Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 16 / 59
1170 résultats taggé 2023  ✕
FakeUpdateRU Chrome Update Infection Spreads Trojan Malware https://blog.sucuri.net/2023/10/fakeupdateru-chrome-update-infection-spreads-trojan-malware.html
30/10/2023 19:07:05
QRCode
archive.org
thumbnail

Learn about the fake Google Chrome update malware, a common form of website malware that tricks users into downloading a remote access trojan disguised as a browser update. Understand how it works, its impact on websites, and how to protect your site from such threats. Stay updated on the latest malware trends with Sucuri.

sucuri EN 2023 Google Chrome update malware fake analysis
3 new NGINX ingress controller Kubernetes related vulnerabilities https://www.armosec.io/blog/cve-2023-5043-nginx-ingress/
30/10/2023 15:13:48
QRCode
archive.org
thumbnail

CVE-2023-5043, CVE-2023-5044 and CVE-2022-4886 can be exploited by attacker to steal secret credentials from the cluster. Read all about it!

armosec EN 2023 ingress NGINX Kubernetes CVE-2023-5043 CVE-2023-5044 CVE-2022-4886
Introducing HAR Sanitizer: secure HAR sharing https://blog.cloudflare.com/introducing-har-sanitizer-secure-har-sharing/
29/10/2023 11:52:06
QRCode
archive.org
thumbnail

As a follow-up to the most recent Okta breach, we are making a HAR file sanitizer available to everyone, not just Cloudflare customers, at no cost.

cloudflare EN 2023 HAR Sanitizer Okta tool
HackerOne paid ethical hackers over $300 million in bug bounties https://www.bleepingcomputer.com/news/security/hackerone-paid-ethical-hackers-over-300-million-in-bug-bounties/
28/10/2023 23:07:20
QRCode
archive.org
thumbnail

HackerOne has announced that its bug bounty programs have awarded over $300 million in rewards to ethical hackers and vulnerability researchers since the platform's inception.

bleepingcomputer EN 2023 Bug-Bounty Ethical-Hacking HackerOne Vulnerability Vulnerability-Disclosure-Program Vulnerability-Rewards-Program White-Hat-Hacker
Turning a boring file move into a privilege escalation on Mac | pwn.win https://pwn.win/2023/10/28/file-move-privesc-mac.html
28/10/2023 13:36:10
QRCode
archive.org

While poking around Parallels Desktop I found a script which is invoked by a setuid-root binary, which has the following snippet: local prl_dir="${usr_home}/Library/Parallels" if [ -e "$prl_dir" -a ! -d "$prl_dir" ]; then log warning "'${prl_dir}' is not a directory. Renaming it." mv -f "$prl_dir"{,~} continue fi Here ${usr_home} represents the home directory of the user for which Parallels Desktop is installed. The code says if ~/Library/Parallels exists and is not a directory then move it to ~/Library/Parallels~, presumably to back it up before creating this path as a directory.

pwn.win EN 2023 Parallels Desktop privesc
SIM Swappers Are Working Directly with Ransomware Gangs Now https://www.404media.co/sim-swappers-are-working-directly-with-ransomware-gangs-now/
27/10/2023 13:54:34
QRCode
archive.org
thumbnail

Hackers connected to “the Comm,” a nebulous group that includes SIM swappers, are working with ALPHV, a ransomware group that has impacted some of the biggest companies on the planet, including MGM Casinos.

404media EN 2023 ALPHV the-Comm SIMSwappers ransomware
CVE-2023-45498: RCE in VinChin Backup https://blog.leakix.net/2023/10/vinchin-backup-rce-chain/
27/10/2023 13:47:49
QRCode
archive.org
thumbnail

CVE-2023-45498/CVE-2023-45499 advisory

leakix EN 2023 advisory RCE VinChin Backup CVE-2023-45498 CVE-2023-4549
CCleaner confirms data breach via MOVEit attack https://cybernews.com/news/ccleaner-confirms-data-breach/
27/10/2023 08:58:56
QRCode
archive.org

CCleaner, a popular software for cleaning files and Windows Registry entries, has confirmed that attackers accessed some of its customer data.

cybernews EN 2023 MOVEit CCleaner
A cascade of compromise: unveiling Lazarus' new campaign https://securelist.com/unveiling-lazarus-new-campaign/110888/
27/10/2023 08:48:29
QRCode
archive.org
thumbnail

We unveil a Lazarus campaign exploiting security company products and examine its intricate connections with other campaigns

securelist EN 2023 Backdoor Lazarus Malware-Descriptions SIGNBT
Hyundai to hold software-upgrade clinics across the US for vehicles targeted by thieves | AP News https://apnews.com/article/hyundai-kia-theft-software-upgrade-b0ce0c9ccf816ced5df68458ea5ab071
27/10/2023 08:25:07
QRCode
archive.org
thumbnail

Hyundai says it will set up “mobile clinics” at five U.S. locations to provide anti-theft software upgrades for vehicles now regularly targeted by thieves using a technique popularized on TikTok and other social platforms.

apnews EN US 2023 Hyundai anti-theft software upgrade TikTok
Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers https://www.welivesecurity.com/en/eset-research/winter-vivern-exploits-zero-day-vulnerability-roundcube-webmail-servers/
27/10/2023 08:24:41
QRCode
archive.org

ESET Research discover campaigns by the Winter Vivern APT group that exploit a zero-day XSS vulnerability in the Roundcube Webmail server and target governmental entities and a think tank in Europe.

welivesecurity ESET 2023 EN WinterVivern APT zero-day XSS vulnerability Roundcube
StripedFly: Perennially flying under the radar https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/
26/10/2023 23:06:55
QRCode
archive.org
thumbnail

Nobody would even suspect the mining malware was merely a mask, masquerading behind an intricate modular framework that supports both Linux and Windows. The amount of effort that went into creating the framework is truly remarkable, and its disclosure was quite astonishing.

securelist EN 2023 stripedfly NSA Data-theft Encryption EternalBlue Linux Malware-Descriptions Malware-Technologies Miner Targeted-attacks TOR
Triangulation: validators, post-compromise activity and modules | Securelist https://securelist.com/triangulation-validators-modules/110847/
26/10/2023 17:49:57
QRCode
archive.org
thumbnail

In this report Kaspersky shares insights into the validation components used in Operation Triangulation, TriangleDB implant post-compromise activity, as well as details of some additional modules.
#2023 #APT #Apple #EN #Malware #Malware-Description #Triangulation #analysis #iOS #macOS #securelist #spyware

EN macOS spyware Apple Malware-Description 2023 analysis APT iOS Triangulation securelist Malware
VMSA-2023-0023 https://www.vmware.com/security/advisories/VMSA-2023-0023.html
25/10/2023 23:47:03
QRCode
archive.org
thumbnail

VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities

vmware EN 2023 vulnerability VMSA-2023-0023 CVE-2023-34048 advisory
iLeakage https://ileakage.com/
25/10/2023 23:45:04
QRCode
archive.org

We present iLeakage, a transient execution side channel targeting the Safari web browser present on Macs, iPads and iPhones. iLeakage shows that the Spectre attack is still relevant and exploitable, even after nearly 6 years of effort to mitigate it since its discovery. We show how an attacker can induce Safari to render an arbitrary webpage, subsequently recovering sensitive information present within it using speculative execution. In particular, we demonstrate how Safari allows a malicious webpage to recover secrets from popular high-value targets, such as Gmail inbox content. Finally, we demonstrate the recovery of passwords, in case these are autofilled by credential managers.

ileakage EN 2023 macos Safari Side-Channel ios Spectre speculative
Hackers can force iOS and macOS browsers to divulge passwords and much more https://arstechnica.com/security/2023/10/hackers-can-force-ios-and-macos-browsers-to-divulge-passwords-and-a-whole-lot-more/
25/10/2023 20:34:57
QRCode
archive.org
thumbnail

iLeakage is practical and requires minimal resources. A patch isn't (yet) available.

arstechnica EN 2023 ileakage macos ios speculative
Partout, les passkeys remplacent les mots de passe. Au tour des entreprises? https://www.ictjournal.ch/articles/2023-10-25/partout-les-passkeys-remplacent-les-mots-de-passe-au-tour-des-entreprises
25/10/2023 17:37:55
QRCode
archive.org
thumbnail

Apple, Microsoft, Google, Amazon, les géants de la technologie adoptent tous les passkeys comme alternative aux mots de passe. Le système a aussi de quoi séduire les entreprises, tant pour sa sécurité que pour sa simplicité, gage de moins d’appels au support technique pour réinitialiser un mot de passe.

ictjournal FR 2023 passkeys entreprises
Citrix warns admins to patch NetScaler CVE-2023-4966 bug immediately https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-netscaler-cve-2023-4966-bug-immediately/
25/10/2023 08:00:52
QRCode
archive.org
thumbnail

Citrix warned admins today to secure all NetScaler ADC and Gateway appliances immediately against ongoing attacks exploiting the CVE-2023-4966 vulnerability.

bleepingcomputer EN 2023 Citrix Netscaler Warning CVE-2023-4966 ADC GAteway
CVE-2023-4966: NetScaler Critical Security Update Now Available https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/
25/10/2023 07:57:47
QRCode
archive.org
thumbnail

CVE-2023-4966 affects NetScaler ADC and NetScaler Gateway and, if exploited, could result in unauthorized data disclosure. Learn more.

NetScaler EN 2023 CVE-2023-4966 ADC
Battling a new DarkGate malware campaign with Malwarebytes MDR https://www.malwarebytes.com/blog/business/2023/10/on-the-frontlines-battling-an-in-the-wild-darkgate-infection-with-malwarebytes-mdr
24/10/2023 19:33:26
QRCode
archive.org
thumbnail

First publicly reported in 2018, DarkGate is a Windows-based malware with a wide-range of capabilities including credential stealing and remote access to victim endpoints. Until recently, it was only seen being delivered through traditional email malspam campaigns. In late August 2023, however, researchers at Trusec found evidence of a campaign using external Teams messages to deliver the DarkGate Loader.

malwarebytes EN 2023 DarkGate malware
page 16 / 59
4837 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn