Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 157 / 220
4391 résultats taggé EN  ✕
Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
16/06/2023 00:57:42
QRCode
archive.org
thumbnail

Mandiant is investigating a Barracuda ESG appliance zero-day vulnerability being exploited in the wild.

mandiant EN 2023 Barracuda ESG Zero-Day CVE-2023-2868 China
Suspected LockBit ransomware affiliate arrested, charged in US https://www.bleepingcomputer.com/news/security/suspected-lockbit-ransomware-affiliate-arrested-charged-in-us/
15/06/2023 21:43:01
QRCode
archive.org
thumbnail

Russian national Ruslan Magomedovich Astamirov was arrested in Arizona and charged by the U.S. Justice Department for allegedly deploying LockBit ransomware on the networks of victims in the United States and abroad.

bleepingcomputer EN 2023 Affiliates LockBit Ransomware Security arrested
Fake Security Researcher GitHub Repositories Deliver Malicious Implant https://vulncheck.com/blog/fake-repos-deliver-malicious-implant
15/06/2023 21:39:46
QRCode
archive.org
thumbnail

VulnCheck discovers a network of fake security researcher accounts promoting hidden malware.

vulncheck EN 2023 fake researcher malware GitHub Repositories Implant
Ransomware gang lists first victims of MOVEit mass-hacks, including US banks and universities | TechCrunch https://techcrunch.com/2023/06/15/moveit-clop-mass-hacks-banks-universities/
15/06/2023 13:53:44
QRCode
archive.org
thumbnail

The hackers responsible for exploiting a flaw to target users of a popular file transfer tool has begun listing victims of the mass-attacks

techcrunch EN 2023 ransomware MOVEit cl0p victims
Microsoft Encrypted Restricted Permission Messages Deliver Phishing | Trustwave https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-encrypted-restricted-permission-messages-deliver-phishing/
15/06/2023 08:21:00
QRCode
archive.org
thumbnail

Over the past few days, we have seen phishing attacks that use a combination of compromised Microsoft 365 accounts and .rpmsg encrypted emails to deliver the phishing message.

trustwave EN 2023 Phishing Microsoft Email Microsoft-365 rpmsg encrypted M365
Cadet Blizzard emerges as a novel and distinct Russian threat actor | Microsoft Security Blog https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/
14/06/2023 22:05:17
QRCode
archive.org
thumbnail

Microsoft attributes several campaigns to a distinct Russian state-sponsored threat actor tracked as Cadet Blizzard (DEV-0586), including the WhisperGate destructive attack, Ukrainian website defacements, and the hack-and-leak front “Free Civilian”.

microsoft EN 2023 CadetBlizzard DEV-0586 Russia analysis
The Phantom Menace: Brute Ratel remains rare and targeted https://news.sophos.com/en-us/2023/05/18/the-phantom-menace-brute-ratel-remains-rare-and-targeted/
14/06/2023 21:42:55
QRCode
archive.org
thumbnail

The commercial attack tool’s use by bad actors has faded after an initial flurry, while Cobalt Strike remains the go-to post-exploitation tool for many.

sophos EN 2023 BruteRatel faded analysis
Switzerland under cyberattack https://www.helpnetsecurity.com/2023/06/14/swiss-government-ddos/
14/06/2023 14:11:04
QRCode
archive.org
thumbnail

The Swiss government is under DDoS attacks, but several ransomware gangs have also turned their sights on other Swiss organizations.

helpnetsecurity EN 2023 CH Swiss DDoS attacks ransomware russia-ukraine-war
Microsoft June 2023 Patch Tuesday fixes 78 flaws, 38 RCE bugs https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/
13/06/2023 19:31:28
QRCode
archive.org
thumbnail

Today is Microsoft's June 2023 Patch Tuesday, with security updates for 78 flaws, including 38 remote code execution vulnerabilities.

bleepingcomputer EN 2023 patch-tuesday June2023
Analysis of CVE-2023-27997 and Clarifications on Volt Typhoon Campaign https://www.fortinet.com/blog/psirt-blogs/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign
13/06/2023 07:31:34
QRCode
archive.org
thumbnail

Affected Platforms: FortiOS
Impacted Users: Targeted at government, manufacturing, and critical infrastructure
Impact: Data loss and OS and file corruption
Severity Level: Critical

Today, Fortinet published a CVSS Critical PSIRT Advisory (FG-IR-23-097 / CVE-2023-27997) along with several other SSL-VPN related fixes. This blog adds context to that advisory, providing our customers with additional details to help them make informed, risk-based decisions, and provides our perspective relative to recent events involving malicious actor activity.

fortinet EN 2023 patch CVE-2023-27997 analysis VoltTyphoon Clarifications
Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was https://labs.watchtowr.com/xortigate-or-cve-2023-27997/
13/06/2023 07:21:59
QRCode
archive.org
thumbnail

When Lexfo Security teased a critical pre-authentication RCE bug in FortiGate devices on Saturday 10th, many people speculated on the practical impact of the bug. Would this be a true, sky-is-falling level vulnerability like the recent CVE-2022-42475? Or was it some edge-case hole, requiring some unusual and exotic requisite before any exposure? Others even went further, questioning the legitimacy of the bug itself. Details were scarce and guesswork was rife.

labs.watchtowr EN 2023 Xortigate XOR RCE CVE-2023-27997 FortiGate analysis
CVE-2023-34362 https://attackerkb.com/topics/mXmV0YpC3W/cve-2023-34362/rapid7-analysis
12/06/2023 17:53:05
QRCode
archive.org
thumbnail

On May 31, 2023, Progress Software disclosed a critical SQL injection vulnerability that was later assigned CVE-2023-34362. Rapid7 has observed exploitation in…

attackerkb EN 2023 MOVEit CVE-2023-34362
How North Korea’s Hacker Army Stole $3 Billion in Crypto, Funding Nuclear Program https://archive.ph/4J5cE
12/06/2023 07:22:54
QRCode
archive.org
thumbnail

Regime has trained cybercriminals to impersonate tech workers or employers, amid other schemes

WSJ EN 2023 North-Korea crypto stolen Funding Nuclear
Shell Recharge security lapse exposed EV drivers’ data https://techcrunch.com/2023/06/09/shell-recharge-security-lapse-exposed-drivers-data/
12/06/2023 07:07:56
QRCode
archive.org
thumbnail

Oil giant Shell said it is investigating after a security researcher found an exposed internal database spilling the personal information of drivers who use the company’s electric vehicle charging stations.

techcrunch EN 2023 Leak Shell DataLeak database
Les CFF et le canton d'Argovie aussi concernés par la cyberattaque qui a touché la société Xplain https://www.rts.ch/info/suisse/14093302-les-cff-et-le-canton-d-argovie-aussi-concernes-par-la-cyberattaque-qui-a-touche-la-societe-xplain.html
11/06/2023 20:08:03
QRCode
archive.org
thumbnail

Les CFF et le canton d'Argovie sont à leur tour concernés par la cyberattaque qui a touché la société informatique bernoise Xplain. Des données ont été volées, ont indiqué l'entreprise ferroviaire et le canton.

Une fuite a entraîné le vol des données, ont confirmé dimanche les CFF, suite à un article de la NZZ am Sonntag. De leur côté, les autorités argoviennes font savoir qu'"un petit volume de données opérationnelles liées à des protocoles d'erreur qui étaient analysées chez Xplain" est concerné par la fuite, ainsi que "de la correspondance commerciale".

rts EN 2023 Xplain CFF Argovie
Cyber Extortion activity reached the highest volume ever recorded in Q1 2023 after a decline of 8% in 2022, reveals new Orange Cyberdefense report https://newsroom.orange.com/cyberextortion/?lang=en
11/06/2023 14:28:05
QRCode
archive.org
  • The shift previously observed in the geographical location of cyber extortion (Cy-X) victims continues to accelerate, moving from the United States (-21%), and Canada (-28%) to Southeast Asia region (+42%), the Nordics (+40%) & Latin America (+32%).
  • Whilst Manufacturing continues to be the biggest industry impacted, the number of victims decreased (-39%), with a shift towards the Utilities sector (+51%), Educational Services (+41%) and Finance and Insurance Sectors (+11%).
  • Businesses in 96 different countries were impacted by Cy-X in 2022, equating to nearly half (49%) the countries in the world. Since 2020 Orange Cyberdefense has recorded victims in over 70% of all countries worldwide
  • Over 2,100 organizations in the world were publicly shamed as a victim of Cy-X in 2022, across an almost even distribution of business sizes.
orange.com EN 2023 Cy-X CyberExtortion Orange Cyberdefense report
MOVEit Transfer and MOVEit Cloud Vulnerability https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability
11/06/2023 14:26:06
QRCode
archive.org
thumbnail

This page provides the latest information on the MOVEit Transfer and MOVEit Cloud vulnerabilities. As we continue our investigation and new details are uncovered, this page will be updated. Please check back frequently for updates.

CVE-PENDING (June 9, 2023)
CVE-2023-34362 (May 31, 2023)

progress.com EN 2023 CVE-2023-34362 MOVEit Cloud
Turkish Citizens' Personal Data Offered Online After Govt Site Hacked https://balkaninsight.com/2023/06/09/turkish-citizens-personal-data-offered-online-after-govt-site-hacked/
10/06/2023 11:39:53
QRCode
archive.org
thumbnail

In a major digital security breach, a website is offering personal data about Turkish citizens including President Recep Tayyip Erdogan that appears to have been stolen by hackers from a government services website.

balkaninsight EN 2023 PII databreach Turkey citizens Erdogan stolen
Pro-Ukraine hackers bring Russian banking system to its knees https://www.firstpost.com/world/pro-ukraine-hackers-bring-russian-banking-system-to-its-knees-12716002.html
09/06/2023 23:22:22
QRCode
archive.org
thumbnail

A team of hackers, hacked into several Russian businesses and the nation's largest ISP and service provider to the Central Bank of Russia. Because of the hack, the Russian banking system went down. The hackers also put up pro-Ukrainian posters on the hacked websites.

firstpost EN 2023 ISP Russian-banking-system central-bank-of-Russia russian-Infotel-JVC russia-ukraine-war
Another huge US medical data breach confirmed after Fortra mass-hack https://techcrunch.com/2023/06/09/intellihartx-data-breach-fortra-ransomware/?guccounter=1
09/06/2023 13:33:38
QRCode
archive.org
thumbnail

Hackers stole another half a million people’s personal and health information during a ransomware attack on a technology vendor earlier this year.

Intellihartx, a Tennessee-based company that handles patient payment balances and collections, said in a notice filed with the Maine attorney general’s office that 489,830 patients had information stolen in the cyberattack targeting its vendor, Fortra.

techcrunch EN 2023 Fortra Intellihartx PHI databreach
page 157 / 220
5001 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn