Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 176 / 237
Balada Injector: Synopsis of a Massive Ongoing WordPress Malware Campaign https://blog.sucuri.net/2023/04/balada-injector-synopsis-of-a-massive-ongoing-wordpress-malware-campaign.html
10/04/2023 21:07:18
QRCode
archive.org
thumbnail

A synopsis of the massive ongoing WordPress malware campaign: Balada Injector, including common techniques, functionalities, and vulnerability exploits used in attacks.

sucuri EN 2023 Wordpress campaigns Balada Injector analysis exploits
Data-leak flaw in Qualcomm, HiSilicon-based Wi-Fi AP chips https://www.theregister.com/2023/04/07/wifi_access_icmp/
10/04/2023 18:55:48
QRCode
archive.org
thumbnail

WPA stands for will-provide-access, if you can successfully exploit a target's setup

theregister EN 2023 Qualcomm Data-leak flaw Wi-Fi AP chips CVE-2022-25667
MERCURY and DEV-1084: Destructive attack on hybrid environment - Microsoft Security Blog https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/
10/04/2023 18:46:22
QRCode
archive.org
thumbnail

Microsoft detected a unique operation where threat actors carried out destructive actions in both on-premises and cloud environments.

microsoft EN 2023 MERCURY DEV-1084 analysis cloud hybrid environment Iran TTPs operation
Cyble — Demystifying Money Message Ransomware  https://blog.cyble.com/2023/04/06/demystifying-money-message-ransomware/
10/04/2023 18:44:46
QRCode
archive.org
thumbnail

CRIL analyses the anatomy of a new ransomware group named Money Message, which can encrypt network shares and target both Windows and Linux.

cyble EN 2023 MoneyMessage ransomware analysis
Water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation. https://www.jpost.com/israel-news/article-738790
10/04/2023 11:31:45
QRCode
archive.org

Several water monitors – which monitor irrigation systems and wastewater treatment systems – were left dysfunctional on Sunday after a cyber attack targeted the monitoring systems.

Specifically, water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation.

jpost EN 2023 Water Galil Sewage Corporation monitors cyber attack controllers hacked
Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company https://zetter.substack.com/p/leaked-pentagon-document-claims-russian
09/04/2023 22:16:55
QRCode
archive.org
thumbnail

The document, part of a cache of leaks recently circulated on the internet, suggests the hackers had the ability to cause an explosion and sought instruction from the FSB.

Zetter EN 2023 FSB pipeline Russia hack FSB Zarya
From Discord to 4chan: The Improbable Journey of a US Intelligence Leak - bellingcat https://www.bellingcat.com/news/2023/04/09/from-discord-to-4chan-the-improbable-journey-of-a-us-defence-leak/
09/04/2023 10:58:41
QRCode
archive.org
thumbnail

In recent days, the US Justice Department and Pentagon have begun investigating an apparent online leak of sensitive documents, including some that were marked “Top Secret”.

A portion of the documents, which have since been widely covered by the news media, focused on Russia’s invasion of Ukraine, while others detailed analysis of potential UK policies on the South China Sea and the activities of a Houthi figure in Yemen.

The existence of the documents was first reported by the New York Times after a number of Russian Telegram channels shared five photographed files relating to the invasion of Ukraine on April 5 – at least one of which has since been found by Bellingcat to be crudely edited.

bellingcat EN 2023 leak 4chan discord US topsecret sensitive document Russia NYT Ukraine
MSI Confirms Breach as Ransomware Gang Claims Responsibility https://www.pcmag.com/news/msi-confirms-breach-as-ransomware-gang-claims-responsibility
08/04/2023 19:25:30
QRCode
archive.org
thumbnail

UPDATE: A new statement(Opens in a new window) from MSI says users should avoid downloading firmware and BIOS updates from third-party sources, and instead only obtain such software from the company's official website.

The statement suggests MSI is worried hackers could circulate malicious versions of the company's BIOS software when the ransomware gang, Money Message, claims it stole the PC maker's source code.

pcmag EN 2023 MSI hacked BIOS PCmaker software statement
L'Anssi pourra bloquer les noms de domaine liés à des cyberattaques https://www.usine-digitale.fr/article/cyberattaque.N2119866
08/04/2023 10:30:44
QRCode
archive.org
thumbnail

La loi de programmation militaire prévoit que l'autorité n'aura pas besoin d'une décision de justice. Un contrôle sera réalisé a posteriori par l'Arcep.

usine-digitale FR 2023 ANSSI saisie noms DNS domaines cyberattaque militaire
Exploit available for critical bug in VM2 JavaScript sandbox library https://www.bleepingcomputer.com/news/security/exploit-available-for-critical-bug-in-vm2-javascript-sandbox-library/
08/04/2023 01:43:08
QRCode
archive.org
thumbnail

Proof-of-concept exploit code has been released for a recently disclosed critical vulnerability in the popular VM2 library, a JavaScript sandbox that is used by multiple software to run code securely in a virtualized environment.

bleepingcomputer Code-Execution Sandbox Sandbox-Escape JavaScript Virtualization VM2 PoC CVE-2023-29017
Samsung Fab Workers Leak Confidential Data While Using ChatGPT https://www.tomshardware.com/news/samsung-fab-workers-leak-confidential-data-to-chatgpt
08/04/2023 01:33:57
QRCode
archive.org
thumbnail

Samsung fab personnel reportedly used ChatGPT to optimize operations and create presentations, leaking confidential data to the third-party AI.

tomshardware EN 2023 Samsung ChatGPT Leak
Cyble — New Cylance Ransomware with Power-Packed CommandLine Options https://blog.cyble.com/2023/04/07/new-cylance-ransomware-with-power-packed-commandline-options/
08/04/2023 01:16:28
QRCode
archive.org
thumbnail

CRIL analyzes Cylance, a new Ransomware variant that uses command-line options to target both Windows and Linux users.

cyble EN 2023 Ransomware Cylance
ALPHV Ransomware Affiliate Targets Vulnerable Backup Installations to Gain Initial Access https://www.mandiant.com/resources/blog/alphv-ransomware-backup
08/04/2023 01:09:27
QRCode
archive.org
thumbnail

A ransomware affiliate is targeting publicly exposed Veritas installations to gain access to organizations.

mandiant EN 2023 ALPHV Ransomware Affiliate Vulnerable Backup Veritas
Special Report: Tesla workers shared sensitive images recorded by customer cars | Reuters https://www.reuters.com/technology/tesla-workers-shared-sensitive-images-recorded-by-customer-cars-2023-04-06/
08/04/2023 01:01:19
QRCode
archive.org
thumbnail

Between 2019 and 2022, groups of Tesla employees privately shared via an internal messaging system sometimes highly invasive videos and images recorded by customers’ car cameras.

reuters EN 2023 Tesla privacy workers privately customers car
Apple fixes two zero-days exploited to hack iPhones and Macs https://www.bleepingcomputer.com/news/apple/apple-fixes-two-zero-days-exploited-to-hack-iphones-and-macs/
07/04/2023 20:29:05
QRCode
archive.org
thumbnail

Apple has released emergency security updates to address two new zero-day vulnerabilities exploited in attacks to compromise iPhones, Macs, and iPads.

Apple EN 2023 updates zero-day vulnerabilities ios macos
Stopping cybercriminals from abusing security tools https://blogs.microsoft.com/on-the-issues/2023/04/06/stopping-cybercriminals-from-abusing-security-tools/
06/04/2023 23:57:40
QRCode
archive.org
thumbnail

Microsoft’s Digital Crimes Unit (DCU), cybersecurity software company Fortra™ and Health Information Sharing and Analysis Center (Health-ISAC) are taking technical and legal action to disrupt cracked, legacy copies of Cobalt Strike and abused Microsoft software, which have been used by cybercriminals to distribute malware, including ransomware. This is a change in the way DCU has...

microsoft EN 2023 CobaltStrike Fortra ISAC security tools abusing statement
Resecurity uncovers STYX, new cybercriminal platform focused on financial fraud - Help Net Security https://www.helpnetsecurity.com/2023/04/06/resecurity-uncovers-styx-cybercriminal-platform/
06/04/2023 08:32:32
QRCode
archive.org
thumbnail

Resecurity has recently identified the STYX Innovation Marketplace, a new cybercriminal e-commerce platform focused on financial fraud.

helpnetsecurity 2023 EN STYX Marketplace financial fraud cybercriminal e-commerce
Mac Malware MacStealer Spreads as Fake P2E Apps https://www.trendmicro.com/en_us/research/23/c/mac-malware-macstealer-spreads-as-fake-p2-e-apps.html
05/04/2023 21:03:16
QRCode
archive.org
thumbnail

We detected Mac malware MacStealer spreading via websites, social media, and messaging platforms Twitter, Discord, and Telegram. Cybercriminals lure victims to download it by plagiarizing legitimate play-to-earn (P2E) apps’ images and offering jobs as beta testers.

trendmicro EN 2023 MacStealer malware macos report Telegram Twitter P2E Mac
Troy Hunt: Seized Genesis Market Data is Now Searchable in Have I Been Pwned, Courtesy of the FBI and "Operation Cookie Monster" https://www.troyhunt.com/seized-genesis-market-data-is-now-searchable-in-have-i-been-pwned-courtesy-of-the-fbi-and-operation-cookie-monster/
05/04/2023 14:05:30
QRCode
archive.org
thumbnail

A quick summary first before the details: This week, the FBI in cooperation with international law enforcement partners took down a notorious marketplace trading in stolen identity data in an effort they've named "Operation Cookie Monster". They've provided millions of impacted email addresses and passwords to Have I Been Pwned

troyhunt EN 2023 Seized Genesis Market Data FBI HaveIBeenPowned
Rilide: A New Malicious Browser Extension for Stealing Cryptocurrencies https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/rilide-a-new-malicious-browser-extension-for-stealing-cryptocurrencies/
05/04/2023 08:59:27
QRCode
archive.org
thumbnail

Trustwave SpiderLabs uncovered a new strain of malware that it dubbed Rilide, which targets Chromium-based browsers such as Google Chrome, Microsoft Edge, Brave, and Opera.

trustwave c2023 EN Cryptocurrencies Rilide Stealer-Extension Chromium-based Browser RAT Ekipa Extension
page 176 / 237
4737 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio