Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 169 / 237
What if we had the SockPuppet vulnerability in iOS 16? https://security.apple.com/blog/what-if-we-had-sockpuppet-in-ios16/
23/05/2023 21:48:17
QRCode
archive.org

The next post in our XNU memory safety series examines how our hardened kernel allocator performs in the real world against a previously patched but powerful UAF software vulnerability. In this detailed analysis, we find out what might happen if SockPuppet were to meet kalloc_type in iOS 16.

security.apple EN 2023 SockPuppet iOS research
Don't @ Me: URL Obfuscation Through Schema Abuse https://www.mandiant.com/resources/blog/url-obfuscation-schema-abuse
23/05/2023 21:41:16
QRCode
archive.org
thumbnail

Attackers are distributing malware using a technique that abuses the URL schema.

mandiant EN 2023 Obfuscation URL Schema Smokeloader
BlackCat Ransomware Deploys New Signed Kernel Driver https://www.trendmicro.com/en_us/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver.html
22/05/2023 22:20:27
QRCode
archive.org
thumbnail

In this blog post, we will provide details on a BlackCat ransomware incident that occurred in February 2023, where we observed a new capability, mainly used for the defense evasion phase.

trendmicro EN 2023 ransomware research BlackCat Kernel Driver
Up to 100 cases taken over HSE cyberattack, judge told https://www.irishtimes.com/crime-law/courts/2023/05/18/up-to-100-cases-taken-over-hse-cyberattack-judge-told/
22/05/2023 07:11:29
QRCode
archive.org
thumbnail

European court to decide key liability issues over data breach but question mark hangs over HSE liability for ‘non-material’ damage such as stress

irishtimes EN 2023 EU DataBreach liability legal
Beijing Bans Micron as Supplier to Big Chinese Firms, Citing National Security https://www.wsj.com/articles/beijing-bans-micron-as-supplier-to-big-chinese-firms-citing-national-security-5f326b90?st=e1re5trsol7ejy0
22/05/2023 07:09:04
QRCode
archive.org
thumbnail

Cyberspace Administration says chip maker failed review, in a move that seems aimed at hitting back at U.S. chip ban

wsj EN 2023 US China ban Micron
Apple Restricts Employee Use of ChatGPT, Joining Other Companies Wary of Leaks https://archive.ph/g6Irs
21/05/2023 17:02:34
QRCode
archive.org

The iPhone maker is concerned workers could release confidential data as it develops its own similar technology.

wsj 2023 Apple ChatGPT Restricts Leak confidential
Popular Android TV boxes sold on Amazon are laced with malware https://techcrunch.com/2023/05/18/popular-android-tv-boxes-sold-on-amazon-are-laced-with-malware/
21/05/2023 16:36:41
QRCode
archive.org
thumbnail

The malware-infected AllWinner and RockChip-powered Android TV models are still available to purchase on Amazon.

techcrunch EN 2023 amazon android-tv malware rockchip Android IoT AllWinner Amazon
MalasLocker ransomware targets Zimbra servers, demands charity donation https://www.bleepingcomputer.com/news/security/malaslocker-ransomware-targets-zimbra-servers-demands-charity-donation/
21/05/2023 16:16:19
QRCode
archive.org
thumbnail

A new ransomware operation is hacking Zimbra servers to steal emails and encrypt files. However, instead of demanding a ransom payment, the threat actors claim to require a donation to charity to provide an encryptor and prevent data leaking.

bleepingcomputer Age-Encryption AgeLocker Charity Email MalasLocker QNAP Ransomware Zimbra
Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices https://www.trendmicro.com/en_us/research/23/e/lemon-group-cybercriminal-businesses-built-on-preinfected-devices.html
21/05/2023 15:53:00
QRCode
archive.org
thumbnail

An overview of the Lemon Group’s use of preinfected mobile devices, and how this scheme is potentially being developed and expanded to other internet of things (IoT) devices. This research was presented in full at the Black Hat Asia 2023 Conference in Singapore in May 2023.

trendmicro EN 2023 malware cyber-crime LemonGroup Preinfected Guerrilla Android mobile mobile-device IoT AndroidOS_Guerilla
Visualizing QakBot Infrastructure https://www.team-cymru.com/post/visualizing-qakbot-infrastructure
18/05/2023 09:53:40
QRCode
archive.org
thumbnail

This blog post seeks to draw out some high-level trends and anomalies based on our ongoing tracking of QakBot command and control (C2) infrastructure. By looking at the data with a broader scope, we hope to supplement other research into this particular threat family, which in general focuses on specific infrastructure elements; e.g., daily alerting on active C2 servers.

team-cymru EN 2023 QakBot Infrastructure research C2
“FleeceGPT” mobile apps target AI-curious to rake in cash https://news.sophos.com/en-us/2023/05/17/fleecegpt-mobile-apps-target-ai-curious-to-rake-in-cash/
18/05/2023 01:37:15
QRCode
archive.org
thumbnail

Interest in OpenAI’s latest version of its interactive language model has spurred a new wave of scam apps looking to cash in on the hype

sophos EN 2023 Fleeceware ChatGPT scam apps
KeePass flaw allows retrieval of master password, PoC is public (CVE-2023-32784) https://www.helpnetsecurity.com/2023/05/17/cve-2023-32784/
17/05/2023 15:31:56
QRCode
archive.org
thumbnail

A vulnerability (CVE-2023-32784) in KeePass can be exploited to retrieve the master password from the software's memory.

helpnetsecurity EN 2023 CVE-2023-32784 password KeePass retrieve
GitHub - vdohney/keepass-password-dumper https://github.com/vdohney/keepass-password-dumper
17/05/2023 15:30:10
QRCode
archive.org
thumbnail

The vulnerability was assigned CVE-2023-32784. It should be fixed in KeePass 2.54, which should come out in ~July 2023. Thanks again to Dominik Reichl for his fast response and creative fix!

vdohney EN 2023 PoC KeePass dumper password CVE-2023-32784
Discord discloses data breach after support agent got hacked https://www.bleepingcomputer.com/news/security/discord-discloses-data-breach-after-support-agent-got-hacked/
17/05/2023 10:10:31
QRCode
archive.org
thumbnail

Discord is notifying users of a data breach that occurred after the account of a third-party support agent was compromised.

bleepingcomputer EN 2023 Customer-Support Data-Breach Discord
SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack https://www.mandiant.com/resources/blog/sim-swapping-abuse-azure-serial
17/05/2023 08:16:57
QRCode
archive.org
thumbnail

Attacker activity in Microsoft Azure that we attribute to a financially motivated threat actor.

mandiant EN 2023 Azure Azure-Serial-Console UNC3944
Piratage et médias suisses, la justice entre en action https://www.letemps.ch/economie/cyber/piratage-medias-suisses-justice-entre-action
16/05/2023 22:34:54
QRCode
archive.org
thumbnail

Comme d’autres médias, «Le Temps» a été sommé par CH Media et la NZZ, via leurs avocats, de ne publier aucune information confidentielle liée à la cyberattaque subie. En Suisse alémanique, deux médias ont dû modifier des articles en ligne

letemps FR 2023 NZZ Cybersécurité Médias avocats legal disclose
Malicious VSCode extensions with more than 45K downloads steal PII and enable backdoors - Check Point Blog https://blog.checkpoint.com/securing-the-cloud/malicious-vscode-extensions-with-more-than-45k-downloads-steal-pii-and-enable-backdoors/
16/05/2023 22:04:01
QRCode
archive.org
thumbnail

Highlights: CloudGuard Spectrals detected malicious extensions on the VSCode marketplace Users installing these extensions were enabling attackers to

checkpoint EN 2023 VSCode extensions malicious
Review and analysis of fake Trezor cryptowallet https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/
15/05/2023 21:56:00
QRCode
archive.org
thumbnail

Fake hardware cryptowallet, and how bitcoins were stolen from it.

kaspersky EN 2023 hardware-wallet trezor fake scam hardware wallet
FBI confirms access to Breached cybercrime forum database https://medium.com/@spixnet.gmbh/fbi-confirms-access-to-breached-cybercrime-forum-database-a12c839e9621
15/05/2023 21:21:07
QRCode
archive.org
thumbnail

Today, the FBI confirmed they have access to the database of the notorious BreachForums (aka Breached) hacking forum after the U.S. Justice Department also officially announced the arrest of its…

@spixnet.gmbh EN 2023 Breached FBI confirmed database Pompompurin
Securonix Threat Labs Security Advisory: Latest Update: Ongoing MEME#4CHAN Attack/Phishing Campaign uses Meme-Filled Code to Drop XWorm Payloads https://www.securonix.com/blog/securonix-threat-labs-security-meme4chan-advisory/
15/05/2023 21:16:07
QRCode
archive.org
thumbnail

An unusual attack/phishing campaign delivering malware while using meme-filled code and complex obfuscation methods continues dropping Xworm payloads for the last few months and is still ongoing today.

securonix EN 2023 XWorm Payloads MEME#4CHAN Phishing Meme-Filled
page 169 / 237
4737 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio