Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 202 / 251
Hostile Takeover: Kraken Hacks Rival Darknet Market Solaris https://www.databreachtoday.com/hostile-takeover-kraken-hacks-rival-darknet-market-solaris-a-20986
23/01/2023 13:12:50
QRCode
archive.org
thumbnail

Since Hydra Market Got Shuttered by Police, Russian Rivals Battle for Market Share.
Competition between Russian-language darknet markets remains fierce following the takedown of market leader Hydra last April by a multinational law enforcement operation.

databreachtoday EN 2023 Hydra darkweb darknet market takeover Kraken Solaris
Darth Vidar: The Dark Side of Evolving Threat Infrastructure https://www.team-cymru.com/post/darth-vidar-the-dark-side-of-evolving-threat-infrastructure
23/01/2023 13:04:53
QRCode
archive.org
thumbnail

Summary Three key takeaways from our analysis of Vidar infrastructure: Russian VPN gateways are potentially providing anonymity for Vidar operators / customers, making it more challenging for analysts to have a complete overview of this threat. These gateways now appear to be migrating to Tor. Vidar operators appear to be expanding their infrastructure, so analysts need to keep them in their sights. We expect a new wave of customers and as a result, an increase of campaigns in the upcoming weeks

team-cymru EN 2023 Vidar infostealer analysis threat infrastructure VPN
Risky Biz News: Crypto-crime volumes went down in 2022, ransomware payments too https://riskybiznews.substack.com/p/risky-biz-news-crypto-crime-volumes
23/01/2023 11:21:46
QRCode
archive.org
thumbnail

Crypto-crime volumes went down in 2022, ransomware payments too
In other news: Riot Games cancels game updates after hack; T-Mobile discloses eighth breach since 2018; APT group deploys DNS changer on victims' routers.

riskybiznews EN 2023 newsletter Crypto-crime T-Mobile RiotGames
New GTA Online exploit now allows cheaters to ban your account https://rockstarintel.com/new-gta-online-exploit-now-lets-cheaters-to-ban-your-account
22/01/2023 15:39:01
QRCode
archive.org
thumbnail

a new Grand Theft Auto: Online exploit now allows cheaters to ban or delete peoples online profile and edit their stats

rockstarintel EN 2023 game vulnerability exploit GTA Online
Breaking Down the SEO Poisoning Attack | How Attackers Are Hijacking Search Results https://www.sentinelone.com/blog/breaking-down-the-seo-poisoning-attack-how-attackers-are-hijacking-search-results/
21/01/2023 22:56:51
QRCode
archive.org
thumbnail

SEO poisoning is gaining momentum as threat actors leverage malicious ads to deliver malware through web browser searches.

sentinelone EN 2023 SEO poisoning Hijacking Search Results googleads malware web malicious
Ransomware Diaries: Volume 1 https://analyst1.com/ransomware-diaries-volume-1/
21/01/2023 17:51:19
QRCode
archive.org

The LockBit ransomware gang is one of the most notorious organized cybercrime syndicates that exists today. The gang is behind attacks targeting private-sector corporations and other high-profile industries worldwide. News and media outlets have documented many LockBit attacks, while security vendors offer technical assessments explaining how each occurred. Although these provide insight into the attacks, I wanted to know more about the human side of the operation to learn about the insights, motivations, and behaviors of the individuals on the other side of the keyboard. To prepare for this project, I spent months developing several online personas and established their credibility over time to gain access to the gang’s operation.

analyst1 EN 2023 LockBit ransomware Insights
Enregistrez un contact de sécurité sur votre site Internet https://www.ncsc.admin.ch/ncsc/fr/home/aktuell/im-fokus/2023/security_txt.html
21/01/2023 14:44:23
QRCode
archive.org

19.01.2023 - En cas de problème de cybersécurité au sein d'une entreprise ou d'une organisation, il est crucial d'en informer aussitôt le responsable de la sécurité. Or, il est généralement difficile, voire impossible, de retrouver ce dernier sur les sites Internet. La norme «security.txt» sert à indiquer de manière uniforme le responsable de la sécurité d'une entreprise ou d'une organisation, ce qui permet de prendre contact avec lui plus rapidement.permet de prendre contact avec lui plus rapidement.

ncsc CH FR 2023 security_txt norme
Technical Advisory – Multiple Vulnerabilities in the Galaxy App Store (CVE-2023-21433, CVE-2023-21434) https://research.nccgroup.com/2023/01/20/technical-advisory-multiple-vulnerabilities-in-the-galaxy-app-store-cve-2023-21433-cve-2023-21434/
21/01/2023 14:37:26
QRCode
archive.org
thumbnail

The Galaxy App Store is an alternative application store that comes pre-installed on Samsung Android devices. Several Android applications are available on both the Galaxy App Store and Google App Store, and users have the option to use either store to install specific applications. Two vulnerabilities were uncovered with the Galaxy App Store application: Technical…

nccgroup EN 2023 Samsung Galaxy App Store Android Advisory CVE-2023-21433 CVE-2023-21434
Des hackers détournent des sites de l’UE pour voler des infos bancaires https://www.numerama.com/cyberguerre/1238968-des-hackers-detournent-des-sites-de-lue-pour-voler-des-infos-bancaires.html
21/01/2023 11:39:31
QRCode
archive.org
thumbnail

Plusieurs noms de domaine de l'Union européenne ont été utilisés par des malfaiteurs pour promouvoir des sites de streaming gratuits. Ces liens sont en réalité des pièges pour dérober des informations bancaires. Le vrai défi d'un piratage réside dans la manière de présenter le piège à la victime. Plutôt que d'envoyer

numerama FR 2023 EU streaming pièges arnaques détournement sites institutionnels arnaques
PayPal Notifies 35,000 Users of Data Breach https://www.hackread.com/paypal-data-breach-alert/
21/01/2023 11:27:50
QRCode
archive.org
thumbnail

PayPal has alerted over 35,000 customers of a data breach revealing that their accounts were hacked between December 6th and 8th, 2022.

hackread EN 2023 PayPal breach accounts hacked
ManageEngine CVE-2022-47966 Technical Deep Dive https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/
20/01/2023 15:29:40
QRCode
archive.org
thumbnail

Introduction On January 10, 2023, ManageEngine released a security advisory for CVE-2022-47966 (discovered by Khoadha of Viettel Cyber Security) affecting a wide range of products. The vulnerability allows an attacker to gain remote code execution by issuing a HTTP POST request containing a malicious SAML response. This vulnerability is a result of  using an outdated […]

horizon3 EN 2023 ManageEngine CVE-2022-47966 Technical DeepDive
T-Mobile hacked to steal data of 37 million accounts in API data breach https://www.bleepingcomputer.com/news/security/t-mobile-hacked-to-steal-data-of-37-million-accounts-in-api-data-breach/
20/01/2023 12:05:15
QRCode
archive.org
thumbnail

T-Mobile disclosed a new data breach after a threat actor stole the personal information of 37 million current postpaid and prepaid customer accounts through one of its Application Programming Interfaces (APIs).

bleepingcomputer EN 2023 Data-Breach Security-Breach T-Mobile
Hackers push malware via Google search ads for VLC, 7-Zip, CCleaner https://www.bleepingcomputer.com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
20/01/2023 12:00:16
QRCode
archive.org
thumbnail

Hackers are setting up fake websites for popular free and open-source software to promote malicious downloads through advertisements in Google search results.

bleepingcomputer EN 2023 googleads Advertisement Google Info-Stealer RedLine Search Vidar
DNS changer in malicious mobile app used by Roaming Mantis https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/
20/01/2023 11:57:51
QRCode
archive.org
thumbnail

Roaming Mantis (a.k.a Shaoye) is a long-term cyberattack campaign that uses malicious Android package (APK) files to control infected Android devices and steal data. In 2022, we observed a DNS changer function implemented in its Android malware Wroba.o.

securelist EN 2023 APT RoamingMantis Google-Android Malware-Descriptions Shaoye Malware-Technologies Mobile-Malware Targeted-attacks Trojan
Batloader Malware Abuses Legitimate Tools Uses Obfuscated JavaScript Files in Q4 2022 Attacks https://www.trendmicro.com/en_us/research/23/a/batloader-malware-abuses-legitimate-tools-uses-obfuscated-javasc.html
19/01/2023 20:11:10
QRCode
archive.org
thumbnail

We discuss the Batloader malware campaigns we observed in the last quarter of 2022, including our analysis of Water Minyades-related events (This is the intrusion set we track behind the creation of Batloader).

trendmicro EN 2023 Malware Batloader analysis
Apple launches major security updates around the world https://www.independent.co.uk/tech/apple-update-iphone-ios-security-encryption-backups-b2264693.html
19/01/2023 14:16:25
QRCode
archive.org
thumbnail

Apple has launched its recent major security updates to the whole world.

independent EN 2023 Apple security updates major backup
Mailchimp says it was hacked — again https://techcrunch.com/2023/01/18/mailchimp-hacked/
19/01/2023 14:12:14
QRCode
archive.org
thumbnail

This is the second breach to hit Mailchimp in six months. It also appears to be almost identical to a previous incident.

techcrunch 2023 EN data-breach intuit mailchimp again
Russian Citizen Accused of Running Cryptocurrency Exchange Used by Criminals https://www.nytimes.com/2023/01/18/us/politics/russian-citizen-bitzlato-cryptocurrency.html?mid=1#cid=128159
19/01/2023 14:11:14
QRCode
archive.org

The charges were part of an intensifying effort by federal law enforcement agencies, in conjunction with European partners, to combat international cryptocurrency schemes and illegal transactions.

nytimes EN 2023 Russian Accused Cryptocurrency Exchange Criminals bitzlato
Russian founder of a cryptocurrency exchange known for funneling ransomware profits arrested https://www.cyberscoop.com/cryptocurrency-bitzlato-exchange-ransomware-profits-arrested/
19/01/2023 14:08:11
QRCode
archive.org
thumbnail

The arrest comes as the U.S. ramps up efforts to crack down on attempts by cybercriminals to use cryptocurrency to evade sanctions.

cyberscoop EN 2023 cryptocurrency exchange founder ransomware arrested Hydra Marketplace
Assessing Potential Exploitation of Sophos Firewall and CVE-2022-3236 https://vulncheck.com/blog/sophos-cve-2022-3236
18/01/2023 21:44:40
QRCode
archive.org
thumbnail

Sophos took immediate steps to remediate CVE-2022-3236 – an unauthenticated and remote code execution vulnerability affecting the Sophos Firewall Webadmin and User Portal HTTP interfaces – with an automated hotfix sent out in September 2022. Through its advisory published on September 23, 2022, it also alerted users who don't receive automatic hotfixes to apply the update themselves. The advisory stated the vulnerability had previously been used against "a small set of specific organizations, primarily in the South Asia region." In December, Sophos released v19.5 GA GA with an official fix.
Key Takeaways

  • As there are no public proof-of-concept exploits for CVE-2022-3236, we created our own to determine its potential for mass exploitation.
  • We scanned internet-facing Sophos Firewalls and found more than 4,000 firewalls that were too old to receive a hotfix.
  • We encourage Sophos Firewall administrators to look through their logs to determine if they see indications of exploit attempts. Two files to focus on include /logs/csc.log and /log/validationError.log.
  • Internet-facing firewalls appear to largely be eligible for hotfixes and the default authentication captcha likely prevented mass exploitation.
vulncheck EN 2023 sophos CVE-2022-3236 PoC
page 202 / 251
5010 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn