Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 183 / 251
Malicious VSCode extensions with more than 45K downloads steal PII and enable backdoors - Check Point Blog https://blog.checkpoint.com/securing-the-cloud/malicious-vscode-extensions-with-more-than-45k-downloads-steal-pii-and-enable-backdoors/
16/05/2023 22:04:01
QRCode
archive.org
thumbnail

Highlights: CloudGuard Spectrals detected malicious extensions on the VSCode marketplace Users installing these extensions were enabling attackers to

checkpoint EN 2023 VSCode extensions malicious
Review and analysis of fake Trezor cryptowallet https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/
15/05/2023 21:56:00
QRCode
archive.org
thumbnail

Fake hardware cryptowallet, and how bitcoins were stolen from it.

kaspersky EN 2023 hardware-wallet trezor fake scam hardware wallet
FBI confirms access to Breached cybercrime forum database https://medium.com/@spixnet.gmbh/fbi-confirms-access-to-breached-cybercrime-forum-database-a12c839e9621
15/05/2023 21:21:07
QRCode
archive.org
thumbnail

Today, the FBI confirmed they have access to the database of the notorious BreachForums (aka Breached) hacking forum after the U.S. Justice Department also officially announced the arrest of its…

@spixnet.gmbh EN 2023 Breached FBI confirmed database Pompompurin
Securonix Threat Labs Security Advisory: Latest Update: Ongoing MEME#4CHAN Attack/Phishing Campaign uses Meme-Filled Code to Drop XWorm Payloads https://www.securonix.com/blog/securonix-threat-labs-security-meme4chan-advisory/
15/05/2023 21:16:07
QRCode
archive.org
thumbnail

An unusual attack/phishing campaign delivering malware while using meme-filled code and complex obfuscation methods continues dropping Xworm payloads for the last few months and is still ongoing today.

securonix EN 2023 XWorm Payloads MEME#4CHAN Phishing Meme-Filled
WordPress Plugin Vulnerability Exposed Ferrari Website to Hackers https://www.securityweek.com/wordpress-plugin-vulnerability-exposed-ferrari-website-to-hackers/
15/05/2023 13:41:19
QRCode
archive.org
thumbnail

A vulnerability in a WordPress plugin exposed the official website of sports car maker Ferrari to hacker attacks.

securityweek EN 2023 WordPress Ferrari vulnerability
Hackers offer personal information of 500,000 Israeli students for sale https://www.ynetnews.com/business/article/syj115nrnn
15/05/2023 11:28:15
QRCode
archive.org
thumbnail

Weeks after breach of college chain Atid servers, hacker group Sharp Boys puts stolen information up for sale and releases additional data of students; Atid: ‘These are Iranian hackers, and most of the materials are outdated’

ynetnews EN 2023 israel breach students school Atid SharpBoys stolen
Ex-ByteDance Executive Accuses TikTok Parent Company of ‘Lawlessness’ https://archive.ph/a0Qbc
14/05/2023 18:47:37
QRCode
archive.org
thumbnail

The former executive sued ByteDance, which owns TikTok, for wrongful termination and accused the company of lifting content from rivals and “supreme access” by the Chinese Communist Party.

NYT EN 2023 TikTok Lawlessness ByteDance privacy supreme-access China
How an Indiana hospital fought to recover from a cyberattack https://www.npr.org/sections/health-shots/2023/05/08/1172569347/cyberattacks-on-health-care-are-increasing-inside-one-hospitals-fight-to-recover
14/05/2023 18:34:32
QRCode
archive.org
thumbnail

It was October 2021 and the staff at Johnson Memorial Health were hoping they could finally catch their breaths. They were just coming out of a weeks-long surge of COVID hospitalizations and deaths, fueled by the Delta variant.

npr EN 2023 Indiana US hospital cyberattack recover Health
The Race to Patch: Attackers Leverage Sample Exploit Code in Wordpress Plugin | Akamai https://www.akamai.com/blog/security-research/attackers-leverage-sample-exploit-wordpress-plugin
14/05/2023 17:20:39
QRCode
archive.org
thumbnail

The time for attackers to respond to known vulnerabilities is shrinking. See an example of an attacker using sample code.

  • The Akamai Security Intelligence Group (SIG) has been analyzing attack attempt activity following the announcement of a critical vulnerability in a WordPress custom fields plug-in affecting more than 2 million sites.

  • Exploiting this vulnerability could lead to a reflected cross-site scripting (XSS) attack, in which malicious code is injected into a victim site and pushed to its visitors.

  • On May 4, 2023, the WP Engine team announced the security fix in version 6.1.6, including sample exploit code as a proof of concept (PoC).

  • Starting on May 6, less than 48 hours after the announcement, the SIG observed significant attack attempt activity, scanning for vulnerable sites using the sample code provided in the technical write-up.

  • This highlights that the response time for attackers is rapidly decreasing, increasing the need for vigorous and prompt patch management.

akamai EN 2023 XSS vulnerability WordPress plugin third-party-risk CVE-2023-30777
Toyota: Car location data of 2 million customers exposed for ten years https://www.bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/
13/05/2023 17:48:53
QRCode
archive.org
thumbnail

Toyota Motor Corporation disclosed a data breach on its cloud environment that exposed the car-location information of 2,150,000 customers for ten years, between November 6, 2013, and April 17, 2023.

bleepingcomputer EN 2023 Automotive Data-Breach Data-Leak Database Toyota
Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-131a
12/05/2023 22:05:56
QRCode
archive.org

The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code remotely without credentials. PaperCut released a patch in March 2023.

cisa EN 2023 PaperCut CVE-2023-27350 advisory
«Cloud souverain»: les cantons latins avancent groupés et font un appel du pied à la Confédération https://www.ictjournal.ch/news/2023-05-12/cloud-souverain-les-cantons-latins-avancent-groupes-et-font-un-appel-du-pied-a-la
12/05/2023 22:03:40
QRCode
archive.org
thumbnail

Les directrices et directeurs du numérique des cantons latins ont décidé d’agir de concert en matière de souveraine

ictjournal FR 2023 CH cloud souverain cantons Confédération cloud-souverain
Multinational tech firm ABB hit by Black Basta ransomware attack https://www.bleepingcomputer.com/news/security/multinational-tech-firm-abb-hit-by-black-basta-ransomware-attack/
12/05/2023 22:02:27
QRCode
archive.org
thumbnail

Swiss multinational company ABB, a leading electrification and automation technology provider, has suffered a Black Basta ransomware attack, reportedly impacting business operations.

bleepingcomputer EN 2023 ABB Automation Black-Basta Cyber-Attack Industrial-Control-Systems Ransomware
White Phoenix: Beating Intermittent Encryption https://www.cyberark.com/resources/threat-research-blog/white-phoenix-beating-intermittent-encryption
12/05/2023 14:21:16
QRCode
archive.org
thumbnail

Recently, a new trend has emerged in the world of ransomware: intermittent encryption, the partial encryption of targeted files. Many ransomware groups, such as BlackCat and Play, have adopted...

cyberark EN 2023 Intermittent-Encryption ransomware decrypt
Critical Privilege Escalation in Essential Addons for Elementor Plugin Affecting 1+ Million Sites https://patchstack.com/articles/critical-privilege-escalation-in-essential-addons-for-elementor-plugin-affecting-1-million-sites/
12/05/2023 12:36:16
QRCode
archive.org
thumbnail

This blog post is about the Essential Addons for Elementor plugin vulnerability. If you’re a Essential Addons for Elementor user, please update the plugin to at least version 5.7.2. Patchstack Developer and Business plan users are protected from the vulnerability. You can also sign up for the Patchstack Community plan to be notified about vulnerabilities […]

patchstack EN 2023 WP Wordpress Elementor
Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020 https://www.malwarebytes.com/blog/threat-intelligence/2023/05/redstinger
12/05/2023 10:57:01
QRCode
archive.org
thumbnail

While the official conflict between Russia and Ukraine began in February 2022, there is a long history of physical conflict between the two nations, including the 2014 annexation of Crimea by Russia and when the regions of Donetsk and Luhansk declared themselves independent from Ukraine and came under Russia's umbrella. Given this context, it would not be surprising that the cybersecurity landscape between these two countries has also been tense.

malwarebytes EN 2023 APT RedStinger
Akira Ransomware is “bringin’ 1988 back” https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/
12/05/2023 10:55:46
QRCode
archive.org
thumbnail

A new recently observed ransomware family dubbed Akira uses a retro aesthetic on their victim site very reminiscent of the 1980s green screen consoles and possibly takes its namesake from the popular 1988 anime film of the same name.

sophos EN 2023 Akira ransomware analysis
infosec company owned completely by 4chan user https://maia.crimew.gay/posts/optimeyes-leak/
12/05/2023 08:53:22
QRCode
archive.org
thumbnail

yesterday evening an anonymous 4chan user dumped a leak on the /g/ technology board, claiming to have completely owned risk visualization company optimeyes:

nyancrimew 4chan optimeyes EN 2023 security infosec jenkins analysis maia-arson-crimew
Google will provide dark web monitoring to all US Gmail users https://securityaffairs.com/146095/deep-web/google-dark-web-monitoring-us-gmail-users.html
12/05/2023 08:40:08
QRCode
archive.org
thumbnail

Google announced the opening of the dark web monitoring report security feature to all Gmail users in the United States. Google is going to offer dark web monitoring to all U.S. Gmail users, the feature allows them to search for their email addresses on the dark web. Dark web scans for Gmail address was previously […]

securityaffairs EN Intelligence Google Gmail darkweb monitoring
Ghost in the network https://www.lighthousereports.com/investigation/ghost-in-the-network/
12/05/2023 08:27:57
QRCode
archive.org
thumbnail

Our investigation shows how Fink has built a surveillance apparatus that he has put at the disposal of governments and companies around the world – including Israel’s Rayzone Group, a top-tier cyber intelligence company. Fink’s set-up is capable of exploiting loopholes in mobile phone connection protocols to track the location of phone users and even redirect their SMS messages to crack internet accounts.

lighthousereports EN 2023 switzerland Fink surveillance SMS Telecoms
page 183 / 251
5001 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn