Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 208 / 238
The Apple security landscape: Moving into the world of enterprise risk https://venturebeat.com/security/apple-security-vulnerabilities/
23/09/2022 12:26:51
QRCode
archive.org
thumbnail

With the enterprise adoption of MacOS and iOS devices increasing, the Apple security landscape is becoming increasingly complex.

venturebeat EN 2022 MacOS iOS security enterprise landscape
Iranian State Actors Conduct Cyber Operations Against the Government of Albania https://www.cisa.gov/uscert/ncas/alerts/aa22-264a
22/09/2022 16:43:03
QRCode
archive.org

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory to provide information on recent cyber operations against the Government of Albania in July and September. This advisory provides a timeline of activity observed, from initial access to execution of encryption and wiper attacks. Additional information concerning files used by the actors during their exploitation of and cyber attack against the victim organization is provided in Appendices A and B.

cisa EN 2022 uscert csirt cert US Iran Albania attribution IoCs FBI
Apple Kills Passwords in iOS 16 and macOS Ventura | WIRED https://www.wired.com/story/apple-passkeys-password-iphone-mac-ios16-ventura/
22/09/2022 16:40:14
QRCode
archive.org
thumbnail

With iOS 16 and macOS Ventura, Apple is introducing passkeys—a more convenient and secure alternative to passwords.

wired EN 2022 apple privacy passwords ios macOS iOS passkeys
Domain Shadowing: A Stealthy Use of DNS Compromise for Cybercrime https://unit42.paloaltonetworks.com/domain-shadowing/
22/09/2022 15:39:32
QRCode
archive.org
thumbnail

Domain shadowing is a special case of DNS hijacking where attackers stealthily create malicious subdomains under compromised domain names.

paloaltonetworks EN 2022 DNS hijacking Domain shadowing analysis IoCs Domain-shadowing
Revealed: US Military Bought Mass Monitoring Tool That Includes Internet Browsing, Email Data https://www.vice.com/en/article/y3pnkw/us-military-bought-mass-monitoring-augury-team-cymru-browsing-email-data
22/09/2022 15:28:19
QRCode
archive.org
thumbnail

The “Augury” platform includes highly sensitive network data that Team Cymru, a private company, is selling to the military. “It’s everything. There’s nothing else to capture except the smell of electricity,” one cybersecurity expert said.

vice EN 2022 Augury Cymru U.S. military NCIS privacy
Los Angeles School District Hit by Ransomware Attack https://www.databreachtoday.com/los-angeles-school-district-hit-by-ransomware-attack-a-19999
22/09/2022 12:27:49
QRCode
archive.org
thumbnail

California's largest public school district and the second-largest in the U.S. is undergoing a ransomware attack. The attack has disrupted the district's email

databreachtoday EN 2022 ransomware Los-Angeles PYSA Ryuk School K-12
Online Attack Disrupts Michigan School District for 2nd Day https://www.databreachtoday.eu/cyberattack-disrupts-michigan-school-district-for-2nd-day-a-20119
22/09/2022 12:27:02
QRCode
archive.org
thumbnail

School is out for more than 3,000 students of a suburban Detroit district undergoing its second day of forensics analysis following an online attack. Students have

databreachtoday EN 2022 Cyberattack Ransomware school k-12 South-Redford-School-District Chromebook Brett-Callow
LockBit ransomware builder leaked online by “angry developer” https://www.bleepingcomputer.com/news/security/lockbit-ransomware-builder-leaked-online-by-angry-developer-/
22/09/2022 12:25:20
QRCode
archive.org
thumbnail

The LockBit ransomware operation has suffered a breach, with an allegedly disgruntled developer leaking the builder for the gang's newest encryptor.

bleepingcomputer EN 2022 Breach Developer Encryptor LockBit Ransomware Ransomware-Builder Leak
Azure Cloud Shell Command Injection Stealing User’s Access Tokens https://blog.lightspin.io/azure-cloud-shell-command-injection-stealing-users-access-tokens
21/09/2022 23:44:32
QRCode
archive.org
thumbnail

This post describes how I took over an Azure Cloud Shell trusted domain and leveraged it to inject and execute commands in other users’ terminals.

lightspin EN 2022 Azure Cloud Shell injection terminals IoCs Analysis Tokens steal
Threat Alert: New Malware in the Cloud By TeamTNT https://blog.aquasec.com/new-malware-in-the-cloud-by-teamtnt
21/09/2022 23:41:46
QRCode
archive.org
thumbnail

Could TeamTNT be back? Our honeypots were attacked by malware that bears a resemblance to these threat actors and we analyze the possible connection.

aquasec EN 2022 TeamTNT Analysis
The Evolution of the Chromeloader Malware - VMware Security Blog - VMware https://blogs.vmware.com/security/2022/09/the-evolution-of-the-chromeloader-malware.html
21/09/2022 23:39:47
QRCode
archive.org

The VMware Carbon Black MDR team goes in depth on the latest variants of the Chromeloader malware and how to detect them.

vmware EN 2022 Chromeloader malware IoCs Analysis
Chromium Blog: Announcing the Launch of the Chrome Root Program https://blog.chromium.org/2022/09/announcing-launch-of-chrome-root-program.html
21/09/2022 23:28:46
QRCode
archive.org
thumbnail

In 2020, we announced we were in the early phases of establishing the Chrome Root Program and launching the Chrome Root Store.

The Chrome Root Program ultimately determines which website certificates are trusted by default in Chrome, and enables more consistent and reliable website certificate validation across platforms.

This post shares an update on our progress and how these changes help us better protect Chrome’s users.

chromium EN 2022 root store certificates trust
Record 25.3 Billion Request Multiplexing Attack Mitigated by Imperva https://www.imperva.com/blog/record-25-3-billion-request-multiplexing-attack-mitigated-by-imperva/
21/09/2022 22:49:37
QRCode
archive.org

On June 27, 2022, Imperva mitigated a single attack with over 25.3 billion requests, setting a new record for Imperva’s application DDoS mitigation solution.

While attacks with over one million requests per second (RPS) aren’t new, we’ve previously only seen them last for several seconds to a few minutes. On June 27, Imperva successfully mitigated a strong attack that lasted more than four hours and peaked at 3.9 million RPS.

imperva EN 2022 DDoS RPS attack
Affaire Pegasus: l'Union européenne se penche sur le dossier suisse - rts.ch - Monde https://www.rts.ch/info/monde/13397954-affaire-pegasus-lunion-europeenne-se-penche-sur-le-dossier-suisse.html
20/09/2022 14:01:13
QRCode
archive.org
thumbnail

Le Haut Commissariat aux droits de l’homme des Nations unies a publié vendredi un nouveau rapport extrêmement alarmant sur les menaces des nouvelles technologies de surveillance quant au respect de la vie privée et des droits humains. Les usages dénoncés font largement écho à la situation en Suisse.

rts CH FR 2022 Pegasus Suisse Fanti EU
Turning Your Computer Into a GPS Tracker With Apple Maps https://breakpoint.sh/posts/turning-your-computer-into-a-gps-tracker-with-apple-maps
20/09/2022 13:41:36
QRCode
archive.org

One of the things Apple cares about in terms of its bug bounty program is your location data. Apple rightly categorizes real-time or historical precise location data as "sensitive data" which in some cases qualifies for a significant monetary award.

breakpoint EN 2022 macOS maps leak sensitive location CVE-2022-32883
Six months into Breached: The legacy of RaidForums? https://ke-la.com/six-months-into-breached-the-legacy-of-raidforums/
20/09/2022 00:27:59
QRCode
archive.org
thumbnail

On March 14, 2022, a new English-language cybercrime forum called Breached (also known as BreachForums) launched, as a response to the closure and seizure of the popular RaidForums. Breached was launched with the same design by the threat actor “pompompurin” as “an alternative to RaidForums,” offering large-scale database leaks, login credentials, adult content, and hacking tools.

ke-la EN 2022 Breached forum Analysis RaidForums pompompurin cybercrime
Incoscienti e sfacciati: le tecniche dei teenager che violano aziende https://www.guerredirete.it/incoscienti-e-sfacciati-le-tecniche-dei-teenager-che-violano-aziende/
20/09/2022 00:19:12
QRCode
archive.org
thumbnail

Specializzati soprattutto in social engineering, i ragazzini di oggi continuano, come un tempo, a essere protagonisti di gravi incidenti informatici. Come è possibile?

guerredirete IT 2022 LAPSUS$ social Social-Engineering teenager
How Russian Trolls Helped Keep the Women’s March Out of Lock Step https://www.nytimes.com/2022/09/18/us/womens-march-russia-trump.html
20/09/2022 00:08:16
QRCode
archive.org

As American feminists came together in 2017 to protest Donald Trump, Russia’s disinformation machine set about deepening the divides among them.

nytimes 2022 EN Russia disinformation divides trolls media
Chrome & Edge Enhanced Spellcheck Features Expose PII, Even Your Passwords https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords
20/09/2022 00:04:47
QRCode
archive.org

Some of the largest websites in the world have exposure to sending Google and Microsoft sensitive user PII, including username, email, and passwords

otto-js EN 2022 Chrome Edge Spellcheck Spell-Jacking leak
Unflattening ConfuserEx .NET Code in IDA https://www.govcert.ch/blog/unflattening-confuserex-code-in-ida/
20/09/2022 00:01:22
QRCode
archive.org

we’re studying the ConfuserEx1 obfuscation mechanism of a Ginzo .NET sample. This class of obfuscator is known as code flatteners. We describe how it can dealt with it using a Python script within IDA Pro2, a famous reverse-engineering tool.

GovCERT EN 2022 CH NCSC ConfuserEx1 ConfuserEx obfuscation IDA reverse-engineering
page 208 / 238
4760 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio