Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 150 / 237
GitLab addressed critical vulnerability CVE-2023-5009 https://securityaffairs.com/151107/security/gitlab-critical-vulnerability-cve-2023-5009.html?amp=1
20/09/2023 11:05:52
QRCode
archive.org
thumbnail

GitLab rolled out security patches to address a critical flaw (CVE-2023-5009) that can be exploited to run pipelines as another user.

Trend Micro addresses actively exploited zero-day in Apex One https://securityaffairs.com/151095/hacking/trend-micro-apex-one-zero-day-flaw.html?amp=1
20/09/2023 07:23:24
QRCode
archive.org
thumbnail
[CVE-2023-42752] integer overflow in Linux kernel leading to exploitable memory access https://seclists.org/oss-sec/2023/q3/192
19/09/2023 21:02:46
QRCode
archive.org
thumbnail

I recently found an integer overflow in the Linux kernel, which leads
to the kernel allocating skb_shared_info in the userspace, which is
exploitable in systems without SMAP protection since skb_shared_info
contains references to function pointers.

seclists EN 2023 CVE-2023-42752 integer overflow Linux kernel
Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/
19/09/2023 20:59:11
QRCode
archive.org
thumbnail

A phony proof-of-concept (PoC) code for CVE-2023-40477 delivered a payload of VenomRAT. We detail our findings, including an analysis of the malicious code.

unit42 EN 2023 PoC fake CVE-2023-40477 VenomRAT malicious
38TB of data accidentally exposed by Microsoft AI researchers | Wiz Blog https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers
19/09/2023 16:30:43
QRCode
archive.org
thumbnail

Wiz Research found a data exposure incident on Microsoft’s AI GitHub repository, including over 30,000 internal Microsoft Teams messages – all caused by one misconfigured SAS token

wiz EN 2023 GitHub Microsoft leak
Leaked Microsoft documents hint at new Doom and Dishonored games https://www.engadget.com/leaked-microsoft-documents-hint-at-new-doom-and-dishonored-games-122130396.html
19/09/2023 16:07:13
QRCode
archive.org
thumbnail

Bethesda's roadmap for the fiscal years starting in 2020 and ending in 2024 has made its way online as part of the documents leaked from the FTC v. Microsoft case.

engadget EN 2023 Bethesda Microsoft Microsoft-Gaming Leak Unredacted
Microsoft AI Employee Accidentally Leaks 38TB of Data https://www.pcmag.com/news/microsoft-ai-employee-accidentally-leaks-38tb-of-data
18/09/2023 20:01:03
QRCode
archive.org
thumbnail

A software repository on GitHub dedicated to supplying open-source code and AI models for image recognition was left open to manipulation by bad actors thanks to an insecure URL.

pcmag EN 2023 DataLeak GitHub Microsoft 38TB
New Python NodeStealer Goes Beyond Facebook Credentials, Now Stealing All Browser Cookies and Login Credentials https://www.netskope.com/blog/new-python-nodestealer-goes-beyond-facebook-credentials-now-stealing-all-browser-cookies-and-login-credentials
18/09/2023 11:48:47
QRCode
archive.org
thumbnail

Netskope Threat Labs is tracking a campaign that uses malicious Python scripts to steal Facebook users’ credentials and browser data. This campaign targets Facebook business accounts with bogus Facebook messages with a malicious file attached. The attacks are reaching victims mainly in Southern Europe and North America across different segments, led by the manufacturing services and technology sectors.

netskope EN 2023 analysis Python NodeStealer Facebook Credentials Login Credentials
BlackCat ransomware hits Azure Storage with Sphynx encryptor https://www.bleepingcomputer.com/news/security/blackcat-ransomware-hits-azure-storage-with-sphynx-encryptor/
17/09/2023 15:32:31
QRCode
archive.org
thumbnail

The BlackCat (ALPHV) ransomware gang now uses stolen Microsoft accounts and the recently spotted Sphynx encryptor to encrypt targets' Azure cloud storage.

bleepingcomputer EN 2023 BlackCat ALPHV Sphynx encryptor Azure
Ransomware flingers hit Manchester cops in the supply chain • The Register https://www.theregister.com/2023/09/15/greater_manchester_police_breach_demonstrates/
17/09/2023 15:27:24
QRCode
archive.org
thumbnail

The UK's Greater Manchester Police (GMP) has admitted that crooks have got their mitts on some of its data after a third-party supplier responsible for ID badges was attacked.

According to the Manchester Evening News the stolen data included the names and pictures of police officers held by the supplier for use on thousands of ID badges.

theregister EN 2023 Greater-Manchester-Police databreach ransomware police UK
TikTok fined €345M by Irish DPC for violating children’s privacy https://securityaffairs.com/150918/breaking-news/tiktok-fined-e345m-irish-dpc.html
17/09/2023 11:29:10
QRCode
archive.org
thumbnail

The Irish Data Protection Commission (DPC) fined TikTok €345 million ($368 million) for violating the privacy of children.

securityaffairs EN 2023 TikTok fines Ireland privacy DPC childrens
When MFA isn't actually MFA https://retool.com/blog/mfa-isnt-mfa/
16/09/2023 12:22:57
QRCode
archive.org
thumbnail

Due to a recent Google change, MFA isn't truly MFA.

retool EN 2023 incident retool MFA SMS-based phishing attack GoogleAuthenticator
How Google Authenticator made one company’s network breach much, much worse https://arstechnica.com/security/2023/09/how-google-authenticator-gave-attackers-one-companys-keys-to-the-kingdom
16/09/2023 12:21:15
QRCode
archive.org
thumbnail

Google's app for generating MFA codes syncs to user accounts by default. Who knew?

arstechnica EN 2023 MFA GoogleAuthenticator
Can't Be Contained: Finding a Command Injection Vulnerability in Kubernetes https://www.akamai.com/blog/security-research/kubernetes-critical-vulnerability-command-injection
15/09/2023 16:34:42
QRCode
archive.org
thumbnail

Akamai researchers discover a critical vulnerability in Kubernetes that can lead to remote code execution.

akamai EN 2023 Kubernetes command-injection vulnerability YAML rce remote-code-execution
Update Adobe Acrobat and Reader to Patch Actively Exploited Vulnerability https://thehackernews.com/2023/09/update-adobe-acrobat-and-reader-to.html
14/09/2023 22:37:37
QRCode
archive.org
thumbnail

Adobe's September 2023 update addresses a new zero-day vulnerability (CVE-2023-26369) in Acrobat and Reader that attackers are exploiting in the wild.

TheHackersNews 2023 EN Adobe Acrobat CVE-2023-26369
Argent russe: la place financière suisse rattrapée par une fuite de données https://www.rts.ch/info/economie/14313737-argent-russe-la-place-financiere-suisse-rattrapee-par-une-fuite-de-donnees.html
14/09/2023 14:58:16
QRCode
archive.org
thumbnail

Un ancien ministre de Vladimir Poutine et la famille du patron d'une entreprise publique russe, impliquée dans l'effort de guerre, se retrouvent dans les données inédites repérées par la RTS. Des liens avec la place financière suisse sont mis en lumière.
Ces révélations proviennent des documents confidentiels de la société de gestion de fortune zurichoise Finaport. Tout commence en janvier 2023 lorsque l'entreprise, sponsor officiel de l'Open de tennis de Zoug, est victime d'un piratage, comme le révélait le site Watson.

rts FR CH 2023 Russie Argent exfiltration journalisme enquête Finaport
macOS MetaStealer | New Family of Obfuscated Go Infostealers Spread in Targeted Attacks https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/
14/09/2023 14:48:30
QRCode
archive.org
thumbnail

The rise of macOS infostealers continues with the latest entrant aiming to compromise business environments with targeted social engineering lures.

sentinelone EN 2023 macOS infostealer MetaStealer
CVE-2023-38146: Arbitrary Code Execution via Windows Themes https://exploits.forsale/themebleed/
14/09/2023 12:31:15
QRCode
archive.org

This is a fun bug I found while poking around at weird Windows file formats. It's a kind of classic Windows style vulnerability featuring broken signing, sketchy DLL loads, file races, cab files, and Mark-of-the-Web silliness. It was also my first experience submitting to the MSRC Windows bug bounty since leaving Microsoft in April of 2022.

exploits.forsale EN 2023 CVE-2023-38146 Arbitrary Code Execution themebleed Windows Themes
Trojanized Free Download Manager found to contain a Linux backdoor https://securelist.com/backdoored-free-download-manager-linux-malware/110465/
14/09/2023 12:20:50
QRCode
archive.org
thumbnail

Kaspersky researchers analyzed a Linux backdoor disguised as Free Download Manager software that remained under the radar for at least three years.

securelist EN 2023 Backdoor Linux Malware Supply-chain-attack Download-Manager
Threat actor leaks sensitive data belonging to Airbus https://securityaffairs.com/150794/data-breach/airbus-investigates-data-leak.html?amp=1
14/09/2023 07:19:41
QRCode
archive.org
thumbnail

The multinational aerospace corporation Airbus has launched an investigation into the recent leak of information allegedly stolen from the company.
The multinational aerospace corporation Airbus announced that it is investigating a data leak after cybersecurity firm Hudson Rock reported that a hacker posted information on thousands of the company’s vendors to the dark web.

securityaffairs EN 2023 Airbus leak databreach
page 150 / 237
4727 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio