Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 167 / 208
4141 résultats taggé EN  ✕
SQL Injection in Multiple WordPress Plugins https://www.tenable.com/security/research/tra-2023-2
16/01/2023 17:43:25
QRCode
archive.org
  • Paid Memberships Pro : CVE-2023-23488 - Unauthenticated SQL Injection

  • Easy Digital Downloads: CVE-2023-23489 - Unauthenticated SQL Injection

  • Survey Maker: CVE-2023-23490 - Authenticated SQL Injection

tenable 2023 EN WordPress Plugins Advisory CVE-2023-23488 CVE-2023 CVE-2023-23490-23489
Sustaining Digital Certificate Security - TrustCor Certificate Distrust https://security.googleblog.com/2023/01/sustaining-digital-certificate-security_13.html
16/01/2023 06:37:40
QRCode
archive.org
thumbnail

Google includes or removes CA certificates within the Chrome Root Store as it deems appropriate for user safety in accordance with our policies. The selection and ongoing inclusion of CA certificates is done to enhance the security of Chrome and promote interoperability.

googleblog EN 2023 Digital Certificate Security Root TrustCor Distrust
MSI's (in)Secure Boot https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/
16/01/2023 06:35:44
QRCode
archive.org

On 2022-12-11, I decided to setup Secure Boot on my new desktop with a help of sbctl. Unfortunately I have found that my firmware was… accepting every OS image I gave it, no matter if it was trusted or not. It wasn't the first time that I have been self-signing Secure Boot, I wasn't doing it wrong.

As I have later discovered on 2022-12-16, it wasn't just broken firmware, MSI had changed their Secure Boot defaults to allow booting on security violations(!!).

dawidpotocki EN 2023 MSI SecureBoot broken insecure firmware
How Finland Is Teaching a Generation to Spot Misinformation https://www.nytimes.com/2023/01/10/world/europe/finland-misinformation-classes.html
16/01/2023 06:34:18
QRCode
archive.org

How Finland Is Teaching a Generation to Spot Misinformation
The Nordic country is testing new ways to teach students about propaganda. Here’s what other countries can learn from its success.

nytimes EN 2022 Finland Teaching Misinformation propaganda education
Compromise of employee device, credentials led to CircleCI breach https://www.scmagazine.com/analysis/breach/compromise-of-employee-device-credentials-led-to-circleci-breach
16/01/2023 06:31:49
QRCode
archive.org
thumbnail

CircleCI’s chief technology officer said malicious hackers infected one of their engineer’s laptops and stole elevated account privileges to breach the company’s systems and data late last year.

scmagazine EN 2023 CircleCI infected laptops breach
A Police App Exposed Secret Details About Raids and Suspects | WIRED https://www.wired.com/story/sweepwizard-police-raids-data-exposure/
15/01/2023 20:28:54
QRCode
archive.org
thumbnail

SweepWizard, an app that law enforcement used to coordinate raids, left sensitive information about hundreds of police operations publicly accessible.

wired EN 2023 SweepWizard privacy police crime app leak sensitive information US
Watch: Ukraine Army Video Tells Russians How to Surrender to a Drone https://www.businessinsider.com/ukraine-army-video-tells-russians-how-to-surrender-to-drone-2022-12?r=US&IR=T
15/01/2023 16:18:39
QRCode
archive.org
thumbnail
  • Ukraine has released an instruction video for Russian soldiers on surrendering to a drone.
  • It's part of the "I Want to Live" hotline, which entices Russians to stop fighting in Ukraine.
  • The video suggests that surrendering via drone may become increasingly common.
businessinsider EN 2022 drones war Army instruction drone russia-ukraine-war surrendering
Accidentally Crashing a Botnet https://www.akamai.com/blog/security-research/kmsdbot-part-two-crashing-a-botnet
15/01/2023 16:15:38
QRCode
archive.org
thumbnail

As part of our research into the cryptomining botnet kmsdbot, we rendered it useless.

akamai EN 2022 Security-Research Research Bot-Attacks DDOS Bot-Attacks Cyber-Security Research Security-Research Kmsdbot botnet SIRT cryptomining crash malware
Pro-Russia hackers use Telegram, GitHub to attack Czech presidential election https://therecord.media/pro-russia-hackers-use-telegram-github-to-attack-czech-presidential-election/
15/01/2023 16:07:24
QRCode
archive.org
thumbnail

The Record by Recorded Future gives exclusive, behind-the-scenes access to leaders, policymakers, researchers, and the shadows of the cyber underground.

therecord EN 2023 Telegram GitHub Pro-Russia Czech election DDOSIA Sentinelone
Royal Mail ransomware attackers threaten to publish stolen data https://www.theguardian.com/business/2023/jan/12/royal-mail-ransomware-attackers-threaten-to-publish-stolen-data
14/01/2023 15:13:49
QRCode
archive.org
thumbnail

Postal service has been unable to send letters and parcels overseas since Wednesday due to hacking

Royal Mail has been hit by a ransomware attack by a criminal group, which has threatened to publish the stolen information online.

The postal service has received a ransom note purporting to be from LockBit, a hacker group widely thought to have close links to Russia.

theguardian EN 2023 Royalmail Postal letters ransomware LockBit Russia
NoName057(16) - The Pro-Russian Hacktivist Group Targeting NATO https://www.sentinelone.com/labs/noname05716-the-pro-russian-hacktivist-group-targeting-nato/
12/01/2023 21:54:07
QRCode
archive.org
thumbnail

In the name of Russia's war in Ukraine, NoName057(16) abuses GitHub and Telegram in an ongoing campaign to disrupt NATO's critical infrastructure.

sentinelone EN 2023 NoName057(16) Russia Telegram Hacktivist NATO
StrongPity espionage campaign targeting Android users https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users/
11/01/2023 22:39:31
QRCode
archive.org
thumbnail

ESET researchers uncover an active StrongPity campaign that spreads a trojanized version of the Android Telegram app posing as the Shagle video chat app.

welivesecurity EN 2023 ESET Android Telegram trojanized Shagle
Misconfigured PostgreSQL Used to Target Kubernetes Clusters https://www.databreachtoday.eu/misconfigured-postgresql-used-to-target-kubernetes-clusters-a-20899?s=09
11/01/2023 11:33:08
QRCode
archive.org
thumbnail

Researchers have found that Kinsing malware gained access to Kubernetes servers by exploiting misconfigured and exposed PostgreSQL servers. The threat actors gained

databreachtoday EN 2023 PostgreSQL Kubernetes Misconfigured malware Kinsing
Zoom Patches High Risk Flaws on Windows, MacOS Platforms https://www.securityweek.com/zoom-patches-high-risk-flaws-windows-macos-platforms
11/01/2023 09:23:06
QRCode
archive.org

Video messaging giant Zoom has released patches for multiple security vulnerabilities that expose both Windows and macOS users to malicious hacker attacks.

securityweek EN 2023 CVE-2022-36930 CVE-2022-36929 CVE-2022-36927 patch-tuesday zoom zoom-rooms windows macos video-conferencing video-messaging privilege-escalation vulnerability
Raspberry Robin's botnet second life https://blog.sekoia.io/raspberry-robins-botnet-second-life/
10/01/2023 20:52:19
QRCode
archive.org
thumbnail

Raspberry Robin appears to be a type of Pay-Per-Install botnet, likely to be used by cybercriminals to distribute other malware.

sekoia EN 2023 RaspberryRobin Pay-Per-Install botnet cybercriminals malware
The OWASSRF + TabShell exploit chain https://blog.viettelcybersecurity.com/tabshell-owassrf/
09/01/2023 23:56:01
QRCode
archive.org
thumbnail

We see that one of our vulnerabilities is exploited in the wild Link. So we decided to public the detail analysis of our two bug chains. Any customer has enough information to mitigate these bugs. The vendor also released all patches a week ago. This blog post shares the detail

viettelcybersecurity EN 2022 Exchange TabShell exploit chain OWASSRF vulnerabilities
New Paper on Old Threema Protocol https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement
09/01/2023 22:50:34
QRCode
archive.org
thumbnail

This is a statement on the NZZ news article from January 9, 2023 about alleged weaknesses in Threema's encryption. But these are completely impractical and theoretical.

threema EN 2023 statement NZZ weaknesses encryption Old Protocol
Three Lessons from Threema: Analysis of a Secure Messenger https://breakingthe3ma.app/
09/01/2023 22:48:01
QRCode
archive.org

Threema is a Swiss encrypted messaging application. It has more than 10 million users and more than 7000 on-premise customers. Prominent users of Threema include the Swiss Government and the Swiss Army, as well as the current Chancellor of Germany, Olaf Scholz. Threema has been widely advertised as a secure alternative to other messengers.

In our work, we present seven attacks against the cryptographic protocols used by Threema, in three distinct threat models. All the attacks are accompanied by proof-of-concept implementations that demonstrate their feasibility in practice.

breakingthe3ma Threema EN 2023 paper vulnerabilies attacks cryptographic protocols
Advertising ID: APPLE DISTRIBUTION INTERNATIONAL fined 8 million euros https://www.cnil.fr/en/advertising-id-apple-distribution-international-fined-8-million-euros
09/01/2023 05:30:39
QRCode
archive.org

On 29 December 2022, the CNIL's restricted committee imposed an administrative fine of 8 million euros on the company APPLE DISTRIBUTION INTERNATIONAL because it did not collect the consent of iPhone's French users (iOS 14.6 version) before depositing and/or writing identifiers used for advertising purposes on their terminals.

CNIL EN 2023 Apple administrative fine collect iPhone France ads advertising
I scanned every package on PyPi and found 57 live AWS keys https://tomforb.es/i-scanned-every-package-on-pypi-and-found-57-live-aws-keys/
07/01/2023 22:21:04
QRCode
archive.org

After inadvertently finding that InfoSys leaked an AWS key on PyPi I wanted to know how many other live AWS keys may be present on Python package index. After scanning every release published to PyPi I found 57 valid access keys from organisations like:

Amazon themselves 😅
Intel
Stanford, Portland and Louisiana University
The Australian Government
General Atomics fusion department
Terradata
Delta Lake
And Top Glove, the worlds largest glove manufacturer 🧤

tomforb EN 2022 leak scan AWS keys PyPi
page 167 / 208
4727 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio