Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 150 / 207
4136 résultats taggé EN  ✕
Hunting Russian Intelligence “Snake” Malware https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a
10/05/2023 09:59:47
QRCode
archive.org

The Snake implant is considered the most sophisticated cyber espionage tool designed and used by Center 16 of Russia’s Federal Security Service (FSB) for long-term intelligence collection on sensitive targets. To conduct operations using this tool, the FSB created a covert peer-to-peer (P2P) network of numerous Snake-infected computers worldwide. Many systems in this P2P network serve as relay nodes which route disguised operational traffic to and from Snake implants on the FSB’s ultimate targets. Snake’s custom communications protocols employ encryption and fragmentation for confidentiality and are designed to hamper detection and collection efforts.

cisa EN 2023 Snake Malware Russia Intelligence FSB espionnage implant PERSEUS
Leaked Intel Boot Guard keys:What happened? How does it affect the software supply chain? https://binarly.io/posts/Leaked_Intel_Boot_Guard_keys_What_happened_How_does_it_affect_the_software_supply_chain/index.html
10/05/2023 09:44:06
QRCode
archive.org

Binarly is the world's most advanced automated firmware supply chain security platform. Using cutting-edge machine-learning techniques, Binary identifies both known and unknown vulnerabilities, misconfigurations, and malicious code in firmware and hardware components.

binarly EN 2023 MSI BootGuard Leaked Intel supplychain
Microsoft May 2023 Patch Tuesday https://isc.sans.edu/diary/Microsoft%20May%202023%20Patch%20Tuesday/29826
10/05/2023 09:42:53
QRCode
archive.org
thumbnail

This month we got patches for 49 vulnerabilities. Of these, 6 are critical, and 2 are already being exploited, according to Microsoft.

One of the exploited vulnerabilities is a Win32k Elevation of Privilege Vulnerability (CVE-2023-29336). This vulnerability has low attack complexity, low privilege, and none user interaction. The attack vector is local, the CVSS is 7.8, and the severity is Important.

sansedu EN 2023 May2023 vulnerabilities PatchTuesday
Microsoft Patch Tuesday, May 2023 Edition https://krebsonsecurity.com/2023/05/microsoft-patch-tuesday-may-2023-edition/
10/05/2023 09:40:56
QRCode
archive.org

Microsoft today released software updates to fix at least four dozen security holes in its Windows operating systems and other software, including patches for two zero-day vulnerabilities that are already being exploited in active attacks.

krebsonsecurity EN 2023 May2023 PatchTuesday
Apple Fails to Fully Reboot iOS Simulator Copyright Case https://news.bloomberglaw.com/ip-law/apple-fails-to-revive-copyright-case-over-iphone-ios-simulator
10/05/2023 09:39:09
QRCode
archive.org
thumbnail

Apple Inc. failed to fully revive a long-running copyright lawsuit against cybersecurity firm Corellium Inc. over its software that simulates the iPhone’s iOS operating systems, letting security researchers identify flaws in the software.

bloomberglaw EN 2023 Apple Corellium
oss-sec: [CVE-2023-32233] Linux kernel use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary reads and writes in kernel memory https://seclists.org/oss-sec/2023/q2/133
10/05/2023 08:23:43
QRCode
archive.org
thumbnail

An issue has been discovered in the Linux kernel that can be abused by
unprivileged local users to escalate privileges.

The issue is about Netfilter nf_tables accepting some invalid updates
to its configuration.

seclists.org EN 2023 CVE-2023-32233 Linux Kernel Netfilter nf_tables arbitrary memory vulnerability
‘PlugwalkJoe’ pleads guilty for the massive 2020 Twitter hack - The Verge https://www.theverge.com/2023/5/9/23717558/plugwalkjoe-pleads-guilty-twitter-hack-other-crimes-tiktok
10/05/2023 08:03:37
QRCode
archive.org
thumbnail

PlugwalkJoe, aka Joseph James O’Connor, a UK citizen connected to the 2020 Twitter hack affecting many high-profile accounts, including Elon Musk, Joe Biden, Barack Obama, and Apple, has pled guilty to cyberstalking and other crimes. On Tuesday, the Department of Justice (DOJ) announced that O’Connor has been extradited to the US.

theverge EN 2023 PlugwalkJoe Twitter hack Obama Apple extradited UK US
The Team of Sleuths Quietly Hunting Cyberattack-for-Hire Services https://www.wired.com/story/big-pipes-ddos-for-hire-fbi/
10/05/2023 08:02:57
QRCode
archive.org
thumbnail

For a decade, a group called Big Pipes has worked behind the scenes with the FBI to target the worst cybercriminal “booter” services plaguing the internet.

WHEN THE FBI announced the takedown of 13 cyberattack-for-hire services yesterday, it may have seemed like just another day in law enforcement’s cat-and-mouse game with a criminal industry that has long plagued the internet’s infrastructure, bombarding victims with relentless waves of junk internet traffic to knock them offline. In fact, it was the latest win for a discreet group of detectives that has quietly worked behind the scenes for nearly a decade with the goal of ending that plague for good.

wired EN 2023 cyberattack-for-hire busted FBI US BigPipes DDoS
On the trail of the Dark Avenger: the most dangerous virus writer in the world https://www.theguardian.com/news/2023/may/09/on-the-trail-of-the-dark-avenger-the-most-dangerous-virus-writer-in-the-world
09/05/2023 08:35:10
QRCode
archive.org
thumbnail

The long read: Bulgaria in the 1980s became known as the ‘virus factory’, where hundreds of malicious computer programs were unleashed to wreak havoc. But who was writing them, and why?

theguardian En 2023 history Virus Bulgaria DarkAvenger 1980 Viruses
CVE-2023-25394 - VideoStream Local Privilege Escalation https://danrevah.github.io/2023/05/03/CVE-2023-25394-VideoStream-LPE/
08/05/2023 15:05:55
QRCode
archive.org

Videostream is a user-friendly wireless application designed to stream videos, music, and images to Google Chromecast devices. Boasting simplicity and reliability, this app enables you to wirelessly play any local video file with a single click. Videostream even transcodes audio and video from incompatible files into Chromecast-supported formats.

With over 5 million installations, Videostream has made its mark in the streaming industry. This figure was obtained from their official website (https://getvideostream.com), while the Chrome app store lists 900,000+ users.

danrevah EN 2023 VideoStream LPE CVE-2023-25394 macOS
WordPress Advanced Custom Fields Pro plugin <= 6.1.5 - Reflected Cross Site Scripting (XSS) vulnerability https://patchstack.com/database/vulnerability/advanced-custom-fields-pro/wordpress-advanced-custom-fields-pro-plugin-6-1-5-reflected-cross-site-scripting-xss-vulnerability
08/05/2023 11:18:18
QRCode
archive.org
thumbnail

Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced Custom Fields PRO Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.1.6.

patchstack EN 2023 WP CVE-2023-30777 Advanced Custom Fields Pro plugin XSS vulnerability Wordpress plugin
Dump these Cisco phone adapters because it's not fixing them https://www.theregister.com/2023/05/05/cisco_phone_adapter_vulnerabilitty/
08/05/2023 07:16:38
QRCode
archive.org
thumbnail

There is a critical security flaw in a Cisco phone adapter, and the business technology giant says the only step to take is dumping the hardware and migrating to new kit.

In an advisory, Cisco this week warned about the vulnerability in the SPA112 2-Port Adapter that, if exploited, could allow a remote attacker to essentially take control of a compromised device by seizing full privileges and executing arbitrary code.

The flaw, tracked as CVE-2023-20126, is rated as "critical," with a base score o

theregister EN 2023 Cisco CVE-2023-20126 SPA112 2-Port phone adaptor
TikTok spied on me. Why? https://archive.is/gn0r0#selection-2023.0-2027.169
08/05/2023 07:06:39
QRCode
archive.org

One evening in late December last year, I received a cryptic phone call from a PR director at TikTok, the popular social media app. I’d written extensively about the company for the Financial Times, so we’d spoken before. But it was puzzling to hear from her just before the holidays, especially since I wasn’t working on anything related to the company at the time.

Financial-Times EN 2023 TikTok spy journalist
MSI Breach Leaks Intel BootGuard & OEM Image Signing Keys, Compromises Security of Over 200 Devices & Major Vendors https://wccftech.com/msi-breach-leaks-intel-bootguard-oem-image-signing-keys-compromises-security-of-over-200-devices-major-vendors/
07/05/2023 13:36:39
QRCode
archive.org
thumbnail

A recent breach in MSI's servers exposed Intel's BootGuard keys and has now put the security of various devices at risk.

Major MSI Breach Affects The Security of Various Intel Devices
Last month, a hacker group by the name of Money Message revealed that they had breached MSI's servers and stolen 1.5 TBs of data from the company's servers including source code amongst a list of various files that are important to the integrity of the company. The group asked MSI to pay $4.0 million in ransom to avert them from releasing the files to the public but MSI refused the payment.

wccftech EN 2023 MSI leak Intel BootGuard OEM Image Signing Keys
OpenAI’s regulatory troubles are just beginning https://www.theverge.com/2023/5/5/23709833/openai-chatgpt-gdpr-ai-regulation-europe-eu-italy
06/05/2023 21:18:35
QRCode
archive.org
thumbnail

OpenAI managed to appease Italian data authorities and lift the country’s effective ban on ChatGPT last week, but its fight against European regulators is far from over. 

theverge EN 2023 OpenAI ChatGPT European GDPR
Who Gets the Algorithm? The Bigger TikTok Danger https://www.lawfareblog.com/who-gets-algorithm-bigger-tiktok-danger
06/05/2023 14:43:44
QRCode
archive.org
thumbnail

Controversy surrounding TikTok, the popular Chinese company-owned social media platform, has continued to give rise to impasse in recent weeks. Just days after the Biden administration issued a divestiture-or-ban ultimatum to the company and Beijing firmly opposed a forced sale, TikTok CEO Shou Zi Chew testified in Congress to try to save the app’s U.S. operations.

lawfareblog EN 2023 TikTok Algorithm Danger
Can Better Training Reduce the Success Rate of Phishing Attacks? https://www.lawfareblog.com/can-better-training-reduce-success-rate-phishing-attacks
06/05/2023 14:40:33
QRCode
archive.org
thumbnail

A review of Arun Vishwanath, “The Weakest Link: How to Diagnose, Detect, and Defend Users From Phishing Attacks” (MIT Press, 2022)

Many elements of the cyber threat landscape have changed significantly over the past two decades. For one, the number of attackers has grown dramatically, aided by the increasing availability of hacking tools and services as commodities for purchase in online marketplaces. The value of the losses cyber criminals have been able to inflict on their victims has also grown, though the dollar estimates vary widely in absolute terms. In recent years, the popularity of ransomware has increased substantially, prompting the Biden administration to initiate an ongoing diplomatic effort to foster cross-border efforts to curb this dangerous form of cyber-enabled extortion.

lawfareblog EN 2023 Phishing Training
From Campus Rape Cases to Child Abuse Reports, ‘Worst-Case’ Data Breach Rocks MN Schools https://www.the74million.org/article/from-campus-rape-cases-to-child-abuse-reports-worst-case-data-breach-rocks-mn-schools/
06/05/2023 14:38:10
QRCode
archive.org
thumbnail

It took two years of middle school girls accusing their Minneapolis English teacher of eyeballing their bodies in a “weird creepy way,” for district investigators to substantiate their complaints.

Their drawn-out response is revealed in confidential and highly sensitive Minneapolis Public Schools investigative records that are now readily available online — just one folder in a trove of tens of thousands of leaked files that outline campus rape cases, child abuse inquiries, student mental health crises and suspension reports.

the74million EN 2023 Schools Abuse Leak ransomware Medusa US Minneapolis Public
The malware threat landscape: NodeStealer, DuckTail, and more https://engineering.fb.com/2023/05/03/security/malware-nodestealer-ducktail/
05/05/2023 10:43:38
QRCode
archive.org
thumbnail

We’re sharing our latest research and analysis into malware campaigns that are targeting online businesses — including newer malware posing as AI tools.

meta EN 2023 NodeStealer DuckTail research analysis campaigns malware
Atomic Stealer | Threat Actor Spawns Second Variant of macOS Malware Sold on Telegram https://www.sentinelone.com/blog/atomic-stealer-threat-actor-spawns-second-variant-of-macos-malware-sold-on-telegram/
04/05/2023 21:16:28
QRCode
archive.org
thumbnail

A macOS infostealer being sold on Telegram, Atomic Stealer has a second variant that appears primed to target users directly on YouTube.

sentinelone EN 2023 macos infostealer Telegram Atomic-Stealer Malware YouTube
page 150 / 207
4722 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio