Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 144 / 237
2022 RTF Global Ransomware Incident Map: Attacks continue worldwide, groups splinter, education sector hit hard https://securityandtechnology.org/blog/2022-global-ransomware-incident-map/
01/11/2023 13:15:39
QRCode
archive.org
thumbnail

According to ecrime.ch data, confirmed ransomware incidents occurred in 105 countries, originating from 58 ransomware groups.  This number is relatively consistent with last year’s data, in which we calculated that incidents impacted organizations in 109 countries and documented at least 60 distinct ransomware families.  Though the overall statistics remain relatively consistent from last year to this year, there is more to the story: new trends in the ecosystem include the shifting dynamics of ransomware groups, the rise of the education sector as a key target, and the trends in geographic distribution of attacks.

securityandtechnology EN 2023 2022 Global Ransomware Incident Map ecrime
Massive cybercrime URL shortening service uncovered via DNS data https://www.bleepingcomputer.com/news/security/massive-cybercrime-url-shortening-service-uncovered-via-dns-data/
01/11/2023 07:25:49
QRCode
archive.org
thumbnail

A threat actor that security researchers call Prolific Puma has been providing link shortening services to cybercriminals for at least four years while keeping a sufficiently low profile to operate undetected.

bleepingcomputer EN 2023 Shortener URL NameSilo Prolific Computer usTLD DNS Security InfoSec Puma TLD
CVE-2023-46747 https://attackerkb.com/topics/t52A9pctHn/cve-2023-46747/rapid7-analysis?referrer=notificationEmail
01/11/2023 06:49:16
QRCode
archive.org
thumbnail

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port…

attackerkb EN 2023 CVE-2023-46747 technical analysis
Atlassian warns of critical Confluence flaw leading to data loss https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-confluence-flaw-leading-to-data-loss/
31/10/2023 19:59:30
QRCode
archive.org
thumbnail

Australian software company Atlassian warned admins to immediately patch Internet-exposed Confluence instances against a critical security flaw that could lead to data loss following successful exploitation.

bleepingcomputer EN 2023 Atlassian Loss Security Data Confluence
SEC accuses SolarWinds CISO of misleading investors before Russian cyberattack | TechCrunch https://techcrunch.com/2023/10/31/sec-solarwinds-ciso-investors-cyberattack/
31/10/2023 14:16:44
QRCode
archive.org
thumbnail

The U.S. Securities and Exchange Commission has charged SolarWinds and its top cybersecurity executive Timothy Brown with fraud and internal control

techcrunch EN 2023 CISO cyberattack espionage russia solarwinds us-government SolarWinds US
Surge in QR Code Quishing: Check Point Records 587% Attack Spike https://www.hackread.com/qr-code-quishing-check-point-attack-spike/
31/10/2023 09:05:11
QRCode
archive.org
thumbnail

Check Point’s Harmony Email team has reported a startling increase of 587% in QR code phishing or Quishing attacks.

hackread EN 2023 QRCode Attack Spike
Two Developers of the Ragnar Locker Ransomware Arrested in Spain https://deform.co/two-developers-of-the-ragnar-locker-ransomware-arrested-in-spain/
30/10/2023 21:57:42
QRCode
archive.org
thumbnail

An international law enforcement operation coordinated by Europol resulted in the dismantling of one of the largest groups involved in the distribution of

deform EN 2023 Locker Ransomware Ragnar law enforcement operation Europol Arrested Spain
GHOSTPULSE haunts victims using defense evasion bag o' tricks https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks
30/10/2023 19:48:40
QRCode
archive.org
thumbnail

Elastic Security Labs reveals details of a new campaign leveraging defense evasion capabilities to infect vicitms with malicious MSIX executables.

elastic EN 2023 GHOSTPULSE analysis
FakeUpdateRU Chrome Update Infection Spreads Trojan Malware https://blog.sucuri.net/2023/10/fakeupdateru-chrome-update-infection-spreads-trojan-malware.html
30/10/2023 19:07:05
QRCode
archive.org
thumbnail

Learn about the fake Google Chrome update malware, a common form of website malware that tricks users into downloading a remote access trojan disguised as a browser update. Understand how it works, its impact on websites, and how to protect your site from such threats. Stay updated on the latest malware trends with Sucuri.

sucuri EN 2023 Google Chrome update malware fake analysis
3 new NGINX ingress controller Kubernetes related vulnerabilities https://www.armosec.io/blog/cve-2023-5043-nginx-ingress/
30/10/2023 15:13:48
QRCode
archive.org
thumbnail

CVE-2023-5043, CVE-2023-5044 and CVE-2022-4886 can be exploited by attacker to steal secret credentials from the cluster. Read all about it!

armosec EN 2023 ingress NGINX Kubernetes CVE-2023-5043 CVE-2023-5044 CVE-2022-4886
Introducing HAR Sanitizer: secure HAR sharing https://blog.cloudflare.com/introducing-har-sanitizer-secure-har-sharing/
29/10/2023 11:52:06
QRCode
archive.org
thumbnail

As a follow-up to the most recent Okta breach, we are making a HAR file sanitizer available to everyone, not just Cloudflare customers, at no cost.

cloudflare EN 2023 HAR Sanitizer Okta tool
HackerOne paid ethical hackers over $300 million in bug bounties https://www.bleepingcomputer.com/news/security/hackerone-paid-ethical-hackers-over-300-million-in-bug-bounties/
28/10/2023 23:07:20
QRCode
archive.org
thumbnail

HackerOne has announced that its bug bounty programs have awarded over $300 million in rewards to ethical hackers and vulnerability researchers since the platform's inception.

bleepingcomputer EN 2023 Bug-Bounty Ethical-Hacking HackerOne Vulnerability Vulnerability-Disclosure-Program Vulnerability-Rewards-Program White-Hat-Hacker
Turning a boring file move into a privilege escalation on Mac | pwn.win https://pwn.win/2023/10/28/file-move-privesc-mac.html
28/10/2023 13:36:10
QRCode
archive.org

While poking around Parallels Desktop I found a script which is invoked by a setuid-root binary, which has the following snippet: local prl_dir="${usr_home}/Library/Parallels" if [ -e "$prl_dir" -a ! -d "$prl_dir" ]; then log warning "'${prl_dir}' is not a directory. Renaming it." mv -f "$prl_dir"{,~} continue fi Here ${usr_home} represents the home directory of the user for which Parallels Desktop is installed. The code says if ~/Library/Parallels exists and is not a directory then move it to ~/Library/Parallels~, presumably to back it up before creating this path as a directory.

pwn.win EN 2023 Parallels Desktop privesc
SIM Swappers Are Working Directly with Ransomware Gangs Now https://www.404media.co/sim-swappers-are-working-directly-with-ransomware-gangs-now/
27/10/2023 13:54:34
QRCode
archive.org
thumbnail

Hackers connected to “the Comm,” a nebulous group that includes SIM swappers, are working with ALPHV, a ransomware group that has impacted some of the biggest companies on the planet, including MGM Casinos.

404media EN 2023 ALPHV the-Comm SIMSwappers ransomware
CVE-2023-45498: RCE in VinChin Backup https://blog.leakix.net/2023/10/vinchin-backup-rce-chain/
27/10/2023 13:47:49
QRCode
archive.org
thumbnail

CVE-2023-45498/CVE-2023-45499 advisory

leakix EN 2023 advisory RCE VinChin Backup CVE-2023-45498 CVE-2023-4549
Compromising F5 BIGIP with Request Smuggling | CVE-2023-46747 https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
27/10/2023 13:43:18
QRCode
archive.org
thumbnail

Our team identified a request smuggling vulnerability that led to complete compromise of an F5 system with the TMUI exposed.

praetorian EN F5 BIGIP Request Smuggling vulnerability CVE-2023-46747
Chatbot Hallucinations Are Poisoning Web Search https://www.wired.com/story/fast-forward-chatbot-hallucinations-are-poisoning-web-search/
27/10/2023 09:06:26
QRCode
archive.org
thumbnail

Untruths spouted by chatbots ended up on the web—and Microsoft's Bing search engine served them up as facts. Generative AI could make search harder to trust.

wired EN search artificial-intelligence algorithms machine-learning hallucinations chatbots GenerativeAI risk search
CCleaner confirms data breach via MOVEit attack https://cybernews.com/news/ccleaner-confirms-data-breach/
27/10/2023 08:58:56
QRCode
archive.org

CCleaner, a popular software for cleaning files and Windows Registry entries, has confirmed that attackers accessed some of its customer data.

cybernews EN 2023 MOVEit CCleaner
European govt email servers hacked using Roundcube zero-day https://www.bleepingcomputer.com/news/security/european-govt-email-servers-hacked-using-roundcube-zero-day/
27/10/2023 08:52:20
QRCode
archive.org
thumbnail

The Winter Vivern Russian hacking group has been exploiting a Roundcube Webmail zero-day since at least October 11 to attack European government entities and think tanks.

Cyber-espionage Email Europe Government Roundcube Russia Winter-Vivern XSS Zero-Day CVE-2023-5631
A cascade of compromise: unveiling Lazarus' new campaign https://securelist.com/unveiling-lazarus-new-campaign/110888/
27/10/2023 08:48:29
QRCode
archive.org
thumbnail

We unveil a Lazarus campaign exploiting security company products and examine its intricate connections with other campaigns

securelist EN 2023 Backdoor Lazarus Malware-Descriptions SIGNBT
page 144 / 237
4725 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio