Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 146 / 213
4246 résultats taggé E*N  ✕
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation https://blog.talosintelligence.com/weaknesses-mac-os-vmware-msrpc/
14/07/2023 09:47:57
QRCode
archive.org
thumbnail

Cisco Talos discovered 12 memory corruption vulnerabilities in MSRPC implementations on Apple macOS and VMWare vCenter.
      - Seven vulnerabilities affect Apple macOS only.
      - Two vulnerabilities affect VMWare vCenter.
      - Three vulnerabilities affect both.

talosintelligence EN 2023 MSRPC macOS VMWare vCenter vulnerabilities
Chinese hackers breached US government email accounts, Microsoft and White House say | CNN Politics https://edition.cnn.com/2023/07/12/politics/china-based-hackers-us-government-email-intl-hnk/index.html
13/07/2023 08:54:31
QRCode
archive.org
thumbnail

China-based hackers have breached email accounts at two-dozen organizations, including some United States government agencies, in an apparent spying campaign aimed at acquiring sensitive information, according to statements from Microsoft and the White House late Tuesday.

cnn EN 2023 China US Microsoft breached Storm0558
Chinese hackers breached U.S. and European government email through Microsoft bug https://therecord.media/chinese-hackers-breached-us-and-european-governments
13/07/2023 00:28:56
QRCode
archive.org
thumbnail

A Chinese hacking group exploited a bug in Microsoft’s cloud email service to spy on two-dozen organizations, including some government agencies, the tech giant said late Tuesday.

therecord EN 2023 China US EU hacking spy Outlook token Storm-0558
Loader activity for Formbook "QM18" https://isc.sans.edu/diary/rss/30020
13/07/2023 00:17:50
QRCode
archive.org

Loader activity for Formbook "QM18", Author: Brad Duncan

SANS EN 2023 QM18 Formbook Loader
The Spies Who Loved You: Infected USB Drives to Steal Secrets https://www.mandiant.com/resources/blog/infected-usb-steal-secrets
12/07/2023 10:01:01
QRCode
archive.org
thumbnail

In the first half of 2023, we observed a threefold increase in the number of attacks using infected USB drives to steal secrets.

mandiant EN 2023 USB drives steal SOGU Malware SNOWYDRIVE
Hackers exploit gaping Windows loophole to give their malware kernel access https://arstechnica.com/security/2023/07/hackers-exploit-gaping-windows-loophole-to-give-their-malware-kernel-access/
12/07/2023 09:37:03
QRCode
archive.org
thumbnail

Microsoft blocks a new batch of system drivers, but the loophole empowering them remains.

arstechnica EN 2023 Windows malicious drivers loophole 2015
Microsoft Revokes Malicious Drivers in Patch Tuesday Culling https://news.sophos.com/en-us/2023/07/11/microsoft-revokes-malicious-drivers-in-patch-tuesday-culling/
12/07/2023 09:33:30
QRCode
archive.org
thumbnail

In December 2022, Microsoft published their monthly Windows Update packages that included an advisory about malicious drivers, signed by Microsoft and other code-signing authorities, that Sophos X-…

sophos EN 2023 malicious drivers Microsoft-signed
Apple & Microsoft Patch Tuesday, July 2023 Edition https://krebsonsecurity.com/2023/07/apple-microsoft-patch-tuesday-july-2023-edition/
12/07/2023 09:30:55
QRCode
archive.org

Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this…

krebsonsecurity EN 2023 PatchTuesday july23023 Microsoft
Apple releases emergency update to fix zero-day exploited in attacks https://www.bleepingcomputer.com/news/apple/apple-releases-emergency-update-to-fix-zero-day-exploited-in-attacks/
12/07/2023 09:09:39
QRCode
archive.org
thumbnail

Apple has issued a new round of Rapid Security Response (RSR) updates to address a new zero-day bug exploited in attacks and impacting fully-patched iPhones, Macs, and iPads.

bleepingcomputer EN 2023 CVE-2023-37450 Apple iOS iPad iPhone Mac macOS Rapid-Security-Response Zero-Day
KB5029033: Notice of additions to the Windows Driver.STL revocation list - Microsoft Support https://support.microsoft.com/en-us/topic/kb5029033-notice-of-additions-to-the-windows-driver-stl-revocation-list-d330efa5-3fb7-4903-9f0b-3230d31fca38
12/07/2023 08:18:16
QRCode
archive.org

The Microsoft Windows Hardware Compatibility Program (WHCP) certifies that drivers, and other products, run reliably on Windows and on Windows certified hardware. First reported by Sophos, and later Trend Micro and Cisco, Microsoft has investigated and confirmed a list of third-party WHCP-certified drivers used in cyber threat campaigns. Because of the drivers’ intent and functionality, Microsoft has added them to the Windows Driver.STL revocation list.

microsoft EN 2023 drivers signed Microsof-signed blocklist
Storm-0978 attacks reveal financial and espionage motives https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/
11/07/2023 20:52:20
QRCode
archive.org
thumbnail

Microsoft has identified a phishing campaign conducted by the threat actor tracked as Storm-0978 targeting defense and government entities in Europe and North America. The campaign involved the abuse of CVE-2023-36884, which included a zero-day remote code execution vulnerability exploited via Microsoft Word documents.

microsoft EN 2023 Storm-0978 Follina CVE-2023-36884 ero-day remote phishing
HCA Healthcare patient data stolen and for sale by hackers https://www.cnbc.com/2023/07/10/hca-healthcare-patient-data-stolen-and-for-sale-by-hackers.html?mid=1#cid=899581
11/07/2023 19:48:24
QRCode
archive.org
thumbnail

The health-care giant claimed no "clinical" information was breached by the hackers, a claim undercut by sample data provided to an industry analyst.

cnbc EN 2023 PHI Databreach Health-care-industry HCA US
Six Malicious Python Packages in the PyPI Targeting Windows Users https://unit42.paloaltonetworks.com/malicious-packages-in-pypi/
11/07/2023 19:40:23
QRCode
archive.org
thumbnail

Malicious packages on PyPI copy W4SP attacks to steal users’ credentials and crypto wallet data. This incident illustrates issues in open-source ecosystems.

unit42 EN 2023 PyPI W4SP attacks packages Supply-Chain-Attack
It’s Raining Phish and Scams – How Cloudflare Pages.dev and Workers.dev Domains Get Abused | Trustwave https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/its-raining-phish-and-scams-how-cloudflare-pages-dev-and-workers-dev-domains-get-abused/
11/07/2023 19:02:22
QRCode
archive.org
thumbnail

As they say, when it rains, it pours. Recently, we observed more than 3,000 phishing emails containing phishing URLs abusing services at workers.dev and pages.dev domains.

trustwave EN 2023 Phish Scams Cloudflare Pages.dev Workers.dev
GTA, Uber and Nvidia Hackers: Lapsus$ Teens Face Blackmail, Fraud Charges https://archive.ph/BOmd3
11/07/2023 18:48:47
QRCode
archive.org

Two UK teenagers were accused of being key members of the notorious hacking group Lapsus$, with prosecutors alleging that the pair were involved in attacks on companies including Nvidia Corp., Rockstar Games Inc., and Uber Technologies Inc.

Bloomberg 2023 EN London UK teenagers Lapsus$ accused Blackmail Fraud Charges
Revolut’s US payment flaws allowed thieves to steal $20mn https://archive.ph/Joh4a#selection-2047.0-2051.60
10/07/2023 09:24:34
QRCode
archive.org

A flaw in Revolut’s payment system in the US allowed criminals to steal more than $20mn of its funds over several months last year before the company could close the loophole, according to multiple people with knowledge of the episode.

ft EN 2023 Revolut steal criminals loophole
The five-day job: A BlackByte ransomware intrusion case study https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/
08/07/2023 11:31:41
QRCode
archive.org
thumbnail

In a recent investigation by Microsoft Incident Response of a BlackByte 2.0 ransomware attack, we found that the threat actor progressed through the full attack chain, from initial access to impact, in less than five days, causing significant business disruption for the victim organization.

microsoft EN 2023 BlackByte ransomware attack report
Unmasking the Meduza Stealer: Comprehensive Analysis & Countermeasures https://www.uptycs.com/blog/what-is-meduza-stealer-and-how-does-it-work
07/07/2023 13:55:01
QRCode
archive.org
thumbnail

Read Uptycs' analysis of the newly discovered Meduza Stealer malware targeting Windows users, revealing capabilities, potential impact & mitigation steps.

Uptycs EN 2023 meduza Stealer Windows analysis
Two spyware tied with China found hiding on the Google Play Store https://blog.pradeo.com/spyware-tied-china-found-google-play-store
07/07/2023 10:21:25
QRCode
archive.org
thumbnail

This week, our engine detected two spyware hiding on the Google Play Store and affecting up to 1.5 million users.

pradeo EN Android spyware GooglePlay
Operation Brainleeches: Malicious npm packages fuel supply chain and phishing attacks https://www.reversinglabs.com/blog/operation-brainleeches-malicious-npm-packages-fuel-supply-chain-and-phishing-attacks
07/07/2023 10:20:48
QRCode
archive.org
thumbnail

“Write once, infect everywhere” might be the new cybercrime motto, with newly discovered campaigns showing malicious npm packages powering phishing kits and supply chain attacks.

reversinglabs EN NPM Malicious packages supplychain Supply-Chain-Attack
page 146 / 213
4827 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn