Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 172 / 208
4142 résultats taggé EN  ✕
Gaming firm Razer wins lawsuit against IT vendor over data leak, awarded $8.7m in damages https://www.straitstimes.com/singapore/courts-crime/gaming-firm-razer-wins-lawsuit-against-it-vendor-over-data-leak-awarded-87m-in-damages
10/12/2022 18:28:53
QRCode
archive.org
thumbnail

Shipping information and order details of thousands of customers worldwide were leaked in September 2020.
Read more at straitstimes.com.

straitstimes EN 2022 Razer lawsuit damages Capgemini
Hitching a ride with Mustang Panda https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
10/12/2022 10:39:35
QRCode
archive.org
thumbnail

Avast discovered a distribution point where a malware toolset is hosted, but also serves as temporary storage for the gigabytes of data being exfiltrated on a daily basis, including documents, recordings, and webmail dumps including scans of passports from Asian, American and European citizens and diplomats applying for Burmese visas, from Burmese human rights activists and Burmese government institutions.

avast EN 2022 MustangPanda exfiltrated analysis
New MuddyWater Threat: Old Kitten; New Tricks https://www.deepinstinct.com/blog/new-muddywater-threat-old-kitten-new-tricks
10/12/2022 09:59:21
QRCode
archive.org
thumbnail

MuddyWater, also known as Static Kitten and Mercury, is a cyber espionage group that’s most likely a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).

Since at least 2017 MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.

deepinstinct MuddyWater EN 2022 analysis malspam StaticKitten Mercury
Apple rolls out end-to-end encryption for iCloud backups https://www.bleepingcomputer.com/news/apple/apple-rolls-out-end-to-end-encryption-for-icloud-backups/
07/12/2022 21:57:14
QRCode
archive.org
thumbnail

Apple introduced today Advanced Data Protection for iCloud, a new feature that uses end-to-end encryption to protect sensitive iCloud data, including backups, Photos, Notes, and more.

bleepingcomputer EN 2022 Apple Backup E2EE End-to-end-encryption iCloud
Mustang Panda Uses the Russian-Ukrainian War to Attack Europe and Asia Pacific Targets https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets?s=09
07/12/2022 21:43:18
QRCode
archive.org
thumbnail

APT group Mustang Panda now appears to have Europe and Asia Pacific targets in its sights. The BlackBerry Research and Intelligence team recently unearthed evidence that the group may be using global interest in the Russian-Ukraine war to deliver PlugX malware via phishing lure to unsuspecting users.

blackberry EN 2022 MustangPanda Europe Asia russia-ukraine-war PlugX malware
Leaked: The Altrnativ world of cybersurveillance https://www.politico.eu/leaked-altrnativ-world-cybersurveillance/
07/12/2022 21:36:16
QRCode
archive.org
thumbnail

Leaked: The Altrnativ world of cybersurveillance About this series: As co-founder of the French search engine Qwant, Eric Leandri was heralded as a champion of digital privacy and an example of Eur…

politico EN FR 2022 LEandri Qwant Altrnativ French privacy spy OSINT surveillance
Top 10 macOS Malware Discoveries in 2022 https://www.sentinelone.com/blog/top-10-macos-malware-discoveries-in-2022/
07/12/2022 21:20:49
QRCode
archive.org
thumbnail

Learn about all the new malware targeting macOS users in 2022 and how to stay safe from the latest Mac-focused campaigns.

sentinelone EN 2022 top10 malware macOS
Supply Chain Vulnerabilities Put Server Ecosystem At Risk https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/
06/12/2022 22:46:22
QRCode
archive.org

BMC&C Eclypsium Research has discovered and reported 3 vulnerabilities in American Megatrends, Inc. (AMI) MegaRAC Baseboard Management Controller (BMC) software. We are referring to these vulnerabilities collectively as BMC&C. MegaRAC BMC is widely used by many leading server manufacturers to provide “lights-out” management capabilities for their server products. Server manufacturers…

eclypsium EN 2022 CVE-2022-40259 CVE-2022-40242 CVE-2022-2827 Research AMI BMC MegaRAC supply-chain vulnerabilities server
Zerobot – New Go-Based Botnet Campaign Targets Multiple Vulnerabilities https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities
06/12/2022 22:38:53
QRCode
archive.org
thumbnail

FortiGuardLabs examines a botnet known as Zerobot written in the Go language targeting IoT vulnerabilities. Read our blog to learn about how it evolves, including self-replication, attacks for different protocols, and self-propagation as well as its behavior once inside an infected device.

fortinet EN 2022 vulnerabilities Botnet iot-security Zerobot Go Threat-Research malware-research malware-analysis
Vice Society: Profiling a Persistent Threat to the Education Sector https://unit42.paloaltonetworks.com/vice-society-targets-education-sector/
06/12/2022 19:52:15
QRCode
archive.org
thumbnail

Vice Society, a ransomware gang, has been involved in high-profile activity against schools this year.

unit42 EN 2022 paloaltonetworks vice-society education ransomware schools
Critical Ping Vulnerability Allows Remote Attackers to Take Over FreeBSD Systems https://thehackernews.com/2022/12/critical-ping-vulnerability-allows.html
06/12/2022 08:35:38
QRCode
archive.org
thumbnail

he maintainers of the FreeBSD operating system have released updates to remediate a security vulnerability impacting the ping module that could be potentially exploited to crash the program or trigger remote code execution.

The issue, assigned the identifier CVE-2022-23093, impacts all supported versions of FreeBSD and concerns a stack-based buffer overflow vulnerability in the ping service.

thehackernews EN 2022 Ping Vulnerability FreeBSD CVE-2022-23093
Blowing Cobalt Strike Out of the Water With Memory Analysis https://unit42.paloaltonetworks.com/cobalt-strike-memory-analysis/
06/12/2022 06:51:47
QRCode
archive.org
thumbnail

Unit 42 researchers examine several malware samples that incorporate Cobalt Strike components, and discuss some of the ways that we catch these samples by analyzing artifacts from the deltas in process memory at key points of execution. We will also discuss the evasion tactics used by these threats, and other issues that make their analysis problematic.

unit42 EN 2022 CobaltStrike analysis paloaltonetworks
W4SP continues to nest in PyPI: Same supply chain attack, different distribution method https://develop.secure.software/w4sp-continues-to-nest-in-pypi-same-supply-chain-attack-different-distribution-method
05/12/2022 12:13:20
QRCode
archive.org
thumbnail

Here's ReversingLabs' discoveries and indicators of compromise (IOCs) for W4SP, as well as links to our YARA rule that can be used to detect the malicious Python packages in your environment. 

develop.secure.software EN 2022 W4SP YARA Python PyPI
Post-quantum cryptography: What is Emmanuel Macron talking about? https://www.lemonde.fr/en/pixels/article/2022/12/04/post-quantum-cryptography-what-is-emmanuel-macron-talking-about_6006537_13.html
05/12/2022 11:56:38
QRCode
archive.org
thumbnail

The President of the Republic announced the sending of the 'first diplomatic telegram encrypted using post-quantum cryptography' to the French embassy in Washington. We explain its importance for the future of confidential communications.

lemonde EN 2022 cryptography Macron post-quantum cryptography
Purpose Built Proxy Services and the Malicious Activity They Enable https://www.domaintools.com/resources/blog/purpose-built-criminal-proxy-services-and-the-malicious-activity-they-enable/
05/12/2022 11:33:44
QRCode
archive.org
thumbnail

As demand for malicious proxy services continues, new players have entered the market. Black Proxies is marketed to other cybercriminals for their reliability, scope, and overwhelming number of IP addresses.

domaintools EN 2022 proxy black-proxies cybercriminals Services
CVE-2022-21661: Exposing Database Info via WordPress SQL Injection https://www.zerodayinitiative.com/blog/2022/1/18/cve-2021-21661-exposing-database-info-via-wordpress-sql-injection
05/12/2022 11:31:28
QRCode
archive.org
thumbnail

In October of this year, we received a report from ngocnb and khuyenn from GiaoHangTietKiem JSC covering a SQL injection vulnerability in WordPress. The bug could allow an attacker to expose data stored in a connected database. This vulnerability was recently addressed as CVE-2022-21661 ( ZDI-22-020

zerodayinitiative EN 2022 CVE-2022-21661 SQL-injection vulnerability WordPress
Connected medical devices are the Achilles' heel of healthcare orgs - Help Net Security https://www.helpnetsecurity.com/2022/12/05/connected-medical-devices-cyberattacks/
05/12/2022 11:29:37
QRCode
archive.org
thumbnail

The rising adoption of connected medical devices is accelerating cyberattacks, according to Capterra’s Medical IoT Survey.

helpnetsecurity EN 2022 IoT connected medical devices statistcs healthcare Survey
Schoolyard Bully Trojan Facebook Credential Stealer - Zimperium https://www.zimperium.com/blog/schoolyard-bully-trojan-facebook-credential-stealer/
05/12/2022 11:17:24
QRCode
archive.org
thumbnail

Zimperium zLabs has discovered a new Android threat campaign, the Schoolyard Bully Trojan, which has been active since 2018 and has spread to over 300,000 victims and is specifically targeting Facebook credentials. To learn more about this new threat, read more on our blog.

zimperium EN 2022 Android Schoolyard-Bully Trojan Facebook schools
Rackspace Cloud Office suffers security breach https://doublepulsar.com/rackspace-cloud-office-suffers-security-breach-958e6c755d7f
05/12/2022 08:52:08
QRCode
archive.org

Thousands of small to medium size businesses are suffering as Rackspace have suffered a security incident on their Hosted Exchange service.

Yesterday, 2nd December 2022, Rackspace announced an outage to their Hosted Exchange Server:

doublepulsar EN 2022 Rackspace Cloud Office breach Exchange
Certpotato – using adcs to privesc from virtual and network service accounts to local system https://sensepost.com/blog/2022/certpotato-using-adcs-to-privesc-from-virtual-and-network-service-accounts-to-local-system/
04/12/2022 11:22:09
QRCode
archive.org

The goal of this blog post is to present a privilege escalation I found while working on ADCS. We will see how it is possible to elevate our privileges to NT AUTHORITY\SYSTEM from virtual and network service accounts of a domain-joined machine (for example from a webshell on a Windows server) using ADCS. I want to call this attack chain “CertPotato” as homage to other *Potato tools and as a way to better remember it.

A popular technique for getting SYSTEM from a virtual or network service account is Delegate 2 Thyself by Charlie Clark. This technique involves using RBCD to elevate your privileges. In this article, I propose an alternative approach to become local SYSTEM using ADCS.

sensepost 2022 EN certpotato adcs privesc escalation
page 172 / 208
4728 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio