Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 147 / 207
4136 résultats taggé EN  ✕
Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware https://blog.talosintelligence.com/mercenary-intellexa-predator/
28/05/2023 13:46:37
QRCode
archive.org
thumbnail

We would like to thank The Citizen Lab for their cooperation, support and inputs into this research.

  • Commercial spyware use is on the rise, with actors leveraging these sophisticated tools to conduct surveillance operations against a growing number of targets. Cisco Talos has new details of a commercial spyware product sold by the spyware firm Intellexa (formerly known as Cytrox).
  • Our research specifically looks at two components of this mobile spyware suite known as “ALIEN” and “PREDATOR,” which compose the backbone of the spyware implant. Our findings include an in-depth walkthrough of the infection chain, including the implants’ various information-stealing capabilities.
  • A deep dive into both spyware components indicates that ALIEN is more than just a loader for PREDATOR and actively sets up the low-level capabilities needed for PREDATOR to spy on its victims.
  • We assess with high confidence that the spyware has two additional components — tcore (main component) and kmem (privilege escalation mechanic) — but we were unable to obtain and analyze these modules.
  • If readers suspect their system(s) may have been compromised by commercial spyware, please consider notifying Talos’ research team at talos-mercenary-spyware-help@external.cisco.com to assist in furthering the community’s knowledge of these threats.
talosintelligence EN 2023 PREDATOR spyware Intellexa ALIEN analysis Android
Inner workings revealed for “Predator,” the Android malware that exploited 5 0-days https://arstechnica.com/information-technology/2023/05/inner-workings-revealed-for-predator-the-android-malware-that-exploited-5-0-days/
28/05/2023 13:46:18
QRCode
archive.org
thumbnail

Spyware is sold to countries including Egypt, Indonesia, Oman, Saudi Arabia, and Serbia.
Smartphone malware sold to governments around the world can surreptitiously record voice calls and nearby audio, collect data from apps such as Signal and WhatsApp, and hide apps or prevent them from running upon device reboots, researchers from Cisco’s Talos security team have found.

arstechnica EN 2023 Smartphone PREDATOR 0-days spyware Android
Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/
27/05/2023 21:48:42
QRCode
archive.org
thumbnail

We analyze Mirai variant IZ1H9, which targets IoT devices. Our overview includes campaigns observed, botnet configuration and vulnerabilities exploited.

paloaltonetworks EN 2023 Mirai IZ1H9 IoT campaigns
NHS data breach: trusts shared patient details with Facebook without consent | Health | The Guardian https://www.theguardian.com/society/2023/may/27/nhs-data-breach-trusts-shared-patient-details-with-facebook-meta-without-consent
27/05/2023 21:43:44
QRCode
archive.org
thumbnail

Observer investigation reveals Meta Pixel tool passed on private details of web browsing on medical sites

theguardian EN 2023 privacy NHS databreach Facebook Health
Armenia spyware victims: Pegasus hacking in war https://www.accessnow.org/publication/armenia-spyware-victims-pegasus-hacking-in-war/
25/05/2023 23:45:14
QRCode
archive.org
thumbnail

A joint investigation by civil society and independent researchers has uncovered hacking of Armenia spyware victims with NSO Group's Pegasus spyware.

accessnow EN 2023 Pegasus Armenia spyware NSO war
COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises | Mandiant https://www.mandiant.com/resources/blog/cosmicenergy-ot-malware-russian-response
25/05/2023 20:17:56
QRCode
archive.org
thumbnail

Mandiant identified novel operational technology (OT) / industrial control system (ICS)-oriented malware, which we track as COSMICENERGY, uploaded to a public malware scanning utility in December 2021 by a submitter in Russia. The malware is designed to cause electric power disruption by interacting with IEC 60870-5-104 (IEC-104) devices, such as remote terminal units (RTUs), that are commonly leveraged in electric transmission and distribution operations in Europe, the Middle East, and Asia.

mandiant EN 2023 COSMICENERGY Malware ICS (ICS)-oriented
Barracuda email security appliances hacked via zero-day vulnerability (CVE-2023-2868) - Help Net Security https://www.helpnetsecurity.com/2023/05/25/cve-2023-2868/
25/05/2023 12:01:27
QRCode
archive.org
thumbnail

A vulnerability (CVE-2023-2868) in Barracuda Networks' ESG appliances is actively exploited by attackers, the company has warned.

helpnetsecurity EN 2023 CVE-2023-2868 Barracuda 0-day
Analysis of new active malware: MediaArena – PUA https://northwave-cybersecurity.com/threat-intel-research/analysis-of-new-active-malware-mediaarena-pua
25/05/2023 11:19:40
QRCode
archive.org

Analysis of new active malware: MediaArena – PUA

northwave-cybersecurity EN 2023 PUA MediaArena infostealer
Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations https://www.secureworks.com/blog/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations
25/05/2023 11:12:22
QRCode
archive.org
thumbnail

Learn how the U.S. National Security Agency (NSA) issued a joint cybersecurity advisory highlighting a cluster of activity it attributes to a People’s Republic of China (PRC) state-sponsored threat group.

secureworks EN 2023 NSA US China Bronze-Silhouette Volt-Typhoon
Free VPN Service SuperVPN Exposes 360 Million User Records https://www.hackread.com/free-vpn-service-supervpn-leaks-user-records/
25/05/2023 08:21:34
QRCode
archive.org
thumbnail

This time, SuperVPN has exposed a whopping 133 GB of data, including personal details of its unsuspecting users, such as IP addresses.

hackeread EN 2023 SuperVPN DataLeak IP
Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign https://www.wordfence.com/blog/2023/05/wordfence-firewall-blocks-bizarre-large-scale-xss-campaign/
25/05/2023 08:17:20
QRCode
archive.org
thumbnail

The Wordfence Threat Intelligence team has been monitoring an increase in attacks targeting a Cross-Site Scripting vulnerability in Beautiful Cookie Consent Banner, a WordPress plugin installed on over 40,000 sites. The vulnerability, which was fully patched in January in version 2.10.2, offers unauthenticated attackers the ability to add malicious JavaScript to a website, potentially allowing ...Read More

wordfence EN 2023 Beautiful-Cookie-Consent-Banner plugin WordPress XSS Campaign
Barracuda identified a vulnerability (CVE-2023-2868) in our Email Security Gateway appliance (ESG) on May 19, 2023. https://status.barracuda.com/incidents/34kx82j5n4q9
25/05/2023 08:11:36
QRCode
archive.org
thumbnail

Barracuda Networks's Status Page - Barracuda identified a vulnerability (CVE-2023-2868) in our Email Security Gateway appliance (ESG) on May 19, 2023..

Barracuda EN 2023 Status CVE-2023-2868 ESG Email Security Gateway appliance
Volt Typhoon targets US critical infrastructure with living-off-the-land techniques https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
25/05/2023 08:04:59
QRCode
archive.org
thumbnail

Chinese state-sponsored actor Volt Typhoon is using stealthy techniques to target US critical infrastructure, conduct espionage, and dwell in compromised environments.

microsoft EN 2023 Critical-infrastructure Volt-Typhoon stealthy China US espionage living-off-the-land
Malvertising via brand impersonation is back again https://www.malwarebytes.com/blog/threat-intelligence/2023/05/malvertising-its-a-jungle-out-there
24/05/2023 21:36:54
QRCode
archive.org
thumbnail

Web search is about to embark on a new journey thanks to artificial intelligence technology that online giants such as Microsoft and Google are experimenting with. Yet, there is a problem when it comes to malicious ads displayed by search engines that AI likely won't be able to fix.

malwarebytes EN 2023 brand impersonation GoogleAds
German arms company Rheinmetall confirms Black Basta ransomware group behind cyberattack https://therecord.media/rheinmetall-confirms-black-basta-ransomware-group-behind-cyberattack
24/05/2023 18:04:05
QRCode
archive.org
thumbnail

Rheinmetall confirmed on Monday that the Black Basta ransomware group was behind a cyberattack it detected last month.

therecord EN 2023 Rheinmetall ransomware BlackBasta
IT employee impersonates ransomware gang to extort employer https://www.bleepingcomputer.com/news/security/it-employee-impersonates-ransomware-gang-to-extort-employer/
24/05/2023 17:01:28
QRCode
archive.org
thumbnail

A 28-year-old United Kingdom man from Fleetwood, Hertfordshire, has been convicted of unauthorized computer access with criminal intent and blackmailing his employer.

bleepingcomputer EN 2023 Court-Case UK Employee Insider-Threat Legal Police Ransomware Rogue
ChatGPT Plugins: Data Exfiltration via Images & Cross Plugin Request Forgery https://embracethered.com/blog/posts/2023/chatgpt-webpilot-data-exfil-via-markdown-injection/
23/05/2023 22:30:12
QRCode
archive.org

Plugins can return malicious content and hijack your AI.

embracethered EN 2023 ChatGPT Data Exfiltration Cross Plugin Request Forgery
Apple fixes three new zero-days exploited to hack iPhones, Macs https://www.bleepingcomputer.com/news/apple/apple-fixes-three-new-zero-days-exploited-to-hack-iphones-macs/
23/05/2023 22:24:42
QRCode
archive.org
thumbnail

Apple has addressed three new zero-day vulnerabilities exploited in attacks to hack into iPhones, Macs, and iPads.

bleepingcomputer EN 2023 Apple iOS iPhone Mac macOS WebKit Zero-Day
File Archiver In The Browser https://mrd0x.com/file-archiver-in-the-browser/?no-cache=1
23/05/2023 22:05:36
QRCode
archive.org

This article explores a phishing technique that emulates a file archiver software in the browser while using a .zip domain.

mrd0x EN 2023 tld domain phishing technique
What if we had the SockPuppet vulnerability in iOS 16? https://security.apple.com/blog/what-if-we-had-sockpuppet-in-ios16/
23/05/2023 21:48:17
QRCode
archive.org

The next post in our XNU memory safety series examines how our hardened kernel allocator performs in the real world against a previously patched but powerful UAF software vulnerability. In this detailed analysis, we find out what might happen if SockPuppet were to meet kalloc_type in iOS 16.

security.apple EN 2023 SockPuppet iOS research
page 147 / 207
4721 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio