Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 185 / 251
Dump these Cisco phone adapters because it's not fixing them https://www.theregister.com/2023/05/05/cisco_phone_adapter_vulnerabilitty/
08/05/2023 07:16:38
QRCode
archive.org
thumbnail

There is a critical security flaw in a Cisco phone adapter, and the business technology giant says the only step to take is dumping the hardware and migrating to new kit.

In an advisory, Cisco this week warned about the vulnerability in the SPA112 2-Port Adapter that, if exploited, could allow a remote attacker to essentially take control of a compromised device by seizing full privileges and executing arbitrary code.

The flaw, tracked as CVE-2023-20126, is rated as "critical," with a base score o

theregister EN 2023 Cisco CVE-2023-20126 SPA112 2-Port phone adaptor
TikTok spied on me. Why? https://archive.is/gn0r0#selection-2023.0-2027.169
08/05/2023 07:06:39
QRCode
archive.org

One evening in late December last year, I received a cryptic phone call from a PR director at TikTok, the popular social media app. I’d written extensively about the company for the Financial Times, so we’d spoken before. But it was puzzling to hear from her just before the holidays, especially since I wasn’t working on anything related to the company at the time.

Financial-Times EN 2023 TikTok spy journalist
Meet Akira — A new ransomware operation targeting the enterprise https://www.bleepingcomputer.com/news/security/meet-akira-a-new-ransomware-operation-targeting-the-enterprise/
07/05/2023 18:35:50
QRCode
archive.org
thumbnail

The new Akira ransomware operation has slowly been building a list of victims as they breach corporate networks worldwide, encrypt files, and then demand million-dollar ransoms.

Akira Data-Leak-Site Extortion Ransomware Security InfoSec Computer-Security
MSI Breach Leaks Intel BootGuard & OEM Image Signing Keys, Compromises Security of Over 200 Devices & Major Vendors https://wccftech.com/msi-breach-leaks-intel-bootguard-oem-image-signing-keys-compromises-security-of-over-200-devices-major-vendors/
07/05/2023 13:36:39
QRCode
archive.org
thumbnail

A recent breach in MSI's servers exposed Intel's BootGuard keys and has now put the security of various devices at risk.

Major MSI Breach Affects The Security of Various Intel Devices
Last month, a hacker group by the name of Money Message revealed that they had breached MSI's servers and stolen 1.5 TBs of data from the company's servers including source code amongst a list of various files that are important to the integrity of the company. The group asked MSI to pay $4.0 million in ransom to avert them from releasing the files to the public but MSI refused the payment.

wccftech EN 2023 MSI leak Intel BootGuard OEM Image Signing Keys
OpenAI’s regulatory troubles are just beginning https://www.theverge.com/2023/5/5/23709833/openai-chatgpt-gdpr-ai-regulation-europe-eu-italy
06/05/2023 21:18:35
QRCode
archive.org
thumbnail

OpenAI managed to appease Italian data authorities and lift the country’s effective ban on ChatGPT last week, but its fight against European regulators is far from over. 

theverge EN 2023 OpenAI ChatGPT European GDPR
Who Gets the Algorithm? The Bigger TikTok Danger https://www.lawfareblog.com/who-gets-algorithm-bigger-tiktok-danger
06/05/2023 14:43:44
QRCode
archive.org
thumbnail

Controversy surrounding TikTok, the popular Chinese company-owned social media platform, has continued to give rise to impasse in recent weeks. Just days after the Biden administration issued a divestiture-or-ban ultimatum to the company and Beijing firmly opposed a forced sale, TikTok CEO Shou Zi Chew testified in Congress to try to save the app’s U.S. operations.

lawfareblog EN 2023 TikTok Algorithm Danger
Can Better Training Reduce the Success Rate of Phishing Attacks? https://www.lawfareblog.com/can-better-training-reduce-success-rate-phishing-attacks
06/05/2023 14:40:33
QRCode
archive.org
thumbnail

A review of Arun Vishwanath, “The Weakest Link: How to Diagnose, Detect, and Defend Users From Phishing Attacks” (MIT Press, 2022)

Many elements of the cyber threat landscape have changed significantly over the past two decades. For one, the number of attackers has grown dramatically, aided by the increasing availability of hacking tools and services as commodities for purchase in online marketplaces. The value of the losses cyber criminals have been able to inflict on their victims has also grown, though the dollar estimates vary widely in absolute terms. In recent years, the popularity of ransomware has increased substantially, prompting the Biden administration to initiate an ongoing diplomatic effort to foster cross-border efforts to curb this dangerous form of cyber-enabled extortion.

lawfareblog EN 2023 Phishing Training
From Campus Rape Cases to Child Abuse Reports, ‘Worst-Case’ Data Breach Rocks MN Schools https://www.the74million.org/article/from-campus-rape-cases-to-child-abuse-reports-worst-case-data-breach-rocks-mn-schools/
06/05/2023 14:38:10
QRCode
archive.org
thumbnail

It took two years of middle school girls accusing their Minneapolis English teacher of eyeballing their bodies in a “weird creepy way,” for district investigators to substantiate their complaints.

Their drawn-out response is revealed in confidential and highly sensitive Minneapolis Public Schools investigative records that are now readily available online — just one folder in a trove of tens of thousands of leaked files that outline campus rape cases, child abuse inquiries, student mental health crises and suspension reports.

the74million EN 2023 Schools Abuse Leak ransomware Medusa US Minneapolis Public
The malware threat landscape: NodeStealer, DuckTail, and more https://engineering.fb.com/2023/05/03/security/malware-nodestealer-ducktail/
05/05/2023 10:43:38
QRCode
archive.org
thumbnail

We’re sharing our latest research and analysis into malware campaigns that are targeting online businesses — including newer malware posing as AI tools.

meta EN 2023 NodeStealer DuckTail research analysis campaigns malware
Atomic Stealer | Threat Actor Spawns Second Variant of macOS Malware Sold on Telegram https://www.sentinelone.com/blog/atomic-stealer-threat-actor-spawns-second-variant-of-macos-malware-sold-on-telegram/
04/05/2023 21:16:28
QRCode
archive.org
thumbnail

A macOS infostealer being sold on Telegram, Atomic Stealer has a second variant that appears primed to target users directly on YouTube.

sentinelone EN 2023 macos infostealer Telegram Atomic-Stealer Malware YouTube
Large Language Models and Elections https://www.schneier.com/blog/archives/2023/05/large-language-models-and-elections.html
04/05/2023 16:16:24
QRCode
archive.org

Earlier this week, the Republican National Committee released a video that it claims was “built entirely with AI imagery.” The content of the ad isn’t especially novel—a dystopian vision of America under a second term with President Joe Biden—but the deliberate emphasis on the technology used to create it stands out: It’s a “Daisy” moment for the 2020s.

Schneier EN 2023 LLM election disinformation AI
macOS' Rapid Security Response: Designed into a Corner https://khronokernel.github.io/macos/2023/04/18/RSR.html?s=09
03/05/2023 22:45:58
QRCode
archive.org

With macOS 13.3.1 dropping a few weeks ago, some people have been wondering what happened to Apple’s featured “Rapid Security Response” system they showed off back at WWDC 2022? For some reason, Apple keeps shipping their usual slow, bulky security updates as opposed to the new small and “rapid” security updates.

Today we’ll look into how the Rapid Security Response was implemented and how Apple’s Engineers designed themselves into a corner with this new system.

khronokernel EN 2023 macOS Rapid-Security-Response
Passkeys: What they are and how to use them https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/
03/05/2023 15:04:54
QRCode
archive.org
thumbnail

For the first time, we’ve begun rolling out passkeys, the easiest and most secure way to sign in to apps and websites and a major step toward a “passwordless future.”

Google EN 2023 Passwordless passkeys rolling
Apple et Google s’accordent sur un cahier des charges industriel pour lutter contre le pistage https://www.apple.com/chfr/newsroom/2023/05/apple-google-partner-on-an-industry-specification-to-address-unwanted-tracking/
03/05/2023 14:12:30
QRCode
archive.org
thumbnail

Aujourd’hui, Apple et Google ont conjointement présenté une proposition de cahier des charges industriel pour empêcher l’utilisation abusive des appareils de géolocalisation Bluetooth.

Apple FR 2023 Google AirTag géolocalisation Bluetooth standard privacy pistage
Ransomware cyberattack continues at Bluefield University https://www.databreaches.net/ransomware-cyberattack-continues-at-bluefield-university/
03/05/2023 13:04:42
QRCode
archive.org

There are new developments on the cybersecurity attack that has crippled internet services at Bluefield University. We’ve learned through “RamAlert” texts sent to students, faculty and staff that the cyber attackers are now directly communicating with everyone on the alert system. They have identified themselves as “AvosLocker” and are demanding payment in return for not leaking students’ private information. The FBI considers AvosLocker to be ransomware. In March 2022, they released an advisory on it. They said avoslocker has “Targeted victims across multiple critical infrastructure sectors in the U.S. Including…The financial services, critical manufacturing, and government facilities sectors.”

databreaches EN SMS AvosLocker ransomware US Education Bluefield University
Bad Actors Are Joining the AI Revolution: Here’s What We’ve Found in the Wild https://hackernoon.com/bad-actors-are-joining-the-ai-revolution-heres-what-weve-found-in-the-wild?source=rss
03/05/2023 10:05:36
QRCode
archive.org
thumbnail

Follow security researchers as they uncover malicious packages on open-source registries, trace bad actors to Discord, and unveil AI-assisted code.

hackernoon EN 2023 python PyPI Supply-Chain-Attack ChatGPT
AI-Powered 'BlackMamba' Keylogging Attack Evades Modern EDR Security https://www.darkreading.com/endpoint/ai-blackmamba-keylogging-edr-security
03/05/2023 09:43:06
QRCode
archive.org
thumbnail

Researchers warn that polymorphic malware created with ChatGPT and other LLMs will force a reinvention of security automation.

darkreading EN 2023 ChatGPT EDR evasion Polymorphic BlackMamba LLM
SolarWinds: The Untold Story of the Boldest Supply-Chain Hack https://www.wired.com/story/the-untold-story-of-solarwinds-the-boldest-supply-chain-hack-ever/
02/05/2023 19:40:42
QRCode
archive.org
thumbnail

It was late 2019, and Adair, the president of the security firm Volexity, was investigating a digital security breach at an American think tank. The intrusion was nothing special. Adair figured he and his team would rout the attackers quickly and be done with the case—until they noticed something strange. A second group of hackers was active in the think tank’s network. They were going after email, making copies and sending them to an outside server. These intruders were much more skilled, and they were returning to the network several times a week to siphon correspondence from specific executives, policy wonks, and IT staff.

wired 2023 EN Supply-Chain Hack SolarWinds 2019 Story
What is a Rapid Security Response (RSR) https://eclecticlight.co/2023/05/02/what-is-a-rapid-security-response-rsr/
02/05/2023 11:17:59
QRCode
archive.org
thumbnail

Intended to be lightweight, timely and quick to install, the first RSR has now been provided for Ventura. Did you know you can also uninstall it easily?

eclecticlight EN 2023 Rapid-Security-Response macis iOS16 RSR
BouldSpy: Android Spyware Tied to Iranian Police Targets Minorities https://security.lookout.com/blog/iranian-spyware-bouldspy
02/05/2023 11:15:40
QRCode
archive.org
thumbnail

Researchers at the Lookout Threat Lab have discovered a new Android surveillance tied to the Law Enforcement Command of the Islamic Republic of Iran (FARAJA).

lookout EN 2023 BouldSpy Spyware Android FARAJA Iran
page 185 / 251
5001 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn