Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 190 / 238
Russian founder of a cryptocurrency exchange known for funneling ransomware profits arrested https://www.cyberscoop.com/cryptocurrency-bitzlato-exchange-ransomware-profits-arrested/
19/01/2023 14:08:11
QRCode
archive.org
thumbnail

The arrest comes as the U.S. ramps up efforts to crack down on attempts by cybercriminals to use cryptocurrency to evade sanctions.

cyberscoop EN 2023 cryptocurrency exchange founder ransomware arrested Hydra Marketplace
Assessing Potential Exploitation of Sophos Firewall and CVE-2022-3236 https://vulncheck.com/blog/sophos-cve-2022-3236
18/01/2023 21:44:40
QRCode
archive.org
thumbnail

Sophos took immediate steps to remediate CVE-2022-3236 – an unauthenticated and remote code execution vulnerability affecting the Sophos Firewall Webadmin and User Portal HTTP interfaces – with an automated hotfix sent out in September 2022. Through its advisory published on September 23, 2022, it also alerted users who don't receive automatic hotfixes to apply the update themselves. The advisory stated the vulnerability had previously been used against "a small set of specific organizations, primarily in the South Asia region." In December, Sophos released v19.5 GA GA with an official fix.
Key Takeaways

  • As there are no public proof-of-concept exploits for CVE-2022-3236, we created our own to determine its potential for mass exploitation.
  • We scanned internet-facing Sophos Firewalls and found more than 4,000 firewalls that were too old to receive a hotfix.
  • We encourage Sophos Firewall administrators to look through their logs to determine if they see indications of exploit attempts. Two files to focus on include /logs/csc.log and /log/validationError.log.
  • Internet-facing firewalls appear to largely be eligible for hotfixes and the default authentication captcha likely prevented mass exploitation.
vulncheck EN 2023 sophos CVE-2022-3236 PoC
Can you rely on macOS Ventura for malware protection? https://eclecticlight.co/2023/01/03/can-you-rely-on-macos-ventura-for-malware-protection/
18/01/2023 13:41:10
QRCode
archive.org
thumbnail

Samples of four malicious software downloaded and run on macOS 13.1. Could it detect and block them effectively? Or do you need 3rd party protection?

eclecticlight EN 2023 macOS malware protection Ventura
7 Ways Threat Actors Deliver macOS Malware in the Enterprise https://www.sentinelone.com/blog/7-ways-threat-actors-deliver-macos-malware-in-the-enterprise/
18/01/2023 13:38:11
QRCode
archive.org
thumbnail

Stay ahead of the game with our review on macOS malware threats. Learn about the top techniques used by threat actors to deliver malware and how to build more resilient defenses.

sentinelone EN 2023 macOS Malware Enterprise threats
InfoSec Handlers Diary Blog - SANS Internet Storm Center https://isc.sans.edu/diary/29448
18/01/2023 13:37:13
QRCode
archive.org
thumbnail

Malicious Google Ad --> Fake Notepad++ Page --> Aurora Stealer malware

SANS EN 2023 googleads Fake Notepad Aurora Stealer malware
Google Ads Exploited to Spread Malware https://heimdalsecurity.com/blog/google-ads-exploited-to-spread-malware/
18/01/2023 13:34:43
QRCode
archive.org
thumbnail

Google Ads is one of the most popular advertising platform, but it's also a target for cybercriminals. Learn how they are using it to spread malware.

heimdalsecurity EN 2022 googleads abuse Malware Exploited
Google Ads Malware Wipes NFT Influencer's Crypto Wallet https://www.hackread.com/google-ads-malware-nft-crypto-wallet/
18/01/2023 13:33:35
QRCode
archive.org
thumbnail

NFT influencer @NFT_GOD downloaded malware through Google Ads while attempting to download OBS, an open-source video streaming software.

hackread EN 2023 googleads OBS open-source abuse influencer NFT
“MasquerAds” — Google’s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e
18/01/2023 13:31:41
QRCode
archive.org

A newly uncovered technique to abuse Google’s ad-words powerful advertisement platform is spreading rogue promoted search results in mass. Pointing to allegedly credible advertisement sites that are fully controlled by threat actors, those are used to masquerade and redirect ad-clickers to malicious phishing pages gaining the powerful credibility and targeting capabilities of Google’s search results. Adding customized malware payloads, threat actors are raising the bar for successful malware deployments on Personal PCs with ad words like Grammarly, Malwarebytes, and Afterburner as well as with Visual Studio, Zoom, Slack, and even Dashlane to target organizations.

labs.guard.io EN 2022 googleads technique advertisement abuse malware distribution
Cyberconseil: les clés USB peuvent servir de porte d'entrée pour les cyberattaques https://www.ncsc.admin.ch/ncsc/fr/home/aktuell/im-fokus/2023/cybertipp-rubberducky.html
16/01/2023 21:43:32
QRCode
archive.org

Les clés USB font partie du paysage informatique depuis longtemps et sont utilisées pour stocker des données ou les transférer d'un ordinateur à un autre. De nombreuses personnes ignorent toutefois que ces clés peuvent également servir d'outil de piratage.

ncsc FR 2023 news Cyberconseil cyberattaques RubberDucky USB
Supply Chain Attack Using Identical PyPI Packages, “colorslib”, “httpslib”, and “libhttps” https://www.fortinet.com/blog/threat-research/supply-chain-attack-using-identical-pypi-packages-colorslib-httpslib-libhttps
16/01/2023 21:21:22
QRCode
archive.org
thumbnail

The FortiGuard Labs team discovered an attack embedded in three PyPI packages called ‘colorslib’, ‘httpslib’, and “libhttps”. Read our blog to learn more.

fortinet EN 2023 threat-research Threat-Research security-attack libhttps httpslib colorslib python PyPI
Vice Society ransomware leaks University of Duisburg-Essen’s data https://www.bleepingcomputer.com/news/security/vice-society-ransomware-leaks-university-of-duisburg-essen-s-data/
16/01/2023 21:11:47
QRCode
archive.org
thumbnail

The Vice Society ransomware gang has claimed responsibility for the November 2022 cyberattack that forced the University of Duisburg-Essen (UDE) to reconstruct its IT infrastructure, a process that's still ongoing.

bleepingcomputer EN 2023 Cyberattack Data-Leak Data-Theft Education Ransomware University-of-Duisburg-Essen Vice-Society
NortonLifeLock warns that hackers breached Password Manager accounts https://www.bleepingcomputer.com/news/security/nortonlifelock-warns-that-hackers-breached-password-manager-accounts/
16/01/2023 20:03:14
QRCode
archive.org
thumbnail

Gen Digital, formerly Symantec Corporation and NortonLifeLock, is sending data breach notifications to customers, informing them that hackers have successfully breached Norton Password Manager accounts in credential-stuffing attacks.

bleepingcomputer EN 2023 Password-manager NortonLifeLock breach Norton Password Manager credential-stuffing attack
SQL Injection in Multiple WordPress Plugins https://www.tenable.com/security/research/tra-2023-2
16/01/2023 17:43:25
QRCode
archive.org
  • Paid Memberships Pro : CVE-2023-23488 - Unauthenticated SQL Injection

  • Easy Digital Downloads: CVE-2023-23489 - Unauthenticated SQL Injection

  • Survey Maker: CVE-2023-23490 - Authenticated SQL Injection

tenable 2023 EN WordPress Plugins Advisory CVE-2023-23488 CVE-2023 CVE-2023-23490-23489
Défense : les interrogations de l’état-major français face aux opérations cyber américaines en Europe https://www.lemonde.fr/international/article/2023/01/13/defense-les-interrogations-de-l-etat-major-francais-face-aux-operations-cyber-americaines-en-europe_6157724_3210.html
16/01/2023 06:38:46
QRCode
archive.org
thumbnail

Depuis la guerre en Ukraine, les Etat-Unis ont envoyé plusieurs équipes spécialisées pour aider les pays se sentant vulnérables aux cyberattaques russes. Du côté français, on s’inquiète que ces démarches ouvrent la voie à des opérations plus larges d’espionnage.

lemonde FR 2023 France US espionnage Etats-Unis cyberattaques Guerre-en-Ukraine
Sustaining Digital Certificate Security - TrustCor Certificate Distrust https://security.googleblog.com/2023/01/sustaining-digital-certificate-security_13.html
16/01/2023 06:37:40
QRCode
archive.org
thumbnail

Google includes or removes CA certificates within the Chrome Root Store as it deems appropriate for user safety in accordance with our policies. The selection and ongoing inclusion of CA certificates is done to enhance the security of Chrome and promote interoperability.

googleblog EN 2023 Digital Certificate Security Root TrustCor Distrust
MSI's (in)Secure Boot https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/
16/01/2023 06:35:44
QRCode
archive.org

On 2022-12-11, I decided to setup Secure Boot on my new desktop with a help of sbctl. Unfortunately I have found that my firmware was… accepting every OS image I gave it, no matter if it was trusted or not. It wasn't the first time that I have been self-signing Secure Boot, I wasn't doing it wrong.

As I have later discovered on 2022-12-16, it wasn't just broken firmware, MSI had changed their Secure Boot defaults to allow booting on security violations(!!).

dawidpotocki EN 2023 MSI SecureBoot broken insecure firmware
How Finland Is Teaching a Generation to Spot Misinformation https://www.nytimes.com/2023/01/10/world/europe/finland-misinformation-classes.html
16/01/2023 06:34:18
QRCode
archive.org

How Finland Is Teaching a Generation to Spot Misinformation
The Nordic country is testing new ways to teach students about propaganda. Here’s what other countries can learn from its success.

nytimes EN 2022 Finland Teaching Misinformation propaganda education
Compromise of employee device, credentials led to CircleCI breach https://www.scmagazine.com/analysis/breach/compromise-of-employee-device-credentials-led-to-circleci-breach
16/01/2023 06:31:49
QRCode
archive.org
thumbnail

CircleCI’s chief technology officer said malicious hackers infected one of their engineer’s laptops and stole elevated account privileges to breach the company’s systems and data late last year.

scmagazine EN 2023 CircleCI infected laptops breach
A Police App Exposed Secret Details About Raids and Suspects | WIRED https://www.wired.com/story/sweepwizard-police-raids-data-exposure/
15/01/2023 20:28:54
QRCode
archive.org
thumbnail

SweepWizard, an app that law enforcement used to coordinate raids, left sensitive information about hundreds of police operations publicly accessible.

wired EN 2023 SweepWizard privacy police crime app leak sensitive information US
Watch: Ukraine Army Video Tells Russians How to Surrender to a Drone https://www.businessinsider.com/ukraine-army-video-tells-russians-how-to-surrender-to-drone-2022-12?r=US&IR=T
15/01/2023 16:18:39
QRCode
archive.org
thumbnail
  • Ukraine has released an instruction video for Russian soldiers on surrendering to a drone.
  • It's part of the "I Want to Live" hotline, which entices Russians to stop fighting in Ukraine.
  • The video suggests that surrendering via drone may become increasingly common.
businessinsider EN 2022 drones war Army instruction drone russia-ukraine-war surrendering
page 190 / 238
4752 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio