management technology - the watchTowr Platform - we're incredibly proud of our ability to discover nested, exploitable vulnerabilities across huge attack surfaces.

Through our rapid PoC process, we enable our clients to understand if they are vulnerable to emerging

labs.watchtowr EN 2023 CVE-2023-36844 Juniper RCE analysis
MOVEit, the biggest hack of the year, by the numbers https://techcrunch.com/2023/08/25/moveit-mass-hack-by-the-numbers/
26/08/2023 02:03:04
QRCode
archive.org
thumbnail

The mass-exploitation of MOVEit file transfer servers — the largest hack of the year so far — now affects at least 60 million people.

techcrunch EN 2023 MOVEit cyberattack mass-exploitation Clop
Technical Advisory – SonicWall Global Management System (GMS) & Analytics – Multiple Critical Vulnerabilities https://research.nccgroup.com/2023/08/24/technical-advisory-sonicwall-global-management-system-gms-analytics-multiple-critical-vulnerabilities/
25/08/2023 11:36:28
QRCode
archive.org
thumbnail

Multiple Unauthenticated SQL Injection Issues & Security Filter Bypass – CVE-2023-34133 Title: Multiple Unauthenticated SQL Injection Issues & Security Filter Bypass Risk: 9.8 (Critic…

nccgroup EN SonicWall GMS CVE-2023-34133 CVE-2023-34124
Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT https://blog.talosintelligence.com/lazarus-quiterat/
25/08/2023 08:39:04
QRCode
archive.org
thumbnail

This is the third documented campaign attributed to this actor in less than a year, with the actor reusing the same infrastructure throughout these operations.

talosintelligence EN 2023 analysis ManageEngine CVE-2022-47966
Time keeps on slippin’ slippin’ slippin’: The 2023 Active Adversary Report for Tech Leaders – Sophos News https://news.sophos.com/en-us/2023/08/23/active-adversary-for-tech-leaders/
25/08/2023 08:34:38
QRCode
archive.org
thumbnail
  • Compromised credentials are a gift that keeps on giving (your stuff away)
  • MFA is your mature, sensible friend
  • Dwell time is sinking faster than RMS Titanic
  • Criminals don’t take time off; neither can you*
  • Active Directory servers: The ultimate attacker tool
  • RDP: High time to decline the risk
  • Missing telemetry just makes things harder
sophos EN 2023 report adversary
Resecurity | Cl0p Ups the Ante with Massive MOVEit Transfer Supply-Chain Exploit https://www.resecurity.com/blog/article/cl0p-ups-the-ante-with-massive-moveit-transfer-supply-chain-exploit
25/08/2023 07:19:21
QRCode
archive.org

The supply-chain cyberattack that targeted Progress Software’s MOVEit Transfer application has compromised over 963 private and public-sector organizations worldwide. The ransomware group, Cl0p, launched this attack campaign over Memorial Day weekend.

Some higher-profile victims of the hack include Maximus, Deloitte, TIAA, Ernst & Young, Shell, Deutsche Bank, PricewaterhouseCoopers, Sony, Siemens, BBC, British Airways, the U.S. Department of Energy, the U.S. Department of Agriculture, the Louisiana Office of Motor Vehicles, the Colorado Department of Health Care Policy and Financing, and other U.S. government agencies. Thus far, the personal data of over 58 million people is believed to have been exposed in this exploit campaign.

resecurity EN 2023 MOVEit Supply-Chain Exploit cyberattack
Ransomware infection wipes all CloudNordic servers https://www.theregister.com/2023/08/23/ransomware_wipes_cloudnordic/
24/08/2023 15:22:16
QRCode
archive.org
thumbnail

IT outfit says it can't — and won't — pay the ransom demand

theregister EN 2023 Ransomware CloudNordic
Fake Roblox packages target npm with Luna Grabber information-stealing malware https://www.reversinglabs.com/blog/fake-roblox-api-packages-luna-grabber-npm
24/08/2023 14:19:10
QRCode
archive.org
thumbnail

ReversingLabs researchers have identified more than a dozen malicious packages targeting Roblox API users on the npm repository. This latest campaign recalls a 2021 attack.

reversinglabs EN 2023 Roblox API npm LunaGrabber
WinRAR 0-day that uses poisoned JPG and TXT files under exploit since April | Ars Technica https://arstechnica.com/security/2023/08/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april/
24/08/2023 08:39:23
QRCode
archive.org
thumbnail

Vulnerability allows hackers to execute malicious code when targets open malicious ZIP files.

arstechnica EN WinRAR 0-day CVE-2023-38831
#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation https://www.deepinstinct.com/blog/nofilter-abusing-windows-filtering-platform-for-privilege-escalation
24/08/2023 08:34:53
QRCode
archive.org
thumbnail

This blog is based on a session we presented at DEF CON 2023 on Sunday, August 13, 2023, in Las Vegas. Privilege escalation is a common attack vector in the Windows OS. There are multiple offensive tools in the wild that can execute code as “NT AUTHORITY\SYSTEM” (Meterpreter, CobaltStrike, Potato tools), and they all usually do so by duplicating tokens and manipulating services. This allows them to perform attacks like LSASS Shtinkering.

deepinstinct EN 2023 #NoFilter DEFCON2023 Privilege escalation
British court convicts two teen Lapsus$ members of hacking tech firms https://therecord.media/lapsus$-hackers-convinctions-teens-uk-court
23/08/2023 15:35:38
QRCode
archive.org
thumbnail

Two teenagers, ages 18 and 17, were found guilty of hacking into major corporations. The cases involved Uber, Nvidia and more.

therecord EN 2023 Lapsus$ teenagers busted
macOS 0day: App Management https://lapcatsoftware.com/articles/2023/8/2.html
22/08/2023 21:26:42
QRCode
archive.org

App Management is a new macOS security feature in Ventura introduced at WWDC last year:

If an app is modified by something that isn't signed by the same development team and isn't allowed by an NSUpdateSecurityPolicy, macOS will block the modification and notify the user that an app wants to manage other apps. Clicking on the notification sends people to System Settings, where they can allow an app to update and modify other apps.

lapcatsoftware EN 2023 macOS 0-day AppManagement
page 141 / 213
4832 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn