Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 189 / 251
Queuejumper: Critical Unauthorized RCE Vulnerability In MSMQ Service https://research.checkpoint.com/2023/queuejumper-critical-unauthorized-rce-vulnerability-in-msmq-service/
12/04/2023 01:01:43
QRCode
archive.org

Check Point Research recently discovered three vulnerabilities in the “Microsoft Message Queuing” service, commonly known as MSMQ. These vulnerabilities were disclosed to Microsoft and patched in the April Patch Tuesday update. The most severe of these, dubbed QueueJumper by CPR (CVE-2023-21554), is a critical vulnerability that could allow unauthorized attackers to remotely execute arbitrary code in the context of the Windows service process mqsvc.exe.

checkpoint EN 2023 analysis RCE Queuejumper CVE-2023-21554 MSMQ Service Critical PatchTuesday
DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia https://www.microsoft.com/en-us/security/blog/2023/04/11/dev-0196-quadreams-kingspawn-malware-used-to-target-civil-society-in-europe-north-america-the-middle-east-and-southeast-asia/
11/04/2023 18:37:46
QRCode
archive.org
thumbnail

Microsoft analyzes a threat group tracked as DEV-0196, the actor’s iOS malware “KingsPawn”, and their link to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infrastructure called REIGN, that’s designed to exfiltrate data from mobile devices.

microsoft EN 2023 QuaDream spyware spy IoCs DEV-0196 iOS calendar zero-click REIGN
Sweet QuaDreams: A First Look at Spyware Vendor QuaDream’s Exploits, Victims, and Customers - The Citizen Lab https://citizenlab.ca/2023/04/spyware-vendor-quadream-exploits-victims-customers/
11/04/2023 18:34:14
QRCode
archive.org
thumbnail

At least five civil society victims of QuaDream’s spyware and exploits were identified in North America, Central Asia, Southeast Asia, Europe, and the Middle East. Victims include journalists, political opposition figures, and an NGO worker. Traces of a suspected iOS 14 zero-click exploit used to deploy QuaDream’s spyware.

CitizenLab EN 2023 QuaDreams Spyware spyware spy iPhone calendar zero-click
Mercenary spyware hacked iPhone victims with rogue calendar invites, researchers say | TechCrunch https://techcrunch.com/2023/04/11/quadream-spyware-hacked-iphones-calendar-invites/
11/04/2023 18:32:54
QRCode
archive.org
thumbnail

Researchers found malware developed by QuaDream, a little-known government spyware maker, which was used against journalists and politicians.

techcrunch EN 2023 security apple cybersecurity hackers hacking ios iphone spyware zero-days
Balada Injector: Synopsis of a Massive Ongoing WordPress Malware Campaign https://blog.sucuri.net/2023/04/balada-injector-synopsis-of-a-massive-ongoing-wordpress-malware-campaign.html
10/04/2023 21:07:18
QRCode
archive.org
thumbnail

A synopsis of the massive ongoing WordPress malware campaign: Balada Injector, including common techniques, functionalities, and vulnerability exploits used in attacks.

sucuri EN 2023 Wordpress campaigns Balada Injector analysis exploits
Data-leak flaw in Qualcomm, HiSilicon-based Wi-Fi AP chips https://www.theregister.com/2023/04/07/wifi_access_icmp/
10/04/2023 18:55:48
QRCode
archive.org
thumbnail

WPA stands for will-provide-access, if you can successfully exploit a target's setup

theregister EN 2023 Qualcomm Data-leak flaw Wi-Fi AP chips CVE-2022-25667
MERCURY and DEV-1084: Destructive attack on hybrid environment - Microsoft Security Blog https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/
10/04/2023 18:46:22
QRCode
archive.org
thumbnail

Microsoft detected a unique operation where threat actors carried out destructive actions in both on-premises and cloud environments.

microsoft EN 2023 MERCURY DEV-1084 analysis cloud hybrid environment Iran TTPs operation
Cyble — Demystifying Money Message Ransomware  https://blog.cyble.com/2023/04/06/demystifying-money-message-ransomware/
10/04/2023 18:44:46
QRCode
archive.org
thumbnail

CRIL analyses the anatomy of a new ransomware group named Money Message, which can encrypt network shares and target both Windows and Linux.

cyble EN 2023 MoneyMessage ransomware analysis
Water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation. https://www.jpost.com/israel-news/article-738790
10/04/2023 11:31:45
QRCode
archive.org

Several water monitors – which monitor irrigation systems and wastewater treatment systems – were left dysfunctional on Sunday after a cyber attack targeted the monitoring systems.

Specifically, water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation.

jpost EN 2023 Water Galil Sewage Corporation monitors cyber attack controllers hacked
Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company https://zetter.substack.com/p/leaked-pentagon-document-claims-russian
09/04/2023 22:16:55
QRCode
archive.org
thumbnail

The document, part of a cache of leaks recently circulated on the internet, suggests the hackers had the ability to cause an explosion and sought instruction from the FSB.

Zetter EN 2023 FSB pipeline Russia hack FSB Zarya
From Discord to 4chan: The Improbable Journey of a US Intelligence Leak - bellingcat https://www.bellingcat.com/news/2023/04/09/from-discord-to-4chan-the-improbable-journey-of-a-us-defence-leak/
09/04/2023 10:58:41
QRCode
archive.org
thumbnail

In recent days, the US Justice Department and Pentagon have begun investigating an apparent online leak of sensitive documents, including some that were marked “Top Secret”.

A portion of the documents, which have since been widely covered by the news media, focused on Russia’s invasion of Ukraine, while others detailed analysis of potential UK policies on the South China Sea and the activities of a Houthi figure in Yemen.

The existence of the documents was first reported by the New York Times after a number of Russian Telegram channels shared five photographed files relating to the invasion of Ukraine on April 5 – at least one of which has since been found by Bellingcat to be crudely edited.

bellingcat EN 2023 leak 4chan discord US topsecret sensitive document Russia NYT Ukraine
MSI Confirms Breach as Ransomware Gang Claims Responsibility https://www.pcmag.com/news/msi-confirms-breach-as-ransomware-gang-claims-responsibility
08/04/2023 19:25:30
QRCode
archive.org
thumbnail

UPDATE: A new statement(Opens in a new window) from MSI says users should avoid downloading firmware and BIOS updates from third-party sources, and instead only obtain such software from the company's official website.

The statement suggests MSI is worried hackers could circulate malicious versions of the company's BIOS software when the ransomware gang, Money Message, claims it stole the PC maker's source code.

pcmag EN 2023 MSI hacked BIOS PCmaker software statement
L'Anssi pourra bloquer les noms de domaine liés à des cyberattaques https://www.usine-digitale.fr/article/cyberattaque.N2119866
08/04/2023 10:30:44
QRCode
archive.org
thumbnail

La loi de programmation militaire prévoit que l'autorité n'aura pas besoin d'une décision de justice. Un contrôle sera réalisé a posteriori par l'Arcep.

usine-digitale FR 2023 ANSSI saisie noms DNS domaines cyberattaque militaire
Exploit available for critical bug in VM2 JavaScript sandbox library https://www.bleepingcomputer.com/news/security/exploit-available-for-critical-bug-in-vm2-javascript-sandbox-library/
08/04/2023 01:43:08
QRCode
archive.org
thumbnail

Proof-of-concept exploit code has been released for a recently disclosed critical vulnerability in the popular VM2 library, a JavaScript sandbox that is used by multiple software to run code securely in a virtualized environment.

bleepingcomputer Code-Execution Sandbox Sandbox-Escape JavaScript Virtualization VM2 PoC CVE-2023-29017
Samsung Fab Workers Leak Confidential Data While Using ChatGPT https://www.tomshardware.com/news/samsung-fab-workers-leak-confidential-data-to-chatgpt
08/04/2023 01:33:57
QRCode
archive.org
thumbnail

Samsung fab personnel reportedly used ChatGPT to optimize operations and create presentations, leaking confidential data to the third-party AI.

tomshardware EN 2023 Samsung ChatGPT Leak
Cyble — New Cylance Ransomware with Power-Packed CommandLine Options https://blog.cyble.com/2023/04/07/new-cylance-ransomware-with-power-packed-commandline-options/
08/04/2023 01:16:28
QRCode
archive.org
thumbnail

CRIL analyzes Cylance, a new Ransomware variant that uses command-line options to target both Windows and Linux users.

cyble EN 2023 Ransomware Cylance
ALPHV Ransomware Affiliate Targets Vulnerable Backup Installations to Gain Initial Access https://www.mandiant.com/resources/blog/alphv-ransomware-backup
08/04/2023 01:09:27
QRCode
archive.org
thumbnail

A ransomware affiliate is targeting publicly exposed Veritas installations to gain access to organizations.

mandiant EN 2023 ALPHV Ransomware Affiliate Vulnerable Backup Veritas
Special Report: Tesla workers shared sensitive images recorded by customer cars | Reuters https://www.reuters.com/technology/tesla-workers-shared-sensitive-images-recorded-by-customer-cars-2023-04-06/
08/04/2023 01:01:19
QRCode
archive.org
thumbnail

Between 2019 and 2022, groups of Tesla employees privately shared via an internal messaging system sometimes highly invasive videos and images recorded by customers’ car cameras.

reuters EN 2023 Tesla privacy workers privately customers car
Apple fixes two zero-days exploited to hack iPhones and Macs https://www.bleepingcomputer.com/news/apple/apple-fixes-two-zero-days-exploited-to-hack-iphones-and-macs/
07/04/2023 20:29:05
QRCode
archive.org
thumbnail

Apple has released emergency security updates to address two new zero-day vulnerabilities exploited in attacks to compromise iPhones, Macs, and iPads.

Apple EN 2023 updates zero-day vulnerabilities ios macos
Stopping cybercriminals from abusing security tools https://blogs.microsoft.com/on-the-issues/2023/04/06/stopping-cybercriminals-from-abusing-security-tools/
06/04/2023 23:57:40
QRCode
archive.org
thumbnail

Microsoft’s Digital Crimes Unit (DCU), cybersecurity software company Fortra™ and Health Information Sharing and Analysis Center (Health-ISAC) are taking technical and legal action to disrupt cracked, legacy copies of Cobalt Strike and abused Microsoft software, which have been used by cybercriminals to distribute malware, including ransomware. This is a change in the way DCU has...

microsoft EN 2023 CobaltStrike Fortra ISAC security tools abusing statement
page 189 / 251
5001 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn