Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 183 / 238
Lumma Stealer targets YouTubers via Spear-phishing Email | by S2W | S2W BLOG | Feb, 2023 | Medium https://medium.com/s2wblog/lumma-stealer-targets-youtubers-via-spear-phishing-email-ade740d486f7
01/03/2023 20:57:15
QRCode
archive.org
thumbnail

Lumma Stealer sellers use the name “LummaC” on an underground forum called XSS, which is based in Russia. The seller has been actively promoting the malware since April 2022. In August of that year…

s2wblog EN 2023 LummaC Stealer analysis
Intrusion dans les systèmes d'information de la Ville de Lille : le point sur la situation https://www.lille.fr/Actualites/Intrusion-dans-les-systemes-d-information-de-la-Ville-de-Lille-le-point-sur-la-situation
01/03/2023 19:42:01
QRCode
archive.org
thumbnail

A cette heure, le diagnostic technique est toujours en cours pour déterminer l'origine et la gravité de l'intrusion.
L'ensemble des services publics est maintenu, à l'Hôtel de Ville, dans les mairies de quartiers et l'ensemble de nos équipements avec un fonctionnement adapté.

Selon les informations dont nous disposons à ce stade, aucune difficulté n'a été constatée sur les données stockées sur le système et les serveurs.

lille FR 2023 Intrusion
U.S. Marshals Service hack compromises sensitive info https://www.nbcnews.com/politics/politics-news/major-us-marshals-service-hack-compromises-sensitive-info-rcna72581
28/02/2023 21:28:19
QRCode
archive.org
thumbnail

The U.S. Marshals Service suffered a security breach, with sensitive data taken from one of its systems just over a week ago.

nbcnews 2023 EN US Marshals breach ransomware
Hackers Claim They Breached T-Mobile More Than 100 Times in 2022 https://krebsonsecurity.com/2023/02/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022/
28/02/2023 21:19:27
QRCode
archive.org

Three different cybercriminal groups claimed access to internal networks at communications giant T-Mobile in more than 100 separate incidents throughout 2022, new data suggests. In each case, the goal of the attackers was the same: Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device.

krebsonsecurity EN 2023 T-Mobile Hackers Claim
The Cyber Defense Assistance Imperative – Lessons from Ukraine https://www.aspeninstitute.org/publications/the-cyber-defense-assistance-imperative-lessons-from-ukraine/
28/02/2023 15:26:27
QRCode
archive.org

Russia’s further invasion of Ukraine in February 2022 was a watershed moment, and unique in that a major nation-state had engaged in coordinated, convergent digital and physical attacks in an effort to conquer a neighboring country. Leaders will draw lessons from this conflict for years, but one is already clear: the ability to deliver cyber defense assistance must be a key national security capability.

aspeninstitute EN 2023 Ukraine russia-ukraine-war CyberDefense assistance
Danish parliament urges to remove TikTok over cybersecurity https://apnews.com/article/technology-politics-denmark-government-mobile-apps-europe-41d1cf56a492ea9c6e0f7885c866e131
28/02/2023 14:32:36
QRCode
archive.org
thumbnail

COPENHAGEN, Denmark (AP) — The Danish parliament on Tuesday urged lawmakers and employees with the 179-member assembly against having TikTok on work phones as a cybersecurity measure, saying “there is a risk of espionage.”

apnews EN 2023 Denmark tiktok ban
LastPass breach update: The few additional bits of information https://palant.info/2023/02/28/lastpass-breach-update-the-few-additional-bits-of-information/
28/02/2023 14:22:33
QRCode
archive.org
thumbnail

LastPass breach was aided by lax security policy, allowing accessing critical data from a home computer. Also, companies implementing federated login are also affected by the breach, despite LastPass originally denying it.

palant.info EN 2023 breach LastPass
Canada bans TikTok on government devices https://www.bbc.com/news/world-us-canada-64792894
28/02/2023 13:01:31
QRCode
archive.org
thumbnail
bbc en 2023 tiktok ban canada
Man stole nearly $18K in electricity in crypto mining operation https://www.dailymail.co.uk/news/article-11790153/Man-stole-nearly-18K-electricity-crypto-mining-operation.html
27/02/2023 21:17:31
QRCode
archive.org

Nadeam Nahas, 39, of Norwell, MA is facing charges of allegedly running a secret cryptocurrency mining operation out of a crawlspace at a middle school.

dailymail EN 2023 Massachusetts school cryptocurrency cryptomining stealing electricity
Hard-to-spot Mac crypto-mining threat, XMRig, hits Pirate Bay https://www.computerworld.com/article/3689149/hard-to-spot-mac-crypto-mining-threat-xmrig-hits-pirate-bay.html
27/02/2023 21:14:56
QRCode
archive.org
thumbnail

Jamf Threat Labs has spotted a family of Mac malware, XMRig, that spreads through pirated versions of Final Cut Pro, Photoshop and Logic Pro X.

computerworld EN 2023 apple macos jamf XMRig malware pirated FinalCutPro
PureCrypter targets government entities through Discord - Blog | Menlo Security https://www.menlosecurity.com/blog/purecrypter-targets-government-entities-through-discord/
27/02/2023 21:13:31
QRCode
archive.org
thumbnail

Menlo Labs has uncovered an unknown threat actor leveraging an evasive threat campaign distributed via Discord featuring the PureCrypter downloader and targeting government entities.

menlosecurity EN 2023 PureCrypter government Discord downloader analysis
Stanford University discloses data breach affecting PhD applicants https://www.bleepingcomputer.com/news/security/stanford-university-discloses-data-breach-affecting-phd-applicants/
27/02/2023 21:11:03
QRCode
archive.org
thumbnail

Stanford University disclosed a data breach after files containing Economics Ph.D. program admission information were downloaded from its website between December 2022 and January 2023.

bleepingcomputer EN 2023 Data-Breach Stanford University breach
Technical Advisory: Various Threat Actors Targeting ManageEngine Exploit CVE-2022-47966 https://businessinsights.bitdefender.com/tech-advisory-manageengine-cve-2022-47966
27/02/2023 21:05:45
QRCode
archive.org
thumbnail

Numerous threat actors were detected abusing a critical CVE-2022-47966 RCE vulnerability affecting products from ManageEngine. Read our advisory.

bitdefender EN 2023 CVE-2022-47966 RCE vulnerability ManageEngine advisory
TA569: SocGholish and Beyond https://www.proofpoint.com/us/blog/threat-insight/ta569-socgholish-and-beyond
27/02/2023 21:01:50
QRCode
archive.org
thumbnail
  • TA569 leverages many types of injections, traffic distribution systems (TDS), and payloads including, but not limited to, SocGholish.
  • In addition to serving as an initial access broker, these additional injects imply TA569 may be running a pay-per-install (PPI) service
  • TA569 may remove injections from compromised websites only to later re-add them to the same websites.
  • There are multiple opportunities for defense against TA569: educating users about the activity, using Proofpoint’s Emerging Threats ruleset to block the payload domains, and blocking .js files from executing in anything but a text editor.
proofpoint EN 2023 SocGholish threat-insight TA569 analysis
EXFILTRATOR-22 - An Emerging Post-Exploitation Framework https://www.cyfirma.com/outofband/exfiltrator-22-an-emerging-post-exploitation-framework/
27/02/2023 20:58:42
QRCode
archive.org
thumbnail

Executive Summary The CYFIRMA Research team has provided a preliminary analysis of a new post- exploitation framework called EXFILTRATOR-22 a.k.a....

cyfirma EN 2023 EXFILTRATOR-22 analysis post-exploitation framework
Cryptomonnaie: arrestation de deux Français suspectés d’avoir piraté la plateforme Platypus https://www.lematin.ch/story/arrestation-de-deux-francais-suspectes-davoir-pirate-la-plateforme-platypus-874095416130
27/02/2023 20:51:15
QRCode
archive.org
thumbnail

Les deux hommes interpellés mercredi en région parisienne, des frères de 18 et 20 ans, ont causé pour 9,5 millions de dollars de préjudice à la société américaine de finance décentralisée.

lematin FR 2023 Cryptomonnaie Platypus Français interpellés piraté cryptomonnaie
OneNote Embedded file abuse https://blog.nviso.eu/2023/02/27/onenote-embedded-file-abuse/
27/02/2023 13:41:35
QRCode
archive.org
thumbnail

In recent weeks OneNote has gotten a lot of media attention as threat actors are abusing the embedded files feature in OneNote in their phishing campaigns.
I first observed this OneNote abuse in the media via Didier’s post. This was later also mentioned in Xavier’s ISC diary and on the podcast. Later, in the beginning of February, the hacker news covered this as well.

nviso EN 2023 OneNote abuse technical report
When Low-Tech Hacks Cause High-Impact Breaches https://krebsonsecurity.com/2023/02/when-low-tech-hacks-cause-high-impact-breaches/
27/02/2023 11:52:55
QRCode
archive.org

Web hosting giant GoDaddy made headlines this month when it disclosed that a multi-year breach allowed intruders to steal company source code, siphon customer and employee login credentials, and foist malware on customer websites. Media coverage understandably focused on GoDaddy's…

krebsonsecurity EN 2023 GoDaddy Hacks intruders employee malware
Suspect in major data theft case linked to Dutch-subsidized cybersecurity org https://nltimes.nl/2023/02/24/suspect-major-data-theft-case-linked-dutch-subsidized-cybersecurity-org-report
26/02/2023 17:56:54
QRCode
archive.org
thumbnail

One of three hackers recently arrested for large-scale data theft was active for cyber security organization DIVD, sources told NOS. DIVD is a government-subsidized association of Dutch security experts that researches unsafe computer systems.

nltimes EN 2023 DIVD arrsted hackers Dutch NL
Dole Experiences Cybersecurity Incident https://www.dole.com/en/press/2023/dole-experiences-cybersecurity-incident
25/02/2023 16:46:17
QRCode
archive.org

Charlotte, NC – February 22, 2023– Dole plc (DOLE:NYSE) announced today that the company recently experienced a cybersecurity incident that has been identified as ransomware.

dole 2023 En incident Security-Incident ransomware
page 183 / 238
4749 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio