Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 175 / 237
CVE-2023-21554: MSMQ https://censys.wpengine.com/cve-2023-21554/
17/04/2023 21:46:05
QRCode
archive.org
thumbnail

On April 12th, 2023, Microsoft released a slew of new patches for its Windows operating system, one of which was to fix CVE-2023-21554, a remotely-exploitable vulnerability in the obscure Windows Message Queuing (MSMQ) service that can lead to remote code execution (RCE).

Censys EN 2023 cve-2023-21554 MSMQ graphs metrics
Analyzing an arm64 mach-O version of LockBit https://objective-see.org/blog/blog_0x75.html
17/04/2023 21:39:29
QRCode
archive.org
thumbnail

The relevance of this macOS specimen is well articulated in their tweet:

“Lockbit ransomware group has created their first MacOS-based payload. We believe this is the first time a large ransomware threat group has developed a payload for Apple products.” vx-underground

Ok, so even though it’s the weekend, we have what appears to be a new macOS malware specimen from one of the more notorious ransomware gangs! Coupled with the fact that this may be, (as noted by @VXUnderground), “the first time a large ransomware threat group has developed a payload for Apple products” …I was intrigued to decided to dig right in!

objective-see EN 2023 LockBit macOS analysis
Linux kernel logic allowed Spectre attack on major cloud https://www.theregister.com/2023/04/14/linux_kernel_spectre_flaw_fixed/
17/04/2023 07:02:47
QRCode
archive.org
thumbnail

Kernel 6.2 ditched a useful defense against ghostly chip design flaw

theregister EN 2023 Spectre Kernel Linux cloud
Google Chrome emergency update fixes first zero-day of 2023 https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-first-zero-day-of-2023/
16/04/2023 23:40:34
QRCode
archive.org
thumbnail

Google has released an emergency Chrome security update to address the first zero-day vulnerability exploited in attacks since the start of the year.

bleepingcomputer EN 2023 0-day vulnerability Emergency-Update Chrome Browser Zero-Day
Remote Code Execution Vulnerability in Google They Are Not Willing To Fix https://giraffesecurity.dev/posts/google-remote-code-execution/
16/04/2023 22:03:00
QRCode
archive.org

This is a story about a security vulnerability in Google that allowed me to run arbitrary code on the computers of 50+ Google employees. Although Google initially considered my finding a serious security incident, later on, it changed its mind and stated that my finding is not, in fact, a vulnerability, but the intended behavior of their software.

giraffesecurity EN 2023 vulnerability disclosure Google RCE intended
Introducing: Red Canary Mac Monitor https://redcanary.com/blog/mac-monitor/
16/04/2023 12:12:26
QRCode
archive.org

Mac Monitor is Red Canary’s newly available tool for collection and dynamic system analysis on macOS endpoints.
Red Canary Mac Monitor is a feature-rich dynamic analysis tool for macOS that leverages our extensive understanding of the platform and Apple’s latest APIs to collect and present relevant security events. Mac Monitor is practically the macOS version of the Microsoft Sysinternals tool, Procmon. Mac Monitor collects a wide variety of telemetry classes, including processes, interprocess, files, file metadata, logins, XProtect detections, and more—enabling defenders to quickly and effectively analyze enriched, high-fidelity macOS security events in a native, modern, and customizable user interface

redcanary EN 2023 tool Monitor announce macOS monitoring Sysinternals Procmon
The (Not so) Secret War on Discord https://www.cyberark.com/resources/threat-research-blog/the-not-so-secret-war-on-discord
16/04/2023 11:44:17
QRCode
archive.org
thumbnail

CyberArk Labs discovered a new malware called Vare that is distributed over the popular chatting service, Discord. Vare has been used to target new malware operators by using social engineering tactics on them. Additionally, we have found that Vare uses Discord’s infrastructure as a backbone for its operations. This malware is linked to a new group called “Kurdistan 4455” based out of southern Turkey and is still early in its forming stage.

cyberark EN 2023 Discord Vare malware Kurdistan4455 Turkey
A Computer Generated Swatting Service Is Causing Havoc Across America https://www.vice.com/en/article/k7z8be/torswats-computer-generated-ai-voice-swatting
16/04/2023 01:01:45
QRCode
archive.org
thumbnail

As the U.S. deals with a nationwide swatting wave, Motherboard has traced much of the activity to a particular swatting-as-a-service account on Telegram. Torswats uses synthesized voices to pressure law enforcement to specific locations.

vice EN 2023 Swatting swatting-as-a-service Telegram synthesized
Espionage campaign linked to Russian intelligence services https://www.gov.pl/web/baza-wiedzy/espionage-campaign-linked-to-russian-intelligence-services
15/04/2023 14:45:32
QRCode
archive.org
thumbnail

The Military Counterintelligence Service and the CERT Polska team (CERT.PL) observed a widespread espionage campaign linked to Russian intelligence services

gov.pl EN 2023 CERT.PL Poland Russian Espionage campaign Russia Counterintelligence
New hacker advocacy group seeks to protect work of security researchers https://cyberscoop.com/new-hacker-advocacy-group-seeks-to-protect-work-of-security-researchers/
15/04/2023 10:25:21
QRCode
archive.org
thumbnail

"There are advocacy groups for reptile owners but not hackers, so that seems like a miss," said Ilona Cohen of HackerOne.

cyberscoop EN 2023 hacker advocacy HackerOne researchers legal
Vice Society: A Tale of Victim Data Exfiltration via PowerShell, aka Stealing off the Land https://unit42.paloaltonetworks.com/vice-society-ransomware-powershell/
14/04/2023 21:50:12
QRCode
archive.org
thumbnail

The Vice Society ransomware gang exfiltrated victim network data using a custom Microsoft PowerShell script. We dissect how each function of it works.

unit42 EN 2023 report analysis ViceSociety PowerShell
Hackers claim vast access to Western Digital systems https://techcrunch.com/2023/04/13/hackers-claim-vast-access-to-western-digital-systems/
14/04/2023 14:54:41
QRCode
archive.org
thumbnail

One of the hackers who breached Western Digital provided some details about the hack, the data stolen, and what the hackers are demanding.

techcrunch EN 2023 WD extortion western-digital hack
En Suisse comme en France, la vidéosurveillance progresse à une vitesse fulgurante https://www.letemps.ch/economie/suisse-france-videosurveillance-progresse-une-vitesse-fulgurante
14/04/2023 13:02:40
QRCode
archive.org
thumbnail

Le parlement français a adopté une loi autorisant la vidéosurveillance algorithmique, très décriée. A Genève, une étude montre l’opacité autour des caméras de surveillance, qui se multiplient

letemps FR 2023 videosurveillance algorithmique caméras surveillance privacy
Discord member details how documents leaked from closed chat group https://www.washingtonpost.com/national-security/2023/04/12/discord-leaked-documents/
14/04/2023 01:13:44
QRCode
archive.org
thumbnail

The man behind a massive leak of U.S. government secrets that has exposed spying on allies, revealed the grim prospects for Ukraine’s war with Russia and ignited diplomatic fires for the White House is a young, charismatic gun enthusiast who shared highly classified documents with a group of far-flung acquaintances searching for companionship amid the isolation of the pandemic.

washingtonpost EN 2023 leak US Discord chat government secrets
Nokoyawa ransomware attacks with Windows zero-day https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/
12/04/2023 10:01:11
QRCode
archive.org
thumbnail

in February 2023, Kaspersky technologies detected a number of attempts to execute similar elevation-of-privilege exploits on Microsoft Windows servers belonging to small and medium-sized businesses in the Middle East, in North America, and previously in Asia regions. These exploits were very similar to already known Common Log File System (CLFS) driver exploits that we analyzed previously, but we decided to double check and it was worth it – one of the exploits turned out to be a zero-day, supporting different versions and builds of Windows, including Windows 11. The exploit was highly obfuscated with more than 80% of the its code being “junk” elegantly compiled into the binary, but we quickly fully reverse-engineered it and reported our findings to Microsoft. Microsoft assigned CVE-2023-28252 to the Common Log File System elevation-of-privilege vulnerability, and a patch was released on April 11, 2023, as part of April Patch Tuesday.

securelist EN 2023 Nokoyawa zero-day Kaspersky CVE-2023-28252 analysis ransomware CLFS
Microsoft’s April 2023 Patch Tuesday Addresses 97 CVEs (CVE-2023-28252) https://www.tenable.com/blog/microsofts-april-2023-patch-tuesday-addresses-97-cves-cve-2023-28252
12/04/2023 09:58:46
QRCode
archive.org
thumbnail

Microsoft addresses 97 CVEs, including one that was exploited in the wild as a zero day

tenable EN 2023 PatchTuesday april zero-day microsoft list
Queuejumper: Critical Unauthorized RCE Vulnerability In MSMQ Service https://research.checkpoint.com/2023/queuejumper-critical-unauthorized-rce-vulnerability-in-msmq-service/
12/04/2023 01:01:43
QRCode
archive.org

Check Point Research recently discovered three vulnerabilities in the “Microsoft Message Queuing” service, commonly known as MSMQ. These vulnerabilities were disclosed to Microsoft and patched in the April Patch Tuesday update. The most severe of these, dubbed QueueJumper by CPR (CVE-2023-21554), is a critical vulnerability that could allow unauthorized attackers to remotely execute arbitrary code in the context of the Windows service process mqsvc.exe.

checkpoint EN 2023 analysis RCE Queuejumper CVE-2023-21554 MSMQ Service Critical PatchTuesday
DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/
11/04/2023 18:37:46
QRCode
archive.org
thumbnail

Microsoft analyzes a threat group tracked as DEV-0196, the actor’s iOS malware “KingsPawn”, and their link to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infrastructure called REIGN, that’s designed to exfiltrate data from mobile devices.

microsoft EN 2023 QuaDream spyware spy IoCs DEV-0196 iOS calendar zero-click REIGN
Sweet QuaDreams: A First Look at Spyware Vendor QuaDream’s Exploits, Victims, and Customers - The Citizen Lab https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/
11/04/2023 18:34:14
QRCode
archive.org
thumbnail

At least five civil society victims of QuaDream’s spyware and exploits were identified in North America, Central Asia, Southeast Asia, Europe, and the Middle East. Victims include journalists, political opposition figures, and an NGO worker. Traces of a suspected iOS 14 zero-click exploit used to deploy QuaDream’s spyware.

CitizenLab EN 2023 QuaDreams Spyware spyware spy iPhone calendar zero-click
Mercenary spyware hacked iPhone victims with rogue calendar invites, researchers say | TechCrunch https://techcrunch.com/2023/04/11/quadream-spyware-hacked-iphones-calendar-invites/
11/04/2023 18:32:54
QRCode
archive.org
thumbnail

Researchers found malware developed by QuaDream, a little-known government spyware maker, which was used against journalists and politicians.

techcrunch EN 2023 security apple cybersecurity hackers hacking ios iphone spyware zero-days
page 175 / 237
4737 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio