Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 183 / 208
4149 résultats taggé EN  ✕
Chromium Blog: Announcing the Launch of the Chrome Root Program https://blog.chromium.org/2022/09/announcing-launch-of-chrome-root-program.html
21/09/2022 23:28:46
QRCode
archive.org
thumbnail

In 2020, we announced we were in the early phases of establishing the Chrome Root Program and launching the Chrome Root Store.

The Chrome Root Program ultimately determines which website certificates are trusted by default in Chrome, and enables more consistent and reliable website certificate validation across platforms.

This post shares an update on our progress and how these changes help us better protect Chrome’s users.

chromium EN 2022 root store certificates trust
Record 25.3 Billion Request Multiplexing Attack Mitigated by Imperva https://www.imperva.com/blog/record-25-3-billion-request-multiplexing-attack-mitigated-by-imperva/
21/09/2022 22:49:37
QRCode
archive.org

On June 27, 2022, Imperva mitigated a single attack with over 25.3 billion requests, setting a new record for Imperva’s application DDoS mitigation solution.

While attacks with over one million requests per second (RPS) aren’t new, we’ve previously only seen them last for several seconds to a few minutes. On June 27, Imperva successfully mitigated a strong attack that lasted more than four hours and peaked at 3.9 million RPS.

imperva EN 2022 DDoS RPS attack
Turning Your Computer Into a GPS Tracker With Apple Maps https://breakpoint.sh/posts/turning-your-computer-into-a-gps-tracker-with-apple-maps
20/09/2022 13:41:36
QRCode
archive.org

One of the things Apple cares about in terms of its bug bounty program is your location data. Apple rightly categorizes real-time or historical precise location data as "sensitive data" which in some cases qualifies for a significant monetary award.

breakpoint EN 2022 macOS maps leak sensitive location CVE-2022-32883
Six months into Breached: The legacy of RaidForums? https://ke-la.com/six-months-into-breached-the-legacy-of-raidforums/
20/09/2022 00:27:59
QRCode
archive.org
thumbnail

On March 14, 2022, a new English-language cybercrime forum called Breached (also known as BreachForums) launched, as a response to the closure and seizure of the popular RaidForums. Breached was launched with the same design by the threat actor “pompompurin” as “an alternative to RaidForums,” offering large-scale database leaks, login credentials, adult content, and hacking tools.

ke-la EN 2022 Breached forum Analysis RaidForums pompompurin cybercrime
How Russian Trolls Helped Keep the Women’s March Out of Lock Step https://www.nytimes.com/2022/09/18/us/womens-march-russia-trump.html
20/09/2022 00:08:16
QRCode
archive.org

As American feminists came together in 2017 to protest Donald Trump, Russia’s disinformation machine set about deepening the divides among them.

nytimes 2022 EN Russia disinformation divides trolls media
Chrome & Edge Enhanced Spellcheck Features Expose PII, Even Your Passwords https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords
20/09/2022 00:04:47
QRCode
archive.org

Some of the largest websites in the world have exposure to sending Google and Microsoft sensitive user PII, including username, email, and passwords

otto-js EN 2022 Chrome Edge Spellcheck Spell-Jacking leak
Unflattening ConfuserEx .NET Code in IDA https://www.govcert.ch/blog/unflattening-confuserex-code-in-ida/
20/09/2022 00:01:22
QRCode
archive.org

we’re studying the ConfuserEx1 obfuscation mechanism of a Ginzo .NET sample. This class of obfuscator is known as code flatteners. We describe how it can dealt with it using a Python script within IDA Pro2, a famous reverse-engineering tool.

GovCERT EN 2022 CH NCSC ConfuserEx1 ConfuserEx obfuscation IDA reverse-engineering
Revolut hack exposes data of 50,000 users, fuels new phishing wave https://www.bleepingcomputer.com/news/security/revolut-hack-exposes-data-of-50-000-users-fuels-new-phishing-wave/
19/09/2022 23:52:34
QRCode
archive.org
thumbnail

Revolut is sending out notices of a data breach to a small percentage of impacted users, informing them of a security incident where an unauthorized third party accessed internal data.

bleepingcomputer EN 2022 Data-Breach Phishing Revolut Smishing
Credential Gathering From Third-Party Software https://unit42.paloaltonetworks.com/credential-gathering-third-party-software/
19/09/2022 23:44:41
QRCode
archive.org
thumbnail

Users often store passwords in third-party software for convenience – but credential gathering techniques can target this behavior.

unit42 EN 2022 passwords Analysis credential gathering techniques
Malvertising on Microsoft Edge's News Feed pushes tech support scams https://www.malwarebytes.com/blog/threat-intelligence/2022/09/microsoft-edges-news-feed-pushes-tech-support-scam
19/09/2022 23:34:16
QRCode
archive.org
thumbnail

We uncovered a campaign on the Microsoft Edge home page where malicious ads are luring victims into tech support scams.

malwarebytes EN 2022 Microsoft Edge Analysis campaign scams IoCs Feed News browser
Ermittlungserfolg gegen Ransomware-Gruppierung https://www.zh.ch/de/news-uebersicht/medienmitteilungen/2022/09/220916_ransomware.html#-792208150
19/09/2022 23:29:54
QRCode
archive.org
thumbnail

In the context of an internationally coordinated operation against a ransomware group, the Zurich Public Prosecutor’s Office is leading criminal proceedings against an accused person. At the same time, cyber investigators of the Zurich Cantonal Police have been intensively analysing the data storage devices seized from that person in the past months. This analysis has revealed numerous private keys. They enable the aggrieved companies to recover their encrypted data.

zh Zurich EN 2022 DE LockerGoga ramsomware decryptor
GTA 6 gameplay leaks online in 90 videos https://www.theverge.com/2022/9/18/23359156/gta-6-leak-gameplay-footage-90-videos
19/09/2022 21:52:21
QRCode
archive.org
thumbnail

A massive GTA VI leak appears to line up with previous reports.

theverge EN 2022 GTA leak DataBreach gameplay Rockstar
Security update https://www.uber.com/newsroom/security-update
19/09/2022 21:50:57
QRCode
archive.org
thumbnail

Updates on security incident

uber 2022 En leak announce Lapsus$ attribution Rockstar
Get root on macOS 12.3.1: proof-of-concepts for Linus Henze’s CoreTrust and DriverKit bugs (CVE-2022-26766, CVE-2022-26763) https://worthdoingbadly.com/coretrust/
16/09/2022 09:07:26
QRCode
archive.org

Here are two proof-of-concepts for CVE-2022-26766 (CoreTrust allows any root certificate) and CVE-2022-26763 (IOPCIDevice::_MemoryAccess not checking bounds at all), two issues discovered by @LinusHenze and patched in macOS 12.4 / iOS 15.5.

worthdoingbadly PoC EN 2022 CVE-2022-26766 CVE-2022-26763 patched macOS iOS LinusHenze
Uber Investigating Breach of Its Computer Systems https://www.nytimes.com/2022/09/15/technology/uber-hacking-breach.html
16/09/2022 08:40:35
QRCode
archive.org

The company said on Thursday that it was looking into the scope of the apparent hack.

nytimes EN 2022 Uber breach investigation
Iran’s cyberwar goes global https://www.economist.com/middle-east-and-africa/2022/09/14/irans-cyberwar-goes-global
15/09/2022 21:38:58
QRCode
archive.org
thumbnail

Its targets include not only Israel but at least one NATO member

economist EN 2022 cyber-assault cyber-attacks cyberwar geopolitics
Webworm: Espionage Attackers Testing and Using Older Modified RATs https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/webworm-espionage-rats
15/09/2022 21:17:57
QRCode
archive.org
thumbnail

The attackers are working on a number of malware threats, some of which have been used in attacks while others are in pre-deployment or testing stages.
Symantec, by Broadcom Software, has gained insight into the current activities of a group we call Webworm. The group has developed customized versions of three older remote access Trojans (RATs), including Trochilus, Gh0st RAT, and 9002 RAT. At least one of the indicators of compromise (IOCs) observed by Symantec was used in an attack against an IT service provider operating in multiple Asian countries, while others appear to be in pre-deployment or testing stages.

symantec-enterprise-blogs.security EN 2022 Gh0st RAT 9002 older Trojans Trochilus
RedLine spreads through ads for cheats and cracks on YouTube https://securelist.com/self-spreading-stealer-attacks-gamers-via-youtube/107407/
15/09/2022 21:14:03
QRCode
archive.org
thumbnail

An unusual malicious bundle (a collection of malicious programs distributed in the form of a single installation file, self-extracting archive or other file with installer-type functionality) recently caught our eye. Its main payload is the widespread RedLine stealer. Discovered in March 2020, RedLine is currently one of the most common Trojans used to steal passwords and credentials from browsers, FTP clients and desktop messengers. It is openly available on underground hacker forums for just a few hundred dollars, a relatively small price tag for malware.

securelist EN 2022 RedLine YouTube stealer
Undermining Microsoft Teams Security by Mining Tokens https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens
15/09/2022 17:40:33
QRCode
archive.org
thumbnail

In August 2022, the Vectra Protect team identified an attack path that enables malicious actors with file system access to steal credentials for any Microsoft Teams user who is signed in.

Vectra EN 2022 token teams Microsoft credentials steal
How Human Traffickers Force Victims Into Cyberscamming https://www.propublica.org/article/human-traffickers-force-victims-into-cyberscamming
14/09/2022 18:13:28
QRCode
archive.org
thumbnail

Traffickers in Southeast Asia force thousands of people into perpetrating cyberscams that defraud Americans out of millions of dollars. Here’s how they do it.

Propublica EN 2022 traffickers scams victims
page 183 / 208
4735 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio