Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 2 / 2
34 résultats taggé GitHub  ✕
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641) https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/
13/10/2023 09:53:33
QRCode
archive.org
thumbnail

CVE-2023-43641 is a vulnerability in libcue, which can lead to code execution by downloading a file on GNOME.

github EN 2023 CVE-2023-43641 libcue GNOME
38TB of data accidentally exposed by Microsoft AI researchers | Wiz Blog https://www.wiz.io/blog/38-terabytes-of-private-data-accidentally-exposed-by-microsoft-ai-researchers
19/09/2023 16:30:43
QRCode
archive.org
thumbnail

Wiz Research found a data exposure incident on Microsoft’s AI GitHub repository, including over 30,000 internal Microsoft Teams messages – all caused by one misconfigured SAS token

wiz EN 2023 GitHub Microsoft leak
Microsoft AI Employee Accidentally Leaks 38TB of Data https://www.pcmag.com/news/microsoft-ai-employee-accidentally-leaks-38tb-of-data
18/09/2023 20:01:03
QRCode
archive.org
thumbnail

A software repository on GitHub dedicated to supplying open-source code and AI models for image recognition was left open to manipulation by bad actors thanks to an insecure URL.

pcmag EN 2023 DataLeak GitHub Microsoft 38TB
BlackLotus UEFI Bootkit Source Code Leaked on GitHub https://www.securityweek.com/blacklotus-uefi-bootkit-source-code-leaked-on-github/?utm_source=substack&utm_medium=email
15/07/2023 13:56:38
QRCode
archive.org
thumbnail

The source code for the BlackLotus UEFI bootkit has been shared publicly on GitHub, albeit with several modifications compared to the original malware.

Designed specifically for Windows, the bootkit emerged on hacker forums in October last year, being advertised with APT-level capabilities such as secure boot and user access control (UAC) bypass and the ability to disable security applications and defense mechanisms on victim systems.

securityweek EN 2023 BlackLotus UEFI Bootkit Source Code Leaked GitHub
Fake Security Researcher GitHub Repositories Deliver Malicious Implant https://vulncheck.com/blog/fake-repos-deliver-malicious-implant
15/06/2023 21:39:46
QRCode
archive.org
thumbnail

VulnCheck discovers a network of fake security researcher accounts promoting hidden malware.

vulncheck EN 2023 fake researcher malware GitHub Repositories Implant
Action needed for GitHub Desktop and Atom users https://github.blog/2023-01-30-action-needed-for-github-desktop-and-atom-users/
01/02/2023 09:51:54
QRCode
archive.org
thumbnail

Update to the latest version of Desktop and previous version of Atom before February 2.

GitHub EN 2023 breach Update repositories
Pro-Russia hackers use Telegram, GitHub to attack Czech presidential election https://therecord.media/pro-russia-hackers-use-telegram-github-to-attack-czech-presidential-election/
15/01/2023 16:07:24
QRCode
archive.org
thumbnail

The Record by Recorded Future gives exclusive, behind-the-scenes access to leaders, policymakers, researchers, and the shadows of the cyber underground.

therecord EN 2023 Telegram GitHub Pro-Russia Czech election DDOSIA Sentinelone
zhuowei/WDBFontOverwrite: Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689. https://github.com/zhuowei/WDBFontOverwrite
30/12/2022 11:46:10
QRCode
archive.org
thumbnail

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

Works on iOS 16.1.2 and below (tested on iOS 16.1) on unjailbroken devices.

zhuowei EN GitHub PoC iOS CVE-2022-46689 unjailbroken ComicSans
Okta's source code stolen after GitHub repositories hacked https://www.bleepingcomputer.com/news/security/oktas-source-code-stolen-after-github-repositories-hacked/
21/12/2022 11:05:22
QRCode
archive.org
thumbnail

In a 'confidential' email notification sent by Okta and seen by BleepingComputer, the company states that attackers gained access to its GitHub repositories this month and stole the company's source code.

bleepingcomputer en 2022 GitHub Okta Source-Code Theft
Attacking Apple's Neural Engine https://github.com/0x36/weightBufs/blob/main/attacking_ane_poc2022.pdf
12/11/2022 21:59:41
QRCode
archive.org
thumbnail

WeightBufs is a kernel r/w exploit for all Apple devices with Neural Engine support. Bugs and Exploit by @simo36, you can read my presentation slides at POC for more details about the vulnerabilities and the exploitation techniques.

0x36 EN 2022 WeightBufs GitHub Apple ios macos exploit NeuralEngine exploitation CVE-2022-32845 CVE-2022-32948 CVE-2022-42805 CVE-2022-32899
How we handled a recent phishing incident that targeted Dropbox https://dropbox.tech/security/a-recent-phishing-campaign-targeting-dropbox
02/11/2022 07:00:10
QRCode
archive.org
thumbnail

We were recently the target of a phishing campaign that successfully accessed some of the code we store in GitHub. No one’s content, passwords, or payment information was accessed, and the issue was quickly resolved. Our core apps and infrastructure were also unaffected, as access to this code is even more limited and strictly controlled. We believe the risk to customers is minimal. Because we take our commitment to security, privacy, and transparency seriously, we have notified those affected and are sharing more here.

dropbox EN 2022 incident phishing GitHub
Dec0ne/KrbRelayUp: KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). https://github.com/Dec0ne/KrbRelayUp
27/04/2022 10:54:45
QRCode
archive.org
thumbnail

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). - GitHub - Dec0ne/KrbRelayUp: KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

GitHub EN 2022 no-fix vulnerability Windows LDAP domain signing KrbRelayUp privilege escalation
GitHub: Attacker breached dozens of orgs using stolen OAuth tokens https://www.bleepingcomputer.com/news/security/github-attacker-breached-dozens-of-orgs-using-stolen-oauth-tokens/
18/04/2022 09:45:06
QRCode
archive.org
thumbnail

GitHub revealed today that an attacker is using stolen OAuth user tokens (issued to Heroku and Travis-CI) to download data from private repositories.

Breach GitHub OAuth Warning bleepingcomputer EN 2022
Git security vulnerability announced https://github.blog/2022-04-12-git-security-vulnerability-announced/
13/04/2022 08:12:27
QRCode
archive.org
thumbnail

GitHub is unaffected by the vulnerabilities, but users should be aware of them and upgrade their local installation of Git.

Git github 2022 EN CVE-2022-24765 CVE-2022-24767 vulnerability
page 2 / 2
4250 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio