Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 173 / 237
Comparison of password strength across top hacking forums (of users that were infected with info-stealing malware) https://old.reddit.com/r/Malware/comments/131kdgb/comparison_of_password_strength_across_top/
01/05/2023 13:50:01
QRCode
archive.org

Comparing the password strength of 5 hacking forum users that were compromised with info-stealers - Hackforums.net,...

reddit r/malware EN 2023 passwords leaks comparison hackforums
LockBit and Cl0p ransomware gangs actively exploiting Papercut vulnerabilities https://www.malwarebytes.com/blog/news/2023/04/lockbit-and-cl0p-are-actively-exploiting-papercut-vulnerabilities
01/05/2023 11:09:49
QRCode
archive.org
thumbnail

Vulnerabilities in PaperCut printing management are being used in ransomware attacks.

malwarebytes EN 2023 malwarebytes lockbit cl0p PaperCut
DOJ Detected SolarWinds Breach Months Before Public Disclosure https://www.wired.com/story/solarwinds-hack-public-disclosure/
29/04/2023 12:10:17
QRCode
archive.org
thumbnail

In May 2020, the US Department of Justice noticed Russian hackers in its network but did not realize the significance of what it had found for six months.

wired EN SolarWinds Russia Detected
Clôture de l’établissement des faits concernant la banque de données de centres privés de dépistage Covid-19 https://www.edoeb.admin.ch/edoeb/fr/home/actualites/medias/medienmitteilungen.msg-id-94662.html
28/04/2023 19:16:04
QRCode
archive.org

Suite à la réception d’un signalement par un particulier, le Préposé a procédé à un établissement des faits concernant une banque de données insuffisamment sécurisée de centres privés de dépistage Covid-19. Dans son rapport final publié ce jour, il a établi que les données de santé traitées dans la banque de données avaient été exposées à des risques de sécurité considérables en raison de la faille signalée. Comme les responsables avaient pris les mesures immédiates appropriées après la découverte de cette faille, le risque pour les personnes concernées a pu être réduit. La procédure est ainsi close sans recommandation.

edoeb CH FR Covid-19 faille confidentialité NCSC
Le Département de la défense et des banques testent le partage confidentiel de données de cybermenace https://www.ictjournal.ch/news/2023-04-28/le-departement-de-la-defense-et-des-banques-testent-le-partage-confidentiel-de
28/04/2023 19:09:15
QRCode
archive.org
thumbnail

Le DDPS annonce avoir achevé un projet pilote de confidential computing avec la BNS, SIX et la Banque cantonale de

ictjournal FR CH DDPS BNS Banque SIX confidentiel confidential-computing
Magecart threat actor rolls out convincing modal forms https://www.malwarebytes.com/blog/threat-intelligence/2023/04/kritec-art
28/04/2023 14:48:41
QRCode
archive.org
thumbnail

To ensnare new victims, criminals will often devise schemes that attempt to look as realistic as possible. Having said that, it is not every day that we see the fraudulent copy exceed the original piece.

While following up on an ongoing Magecart credit card skimmer campaign, we were almost fooled by a payment form that looked so well done we thought it was real. The threat actor used original logos from the compromised store and customized a web element known as a modal to perfectly hijack the checkout page.

malwarebytes EN 2023 Magecart forms analysis
Hackers Leaked Minneapolis Students' Psychological Reports, Allegations of Abuse https://gizmodo.com/ransomware-gang-medusa-data-breach-minneapolis-school-a-1850380421
27/04/2023 22:43:07
QRCode
archive.org
thumbnail

In a hacking episode that is spiraling from bad to worse, cybercriminals have leaked highly sensitive documents related to droves of Minneapolis students.

gizmodo EN 2023 Ransomware leack childrens Education school US Minneapolis
RTM Locker Ransomware as a Service (RaaS) Now on Linux - Uptycs https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux
27/04/2023 13:53:22
QRCode
archive.org
thumbnail

Uptycs threat research team discovered a new ransomware Linux binary attributed to the RTM group Locker, a known Ransomware-as-a-Service (RaaS) provider.

Uptycs EN 2023 ransomware Linux RTM group Locker Ransomware-as-a-Service
Never Connect to RDP Servers Over Untrusted Networks https://www.gosecure.net/blog/2023/04/26/never-connect-to-rdp-servers-over-untrusted-networks/
27/04/2023 13:50:02
QRCode
archive.org
thumbnail

Did you know that RDP is unsafe without the use of additional protection like a VPN? In this blog post we will explain why and demonstrate the impact.

gosecure EN 2023 RDP Untrusted
Mirai Botnet Attackers Exploit TP-Link Router Bug https://duo.com/decipher/mirai-botnet-attackers-exploit-tp-link-bug
26/04/2023 21:43:45
QRCode
archive.org
thumbnail

Researchers began to detect exploit attempts in the wild targeting the patched, high-severity flaw in TP-Link routers starting on April 11.

duo decipher EN 2023 Mirai Exploit TP-Link CVE-2023-1389
Attackers Use Containers for Profit via TrafficStealer https://www.trendmicro.com/en_us/research/23/d/attackers-use-containers-for-profit-via-trafficstealer.html
26/04/2023 21:29:42
QRCode
archive.org
thumbnail

We found TrafficStealer abusing open container APIs in order to redirect traffic to specific websites and manipulate engagement with ads.

trendmicro EN 2023 cloud report Containers TrafficStealer docker
Cyble — Threat Actor Selling New Atomic macOS (AMOS) Stealer on Telegram https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/
26/04/2023 15:07:55
QRCode
archive.org
thumbnail

CRIL analyzes AMOS, a stealthy new information stealer targeting macOS and disseminating stolen information via Telegram.

cyble EN 2023 AMOS macOS stealer Telegram Golang AMOS MacStealer
VMware Patches Critical Vulnerability Disclosed at Pwn2Own Hacking Contest https://www.securityweek.com/vmware-patches-critical-vulnerability-disclosed-at-pwn2own-hacking-contest/
26/04/2023 11:27:38
QRCode
archive.org
thumbnail

VMware this week released patches for a critical vulnerability disclosed at the Pwn2Own Vancouver 2023 hacking contest.

securityweek EN 2023 VMware critical vulnerability Pwn2Own CVE-2023-20869
Gootloader Unloaded: Researchers Launch Multi-Pronged Offensive Against Gootloader, Cutting Off Traffic to Thousands of Gootloader Web Pages and Using the Operator’s Very Own Tactics to Protect End-Users https://www.esentire.com/web-native-pages/gootloader-unloaded
26/04/2023 09:11:35
QRCode
archive.org

eSentire’s Threat Response Unit (TRU), led by researchers Joe Stewart and Keegan Keplinger, have launched a multi-pronged offensive against a growing cyberthreat: the Gootloader Initial Access-as-a-Service Operation. The Gootloader Operation is an expansive cybercrime business, and it has been active since 2018. For the past 15 months, the Gootloader Operator has been launching ongoing attacks targeting legal professionals working for both law firms and corporate legal departments in the U.S., Canada, the U.K. and Australia. Between January and March 2023, TRU shut down Gootloader attacks against 12 different organizations, seven of which were law firms.

esentire EN 2023 Gootloader Access-as-a-Service Offensive hackback
New high-severity vulnerability (CVE-2023-29552) discovered in the Service Location Protocol (SLP) https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp
26/04/2023 08:58:02
QRCode
archive.org

Researchers from Bitsight and Curesec have jointly discovered a high-severity vulnerability — tracked as CVE-2023-29552 — in the Service Location Protocol (SLP)

bitsight EN 2023 CVE-2023-29552 SLP DoS Amplification
Smartphones With Popular Qualcomm Chip Secretly Share Private Information With US Chip-Maker https://www.nitrokey.com/news/2023/smartphones-popular-qualcomm-chip-secretly-share-private-information-us-chip-maker
25/04/2023 22:43:43
QRCode
archive.org
thumbnail

During our security research we found that smart phones with Qualcomm chip secretly send personal data to Qualcomm. This data is sent without user consent, unencrypted, and even when using a Google-free Android distribution. This is possible because the Qualcomm chipset itself sends the data, circumventing any potential Android operating system setting and protection mechanisms. Affected smart phones are Sony Xperia XA2 and likely the Fairphone and many more Android phones which use popular Qualcomm chips.

nitrokey EN 2023 privacy Qualcomm Chip Secretly Share
PSA: upgrade your LUKS key derivation function https://mjg59.dreamwidth.org/66429.html
23/04/2023 11:23:25
QRCode
archive.org

Here's an article from a French anarchist describing how his (encrypted) laptop was seized after he was arrested, and material from the encrypted partition has since been entered as evidence against him. His encryption password was supposedly greater than 20 characters and included a mixture of cases, numbers, and punctuation, so in the absence of any sort of opsec failures this implies that even relatively complex passwords can now be brute forced, and we should be transitioning to even more secure passphrases.

Or does it? Let's go into what LUKS is doing in the first place. The actual data is typically encrypted with AES, an extremely popular and well-tested encryption algorithm. AES has no known major weaknesses and is not considered to be practically brute-forceable - at least, assuming you have a random key. Unfortunately it's not really practical to ask a user to type in 128 bits of binary every time they want to unlock their drive, so another approach has to be taken.

mjg59 EN Linux LUKS KDF cracked police encryption password AES
Meet the hacker armies on Ukraine's cyber front line https://www.bbc.com/news/technology-65250356
23/04/2023 00:35:55
QRCode
archive.org
thumbnail

How links between ‘hacktivists’ and official military are becoming blurred on both sides in the war.

bbc EN 2023 hacktivists military Ukraine cyberarmy vigilante Telegram russia-ukraine-war
Analysis of Pre-Auth RCE in Sophos Web Appliance (CVE-2023-1671) https://vulncheck.com/blog/cve-2023-1671-analysis
22/04/2023 20:04:20
QRCode
archive.org
thumbnail

CVE-2023-1671 is a pre-authenticated command injection in Sophos Web Appliance. In this blog post, VulnCheck researchers analyze the vulnerability and develop a proof of concept (PoC) for it.

vulncheck EN 2023 analysis vulnerability Sophos CVE-2023-1671 pre-authenticated command injection
Software Maker 3CX Was Compromised in First-of-its-Kind Threaded Supply-Chain Hack https://zetter.substack.com/p/software-maker-3cx-was-compromised
22/04/2023 17:28:04
QRCode
archive.org
thumbnail

Hackers first compromised a different software maker and embedded malware in one of its programs. 3CX got compromised when a worker downloaded that program. It's not known why worker downloaded it.

zetter EN 2023 3CX Supply-Chain-Attack
page 173 / 237
4737 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio