Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 148 / 237
23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews https://www.wired.com/story/23andme-credential-stuffing-data-stolen/
09/10/2023 06:49:57
QRCode
archive.org
thumbnail

At least a million data points from 23andMe accounts appear to have been exposed on BreachForums. While the scale of the campaign is unknown, 23andMe says it's working to verify the data.

wired EN 2023 23andme genetics security Ashkenazi Jews
90s Vulns In 90s Software (Exim) - Is the Sky Falling? https://labs.watchtowr.com/exim-0days-90s-vulns-in-90s-software/
08/10/2023 18:23:35
QRCode
archive.org
thumbnail

A few days ago, ZDI went public with no less than six 0days in the popular mail server Exim. Ranging from ‘potentially world-ending' through to ‘a bit of a damp squib’, these bugs were apparently discovered way back in June 2022 (!) - but naturally got caught up in the void between the ZDI and Exim for quite some time. Mysterious void.

labs.watchtowr EN 2023 Exim analysis CVE-2023-42115
Rules of engagement issued to hacktivists after chaos https://www.bbc.com/news/technology-66998064
08/10/2023 18:18:39
QRCode
archive.org
thumbnail

The Red Cross writes rules of engagement for civilian hackers as numbers rise

BBC 2023 EN rules engagement civilians CRC hackers red-cross
Android TV Boxes Infected with Backdoors, Compromising Home Networks https://www.hackread.com/android-tv-boxes-backdoors-home-networks/
08/10/2023 15:51:31
QRCode
archive.org
thumbnail
  • Cybersecurity Firm Human Security has discovered malware on dozens of streaming devices and iOS/Android apps.
  • A huge number of Android TV boxes contain malware capable of conducting ad fraud, creating fake accounts, and selling access to home networks.
  • Researchers found that the malware they have dubbed Badbox is not only tricky to detect but difficult to remove as well.
  • Android TV box users must prefer installing apps from reliable sources and keep their devices up-to-date.
  • Human Security has already shared details of its findings with concerned law enforcement agencies.
hackread EN 2023 Human-Security AndroidTV box malware Badbox
X-Force uncovers global NetScaler Gateway credential harvesting campaign https://securityintelligence.com/posts/x-force-uncovers-global-netscaler-gateway-credential-harvesting-campaign/
08/10/2023 13:16:54
QRCode
archive.org
thumbnail

In September of 2023, X-Force uncovered a campaign where attackers were exploiting the vulnerability identified in CVE-2023-3519 to attack unpatched NetScaler Gateways to insert a malicious script into the HTML content of the authentication web page to capture user credentials. The campaign is another example of increased interest from cyber criminals in credentials. The 2023 X-Force cloud threat report found that 67% of cloud-related incident response engagements were associated with the use of stolen credentials.

securityintelligence EN 2023 NetScaler Gateway CVE-2023-3519 credential harvesting campaign
n their push for AI-generated content, tech companies are dancing on the edge between fucking around and finding out. https://www.vice.com/en/article/88xdez/generative-ai-is-a-disaster-and-companies-dont-seem-to-really-care
08/10/2023 12:58:58
QRCode
archive.org
thumbnail

Tech companies continue to insist that AI-generated content is the future as they release more trendy chatbots and image-generating tools. But despite reassurances that these systems will have robust safeguards against misuse, the screenshots speak for themselves.

vice 2023 EN AI-generated safeguards misuse AI
Google Online Security Blog: Expanding our exploit reward program to Chrome and Cloud https://security.googleblog.com/2023/10/expanding-our-exploit-reward-program-to.html?m=1
08/10/2023 11:35:26
QRCode
archive.org

In 2020, we launched a novel format for our vulnerability reward program (VRP) with the kCTF VRP and its continuation kernelCTF. For the first time, security researchers could get bounties for n-day exploits even if they didn’t find the vulnerability themselves. This format proved valuable in improving our understanding of the most widely exploited parts of the linux kernel. Its success motivated us to expand it to new areas and we're now excited to announce that we're extending it to two new targets: v8CTF and kvmCTF.

googleblog EN 2023 exploit reward program bugbounty
Genetics firm 23andMe says user data stolen in credential stuffing attack https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/
07/10/2023 09:44:05
QRCode
archive.org
thumbnail

23andMe has confirmed to BleepingComputer that it is aware of user data from its platform circulating on hacker forums and attributes the leak to a credential-stuffing attack.

bleepingcomputer EN 2023 23andMe credential-stuffing leak databreach genetics
Mirai Botnet's New Wave: hailBot,kiraiBot, catDDoS, and Their Fierce Onslaught - NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks. https://nsfocusglobal.com/mirai-botnets-new-wave-hailbot-kiraibot-catddos-and-their-fierce-onslaught/
07/10/2023 01:20:26
QRCode
archive.org
thumbnail

Several new Mirai variant families were widely deployed in September 2023, among which hailBot, kiraiBot and catDDoS are the most active.

nsfocusglobal EN 2023 analysis Mirai catDDoS hailBot kiraiBot
New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks https://www.securityweek.com/new-supermicro-bmc-vulnerabilities-could-expose-many-servers-to-remote-attacks/
05/10/2023 12:47:44
QRCode
archive.org
thumbnail

Supermicro has released BMC IPMI firmware updates to address multiple vulnerabilities impacting select motherboard models.

securityweek EN 2023 BMC Supermicro CVE-2023-40284 CVE-2023-40290
Binarly REsearch Uncovers Major Vulnerabilities in Supermicro BMCs https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html
05/10/2023 12:46:23
QRCode
archive.org
thumbnail

Behind the screens: An overview of hidden attack surfaces in powerful BMC chip infrastructure.

binarly EN 2023 BMC CVE-2023-40289 Supermicro
The evolutionary tale of a persistent Python threat  https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/
05/10/2023 12:41:52
QRCode
archive.org
thumbnail

Since early April 2023, an attacker has been relentlessly deploying hundreds of malicious packages through various usernames, accumulating nearly 75,000 downloads. Our team at Checkmarx’s Supply Chain Security has been on this malicious actor’s trail since early April, documenting each step of its evolution. We have been actively observing an attacker who seems to be evermore refining their craft. 

checkmarx EN 2023 Supply-chain-attack malicious packages Python
Ransomware Negotiation: Dos and Don’ts! https://www.neteye-blog.com/2023/09/ransomware-negotiation-dos-and-donts/
05/10/2023 12:07:19
QRCode
archive.org

Double extortion ransomware attacks have reached very high numerical values. One of the key elements, when suffering such an attack, concerns the negotiation that can be initiated (not always!) with the ransomware gang. The analysis, carried out by the SEC4U team, of hundreds of negotiations makes it possible to apply a scientific approach to this

neteye-blog EN 2023 ransomchats negotiation negotiator ransomware ransomware-double-extortion ransomware-negotiation blue-team sec4u
CVE: Zero-Day Privilege Escalation in Confluence Server & Data Center https://www.rapid7.com/blog/post/2023/10/04/etr-cve-2023-22515-zero-day-privilege-escalation-in-confluence-server-and-data-center/
04/10/2023 22:04:13
QRCode
archive.org
thumbnail

On 10/4/2023, Atlassian published a security advisory on CVE-2023-22515, a privilege escalation vulnerability affecting Confluence Server & Data Center.

rapid7 EN 2023 Atlassian Confluence cve-2023-22515 0-Day
Coop et Migros vendent des données clients à des entreprises tierces https://www.ictjournal.ch/news/2023-10-04/coop-et-migros-vendent-des-donnees-clients-a-des-entreprises-tierces
04/10/2023 18:34:01
QRCode
archive.org
thumbnail

Depuis un an, la chaîne de supermarchés Coop exploite une plateforme de données.

ictjournal FR 2023 CH privacy coop migros vente données
Sony confirms data breach impacting thousands in the U.S. https://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/#google_vignette
04/10/2023 16:50:10
QRCode
archive.org
thumbnail

Sony Interactive Entertainment (Sony) has notified current and former employees and their family members about a cybersecurity breach that exposed personal information.

bleepingcomputer EN 2023 Clop Data-Breach Data-Leak MOVEit MOVEit-Transfer Ransomware Sony Zero-Day
CVE-2023-4911: Looney Tunables - Local Privilege Escalation in the glibc’s ld.so https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so#potential-impact-of-looney-tunables
04/10/2023 09:33:44
QRCode
archive.org
thumbnail

The Qualys Threat Research Unit (TRU) has discovered a buffer overflow vulnerability in GNU C Library's dynamic loader's processing of the GLIBC_TUNABLES…

qualys EN 2023 GLIBC_TUNABLES CVE-2023-4911 buffer overflow vulnerability
Vulnerable Arm GPU drivers under active exploitation. Patches may not be available | Ars Technica https://arstechnica.com/security/2023/10/vulnerable-arm-gpu-drivers-under-active-exploitation-patches-may-not-be-available/?
03/10/2023 21:39:01
QRCode
archive.org
thumbnail

Vulnerability allows attackers to tamper with data stored in device memory.

arstechnica EN 2023 CVE-2023-4211Mali GPU ARM
Qualcomm says hackers exploit 3 zero-days in its GPU, DSP drivers https://www.bleepingcomputer.com/news/security/qualcomm-says-hackers-exploit-3-zero-days-in-its-gpu-dsp-drivers/
03/10/2023 17:31:45
QRCode
archive.org
thumbnail

Qualcomm is warning of three zero-day vulnerabilities in its GPU and Compute DSP drivers that hackers are actively exploiting in attacks.

bleepingcomputer EN 2023 Actively-Exploited Android Mobile Qualcomm Vulnerability Zero-Day GPU Adreno
Microsoft Defender Flags Tor Browser as a Trojan and Removes it from the System https://deform.co/microsoft-defender-flags-tor-browser-as-a-trojan-and-removes-it-from-the-system/
02/10/2023 21:00:20
QRCode
archive.org
thumbnail

Windows users have recently begun mass-reporting that Microsoft's Defender antivirus program, which is integrated into Windows 10 and 11 by default, is

deform EN 2023 TOR Browser Microsoft Defender antivirus
page 148 / 237
4727 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio