Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 166 / 237
Analysis of CVE-2023-29336 Win32k Privilege Escalation https://www.numencyber.com/cve-2023-29336-win32k-analysis/
08/06/2023 22:55:34
QRCode
archive.org
thumbnail

Analyzing CVE-2023-29336 Win32k vulnerability, its exploitation, and mitigation measures in the context of evolving security practices.

numencyber EN 2023 Analysis CVE-2023-29336 Win32k Privilege Escalation
Unmasking the Darkrace Ransomware Gang https://blog.cyble.com/2023/06/08/unmasking-the-darkrace-ransomware-gang/
08/06/2023 14:14:32
QRCode
archive.org
thumbnail

Cyble analyses Darkrace Ransomware, a new ransomware group shares similarities with infamous LockBit Ransomware.

cyble 2023 EN Darkrace Ransomware Gang
Le site web du parlement suisse attaqué par des hackers https://www.letemps.ch/economie/cyber/site-web-parlement-suisse-attaque-hackers
08/06/2023 11:57:21
QRCode
archive.org
thumbnail

Une cyberattaque paralyse en partie le site www.parlament.ch, une agression peut-être en lien avec la prochaine prise de parole du président ukrainien.

letemps FR CH 2023 Parlement cyberattaque DDoS parlament.ch
CVE-2023-34362: MOVEit Transfer SQL Injection Vulnerability Threat Brief https://unit42.paloaltonetworks.com/threat-brief-moveit-cve-2023-34362/
07/06/2023 20:25:16
QRCode
archive.org
thumbnail

On May 31, Progress Software posted a notification alerting customers of a critical Structured Query Language injection (SQLi) vulnerability (CVE-2023-34362) in their MOVEit Transfer product. MOVEit Transfer is a managed file transfer (MFT) application intended to provide secure collaboration and automated file transfers of sensitive data.

paloaltonetworks EN 2023 MOVEit SQL Injection Vulnerability CVE-2023-34362
ChatGPT creates mutating malware that evades detection by EDR https://www.csoonline.com/article/3698516/chatgpt-creates-mutating-malware-that-evades-detection-by-edr.html
07/06/2023 19:56:49
QRCode
archive.org
thumbnail

A global sensation since its initial release at the end of last year, ChatGPT's popularity among consumers and IT professionals alike has stirred up cybersecurity nightmares about how it can be used to exploit system vulnerabilities. A key problem, cybersecurity experts have demonstrated, is the ability of ChatGPT and other large language models (LLMs) to generate polymorphic, or mutating, code to evade endpoint detection and response (EDR) systems.

csoonline EN 2023 ChatGPT LLMs EDR BlackMamba
Service Rents Email Addresses for Account Signups https://krebsonsecurity.com/2023/06/service-rents-email-addresses-for-account-signups/
07/06/2023 12:57:56
QRCode
archive.org

One of the most expensive aspects of any cybercriminal operation is the time and effort it takes to create large numbers of new throwaway email accounts. Now a new service offers to help dramatically cut costs associated with large-scale spam…

krebsonsecurity EN 2023 Rents Email Addresses large-scale spam Quotpw Impulse-Team Scam-Doc[.]com
Mass exploitation of critical MOVEit flaw is ransacking orgs big and small | Ars Technica https://arstechnica.com/information-technology/2023/06/mass-exploitation-of-critical-moveit-flaw-is-ransacking-orgs-big-and-small/
07/06/2023 07:46:55
QRCode
archive.org
thumbnail

SQL injection attacks on MOVEit file-transfer service likely to get worse.

arstechnica EN 2023 CVE-2023-34362 MOVEit
Trustwave Action Response: Zero Day Exploitation of MOVEit (CVE-2023-34362) https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trustwave-action-response-zero-day-exploitation-of-moveit-cve-2023-34362/
06/06/2023 19:42:58
QRCode
archive.org
thumbnail

On May 31, threat actors were discovered targeting a critical zero day in MOVEit Transfer software resulting in escalated privileges and unauthorized data access. The vulnerability being exploited is an SQL injection and has since been patched. Resources links, including one for the patch, are at the bottom of this post.

trustwave EN 2023 0-day MOVEit CVE-2023-34362 analysis
GobRAT malware written in Go language targeting Linux routers https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
05/06/2023 21:54:15
QRCode
archive.org
thumbnail

JPCERT/CC has confirmed attacks that infected routers in Japan with malware around February 2023. This blog article explains the details of the attack confirmed by JPCERT/CC and GobRAT malware, which was used in the attack. ### Attack flow up to...

jpcert EN 20233 GobRAT malware analysis Linux routers Go
How malicious extensions hide running arbitrary code https://palant.info/2023/06/02/how-malicious-extensions-hide-running-arbitrary-code
05/06/2023 21:50:41
QRCode
archive.org
thumbnail

Eight malicious extensions still remain in Chrome Web Store. These use some interesting tricks to keep running arbitrary code despite restrictions of Manifest V3.

palant EN 2023 Chrome Web Store extensions malicious
Hackers steal Swiss police and customs data https://www.swissinfo.ch/eng/politics/hackers-steal-swiss-police-and-customs-data/48563830
05/06/2023 21:47:54
QRCode
archive.org
thumbnail

Hackers have published data from the federal police and customs offices on the Darknet, after an attack on the servers of the host company.

swissinfo EN 2023 Hackers Darknet Fedpol FOCBS Xplain
Russian Radio Stations Hacked, Fake Putin Message Announcing Invasion of Russia Broadcast https://www.kyivpost.com/post/17912
05/06/2023 21:43:30
QRCode
archive.org
thumbnail

The voice, very similar to President Putin’s, also announced martial law, general mobilisation and the evacuation of civilians in three regions bordering Ukraine.

kyivpost EN 2023 Radio russia-ukraine-war fake Broadcast Putin
L’armée suisse et Fedpol touchés par une cyberattaque https://www.ictjournal.ch/news/2023-06-05/larmee-suisse-et-fedpol-touches-par-une-cyberattaque
05/06/2023 21:40:40
QRCode
archive.org
thumbnail

Des cyberpirates ont mis la main sur des données de plusieurs offices de l'administration fédérale et les ont

ictjournal FR CH Fedpol armée xplain ransomware Play
MOVEit hack: BBC, BA and Boots among cyber attack victims https://www.bbc.com/news/technology-65814104
05/06/2023 21:31:05
QRCode
archive.org
thumbnail

Staff at multiple organisations are warned of a payroll data breach after an IT supplier is hacked.

bbc EN 2023 MOVEit databreach BritishAirways UK
New Magecart-Style Campaign Abusing Legitimate Websites to Attack Others | Akamai https://www.akamai.com/blog/security-research/new-magecart-hides-behind-legit-domains
05/06/2023 09:00:06
QRCode
archive.org
thumbnail

Akamai researchers have identified a new Magecart-style skimmer campaign that hides behind legitimate website domains to steal PII and credit card information.

akamai EN 2023 Research Magecart skimmer campaign WP
Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/
04/06/2023 23:02:39
QRCode
archive.org
thumbnail

Rapid7 is observing exploitation of a critical vulnerability in Progress Software’s MOVEit Transfer solution across multiple customer environments.

Rapid7 EN 2023 MOVEit Transfer Vulnerability
Enzo Biochem Ransomware Attack Exposes Information of 2.5M Individuals - SecurityWeek https://www.securityweek.com/enzo-biochem-ransomware-attack-exposes-information-of-2-5m-individuals/
04/06/2023 22:38:10
QRCode
archive.org
thumbnail

Enzo Biochem says the clinical test information of roughly 2.47 million individuals was exposed in a recent ransomware attack.

securityweek EN 2023 Enzo_Biochem PHI ransomware
Bypassing SELinux with init_module https://seanpesce.blogspot.com/2023/05/bypassing-selinux-with-initmodule.html?m=1
04/06/2023 22:33:35
QRCode
archive.org

There are two Linux system calls for loading a kernel module - init_module and finit_module. By leveraging init_module, I bypassed a filesystem-based SELinux rule that prevented me from loading a kernel module through traditional means (e.g., insmod). I then disabled SELinux from kernel-space. Proof of concept code can be found on my GitHub.

seanpesce EN 2023 SELinux bypass
New macOS vulnerability, Migraine, could bypass System Integrity Protection | Microsoft Security Blog https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integrity-protection/
04/06/2023 22:30:35
QRCode
archive.org
thumbnail

A new vulnerability, which we refer to as “Migraine” for its involvement with macOS migration, could allow an attacker with root access to automatically bypass System Integrity Protection (SIP) in macOS and perform arbitrary operations on a device

Microsoft en 2023 research vulnerability macOS Migraine bypass SIP
‘Gravity Forms’ WordPress Plugin Found Vulnerable to PHP Object Injection https://www.bitdefender.com/blog/hotforsecurity/gravity-forms-wordpress-plugin-found-vulnerable-to-php-object-injection/
04/06/2023 14:05:54
QRCode
archive.org
thumbnail

Gravity Forms, a popular WordPress plugin, has been found vulnerable to
unauthenticated PHP Object Injection attacks.

bitdefender EN 2023 WP WordPress Plugin gravity-forms CVE-2023-28782
page 166 / 237
4736 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio