Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 166 / 208
4141 résultats taggé EN  ✕
PayPal Notifies 35,000 Users of Data Breach https://www.hackread.com/paypal-data-breach-alert/
21/01/2023 11:27:50
QRCode
archive.org
thumbnail

PayPal has alerted over 35,000 customers of a data breach revealing that their accounts were hacked between December 6th and 8th, 2022.

hackread EN 2023 PayPal breach accounts hacked
ManageEngine CVE-2022-47966 Technical Deep Dive https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/
20/01/2023 15:29:40
QRCode
archive.org
thumbnail

Introduction On January 10, 2023, ManageEngine released a security advisory for CVE-2022-47966 (discovered by Khoadha of Viettel Cyber Security) affecting a wide range of products. The vulnerability allows an attacker to gain remote code execution by issuing a HTTP POST request containing a malicious SAML response. This vulnerability is a result of  using an outdated […]

horizon3 EN 2023 ManageEngine CVE-2022-47966 Technical DeepDive
T-Mobile hacked to steal data of 37 million accounts in API data breach https://www.bleepingcomputer.com/news/security/t-mobile-hacked-to-steal-data-of-37-million-accounts-in-api-data-breach/
20/01/2023 12:05:15
QRCode
archive.org
thumbnail

T-Mobile disclosed a new data breach after a threat actor stole the personal information of 37 million current postpaid and prepaid customer accounts through one of its Application Programming Interfaces (APIs).

bleepingcomputer EN 2023 Data-Breach Security-Breach T-Mobile
Hackers push malware via Google search ads for VLC, 7-Zip, CCleaner https://www.bleepingcomputer.com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
20/01/2023 12:00:16
QRCode
archive.org
thumbnail

Hackers are setting up fake websites for popular free and open-source software to promote malicious downloads through advertisements in Google search results.

bleepingcomputer EN 2023 googleads Advertisement Google Info-Stealer RedLine Search Vidar
DNS changer in malicious mobile app used by Roaming Mantis https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/
20/01/2023 11:57:51
QRCode
archive.org
thumbnail

Roaming Mantis (a.k.a Shaoye) is a long-term cyberattack campaign that uses malicious Android package (APK) files to control infected Android devices and steal data. In 2022, we observed a DNS changer function implemented in its Android malware Wroba.o.

securelist EN 2023 APT RoamingMantis Google-Android Malware-Descriptions Shaoye Malware-Technologies Mobile-Malware Targeted-attacks Trojan
Batloader Malware Abuses Legitimate Tools Uses Obfuscated JavaScript Files in Q4 2022 Attacks https://www.trendmicro.com/en_us/research/23/a/batloader-malware-abuses-legitimate-tools-uses-obfuscated-javasc.html
19/01/2023 20:11:10
QRCode
archive.org
thumbnail

We discuss the Batloader malware campaigns we observed in the last quarter of 2022, including our analysis of Water Minyades-related events (This is the intrusion set we track behind the creation of Batloader).

trendmicro EN 2023 Malware Batloader analysis
Apple launches major security updates around the world https://www.independent.co.uk/tech/apple-update-iphone-ios-security-encryption-backups-b2264693.html
19/01/2023 14:16:25
QRCode
archive.org
thumbnail

Apple has launched its recent major security updates to the whole world.

independent EN 2023 Apple security updates major backup
Mailchimp says it was hacked — again https://techcrunch.com/2023/01/18/mailchimp-hacked/
19/01/2023 14:12:14
QRCode
archive.org
thumbnail

This is the second breach to hit Mailchimp in six months. It also appears to be almost identical to a previous incident.

techcrunch 2023 EN data-breach intuit mailchimp again
Russian Citizen Accused of Running Cryptocurrency Exchange Used by Criminals https://www.nytimes.com/2023/01/18/us/politics/russian-citizen-bitzlato-cryptocurrency.html?mid=1#cid=128159
19/01/2023 14:11:14
QRCode
archive.org

The charges were part of an intensifying effort by federal law enforcement agencies, in conjunction with European partners, to combat international cryptocurrency schemes and illegal transactions.

nytimes EN 2023 Russian Accused Cryptocurrency Exchange Criminals bitzlato
Russian founder of a cryptocurrency exchange known for funneling ransomware profits arrested https://www.cyberscoop.com/cryptocurrency-bitzlato-exchange-ransomware-profits-arrested/
19/01/2023 14:08:11
QRCode
archive.org
thumbnail

The arrest comes as the U.S. ramps up efforts to crack down on attempts by cybercriminals to use cryptocurrency to evade sanctions.

cyberscoop EN 2023 cryptocurrency exchange founder ransomware arrested Hydra Marketplace
Assessing Potential Exploitation of Sophos Firewall and CVE-2022-3236 https://vulncheck.com/blog/sophos-cve-2022-3236
18/01/2023 21:44:40
QRCode
archive.org
thumbnail

Sophos took immediate steps to remediate CVE-2022-3236 – an unauthenticated and remote code execution vulnerability affecting the Sophos Firewall Webadmin and User Portal HTTP interfaces – with an automated hotfix sent out in September 2022. Through its advisory published on September 23, 2022, it also alerted users who don't receive automatic hotfixes to apply the update themselves. The advisory stated the vulnerability had previously been used against "a small set of specific organizations, primarily in the South Asia region." In December, Sophos released v19.5 GA GA with an official fix.
Key Takeaways

  • As there are no public proof-of-concept exploits for CVE-2022-3236, we created our own to determine its potential for mass exploitation.
  • We scanned internet-facing Sophos Firewalls and found more than 4,000 firewalls that were too old to receive a hotfix.
  • We encourage Sophos Firewall administrators to look through their logs to determine if they see indications of exploit attempts. Two files to focus on include /logs/csc.log and /log/validationError.log.
  • Internet-facing firewalls appear to largely be eligible for hotfixes and the default authentication captcha likely prevented mass exploitation.
vulncheck EN 2023 sophos CVE-2022-3236 PoC
Can you rely on macOS Ventura for malware protection? https://eclecticlight.co/2023/01/03/can-you-rely-on-macos-ventura-for-malware-protection/
18/01/2023 13:41:10
QRCode
archive.org
thumbnail

Samples of four malicious software downloaded and run on macOS 13.1. Could it detect and block them effectively? Or do you need 3rd party protection?

eclecticlight EN 2023 macOS malware protection Ventura
7 Ways Threat Actors Deliver macOS Malware in the Enterprise https://www.sentinelone.com/blog/7-ways-threat-actors-deliver-macos-malware-in-the-enterprise/
18/01/2023 13:38:11
QRCode
archive.org
thumbnail

Stay ahead of the game with our review on macOS malware threats. Learn about the top techniques used by threat actors to deliver malware and how to build more resilient defenses.

sentinelone EN 2023 macOS Malware Enterprise threats
InfoSec Handlers Diary Blog - SANS Internet Storm Center https://isc.sans.edu/diary/29448
18/01/2023 13:37:13
QRCode
archive.org
thumbnail

Malicious Google Ad --> Fake Notepad++ Page --> Aurora Stealer malware

SANS EN 2023 googleads Fake Notepad Aurora Stealer malware
Google Ads Exploited to Spread Malware https://heimdalsecurity.com/blog/google-ads-exploited-to-spread-malware/
18/01/2023 13:34:43
QRCode
archive.org
thumbnail

Google Ads is one of the most popular advertising platform, but it's also a target for cybercriminals. Learn how they are using it to spread malware.

heimdalsecurity EN 2022 googleads abuse Malware Exploited
Google Ads Malware Wipes NFT Influencer's Crypto Wallet https://www.hackread.com/google-ads-malware-nft-crypto-wallet/
18/01/2023 13:33:35
QRCode
archive.org
thumbnail

NFT influencer @NFT_GOD downloaded malware through Google Ads while attempting to download OBS, an open-source video streaming software.

hackread EN 2023 googleads OBS open-source abuse influencer NFT
“MasquerAds” — Google’s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e
18/01/2023 13:31:41
QRCode
archive.org

A newly uncovered technique to abuse Google’s ad-words powerful advertisement platform is spreading rogue promoted search results in mass. Pointing to allegedly credible advertisement sites that are fully controlled by threat actors, those are used to masquerade and redirect ad-clickers to malicious phishing pages gaining the powerful credibility and targeting capabilities of Google’s search results. Adding customized malware payloads, threat actors are raising the bar for successful malware deployments on Personal PCs with ad words like Grammarly, Malwarebytes, and Afterburner as well as with Visual Studio, Zoom, Slack, and even Dashlane to target organizations.

labs.guard.io EN 2022 googleads technique advertisement abuse malware distribution
Supply Chain Attack Using Identical PyPI Packages, “colorslib”, “httpslib”, and “libhttps” https://www.fortinet.com/blog/threat-research/supply-chain-attack-using-identical-pypi-packages-colorslib-httpslib-libhttps
16/01/2023 21:21:22
QRCode
archive.org
thumbnail

The FortiGuard Labs team discovered an attack embedded in three PyPI packages called ‘colorslib’, ‘httpslib’, and “libhttps”. Read our blog to learn more.

fortinet EN 2023 threat-research Threat-Research security-attack libhttps httpslib colorslib python PyPI
Vice Society ransomware leaks University of Duisburg-Essen’s data https://www.bleepingcomputer.com/news/security/vice-society-ransomware-leaks-university-of-duisburg-essen-s-data/
16/01/2023 21:11:47
QRCode
archive.org
thumbnail

The Vice Society ransomware gang has claimed responsibility for the November 2022 cyberattack that forced the University of Duisburg-Essen (UDE) to reconstruct its IT infrastructure, a process that's still ongoing.

bleepingcomputer EN 2023 Cyberattack Data-Leak Data-Theft Education Ransomware University-of-Duisburg-Essen Vice-Society
NortonLifeLock warns that hackers breached Password Manager accounts https://www.bleepingcomputer.com/news/security/nortonlifelock-warns-that-hackers-breached-password-manager-accounts/
16/01/2023 20:03:14
QRCode
archive.org
thumbnail

Gen Digital, formerly Symantec Corporation and NortonLifeLock, is sending data breach notifications to customers, informing them that hackers have successfully breached Norton Password Manager accounts in credential-stuffing attacks.

bleepingcomputer EN 2023 Password-manager NortonLifeLock breach Norton Password Manager credential-stuffing attack
page 166 / 208
4727 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio