Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 21 / 41
817 résultats taggé 2022  ✕
Impact to DigitalOcean customers resulting from Mailchimp security incident https://www.digitalocean.com/blog/digitalocean-response-to-mailchimp-security-incident
17/08/2022 12:44:54
QRCode
archive.org
thumbnail

The security of DigitalOcean customers and their data is a responsibility we approach with utmost dedication. When our customers' security is threatened we respond swiftly, communicate with transpa...

digitalocean EN 2022 Mailchimp incident breach
Two more malicious Python packages in the PyPI https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218/
16/08/2022 19:41:05
QRCode
archive.org

We used our internal automated system for monitoring open-source repositories and discovered two other malicious Python packages in the PyPI.

securelist 2022 EN PyPI Credentials-theft Data-theft Malware Open-source Python Trojan
Ransomware Now Threatens the Global South https://rusi.org/explore-our-research/publications/commentary/ransomware-now-threatens-global-south
16/08/2022 19:29:03
QRCode
archive.org
thumbnail

Increased targeting of developing and middle-income countries by ransomware actors presents a challenge to political resilience, economic development and global cyber security.

rusi EN 2022 ransomware South shift target political resilience
Zoom’s latest update on Mac includes a fix for a dangerous security flaw https://www.theverge.com/2022/8/14/23305548/zoom-update-macos-fix-dangerous-security-flaw-hackers?scrolla=5eb6d68b7fedc32c19ef33b4
16/08/2022 06:51:56
QRCode
archive.org
thumbnail

Zoom has issued a patch for a bug on macOS that could allow a hacker to take control of a user’s operating system (via MacRumors). In an update on its security bulletin, Zoom acknowledges the issue (CVE-2022-28756) and says a fix is included in version 5.11.5 of the app on Mac, which you can (and should) download now.

theverge EN 2022 CVE-2022-28756 macos Zoom
Process injection: breaking all macOS security layers with a single vulnerability &middot https://sector7.computest.nl/post/2022-08-process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability/
15/08/2022 10:13:36
QRCode
archive.org

In macOS 12.0.1 Monterey, Apple fixed CVE-2021-30873. This was a process injection vulnerability affecting (essentially) all macOS AppKit-based applications. We reported this vulnerability to Apple, along with methods to use this vulnerability to escape the sandbox, elevate privileges to root and bypass the filesystem restrictions of SIP.

sector7 EN 2022 macOS CVE-2021-30873 Process injection
NHS IT supplier held to ransom by hackers https://www.bbc.com/news/technology-62506039
14/08/2022 21:42:51
QRCode
archive.org
thumbnail

Its IT provider says it may take three or four weeks to fully recover from the cyber-attack.

BBC EN 2022 NHS UK Ransomware healthcare
Cisco confirms May attack by Yanluowang ransomware group https://therecord.media/cisco-confirms-may-attack-by-yanluowang-ransomware-group/
14/08/2022 21:40:33
QRCode
archive.org
thumbnail

Cisco confirmed on Wednesday that it was attack by the Yanluowang ransomware group in May, but said the hackers were not able to steal sensitive data or impact the company’s operations.

In a statement to The Record, Cisco said the incident occured on their corporate network in late May and that they “immediately took action to contain and eradicate the bad actors.”

therecord EN 2022 Yanluowang Cisco talos phishing voicemail
Phishers who breached Twilio and targeted Cloudflare could easily get you, too https://arstechnica.com/information-technology/2022/08/phishers-breach-twilio-and-target-cloudflare-using-workers-home-numbers/
14/08/2022 21:37:56
QRCode
archive.org
thumbnail

Unusually resourced threat actor has targeted multiple companies in recent days.

arstechnica EN 2022 Twilio cloudflare phishing threat
The mechanics of a sophisticated phishing scam and how we stopped it https://blog.cloudflare.com/2022-07-sms-phishing-attacks/
14/08/2022 21:36:00
QRCode
archive.org

Yesterday, August 8, 2022, Twilio shared that they’d been compromised by a targeted phishing attack. Around the same time as Twilio was attacked, we saw an attack with very similar characteristics also targeting Cloudflare’s employees. While individual employees did fall for the phishing messages, we were able to thwart the attack through our own use of Cloudflare One products, and physical security keys issued to every employee that are required to access all our applications.

cloudflare EN 2022 phishing scam Twilio okra
Hands-on with Lockdown Mode in iOS 16 https://techcrunch.com/2022/08/12/apple-lockdown-mode-ios-16/
14/08/2022 18:31:18
QRCode
archive.org
thumbnail

Lockdown Mode is a new Apple feature you should hope you’ll never need to use. But for those who do, like journalists, politicians, lawyers and human rights defenders, it’s a last line of defense against nation-state spyware designed to punch through an iPhone’s protections. The new security feature was announced earlier this year as an […]

techcrunch EN 2022 apple LockdownMode ios ipad iphone handson ios16
You're M̶u̶t̶e̶d̶ Rooted https://speakerdeck.com/patrickwardle/youre-muted-rooted
13/08/2022 22:44:11
QRCode
archive.org
thumbnail

With a recent market cap of over $100 billion and the genericization of its name, the popularity of Zoom is undeniable. But what about its security? This imperative question is often quite personal, as who amongst us isn't jumping on weekly (daily?) Zoom calls?

In this talk, we’ll explore Zoom’s macOS application to uncover several critical security flaws. Flaws, that provided a local unprivileged attacker a direct and reliable path to root.

The first flaw, presents itself subtly in a core cryptographic validation routine, while the second is due to a nuanced trust issue between Zoom’s client and its privileged helper component.

After detailing both root cause analysis and full exploitation of these flaws, we’ll end the talk by showing how such issues could be avoided …both by Zoom, but also in other macOS applications.

patrickwardle EN 2022 macOS zoom rooted defcon PoC
Realtek SDK Vulnerability Exposes Routers From Many Vendors to Remote Attacks https://www.securityweek.com/realtek-sdk-vulnerability-exposes-routers-many-vendors-remote-attacks
13/08/2022 19:21:14
QRCode
archive.org

A serious vulnerability affecting the eCos SDK made by Taiwanese semiconductor company Realtek could expose the networking devices of many vendors to remote attacks.

securityweek EN 2022 SDK remote attack vulnerability Rrealtek CVE-2022-27255
Palo Alto bug used for DDoS attacks and there's no fix yet https://www.theregister.com/2022/08/12/palo_alto_bug/
13/08/2022 10:46:28
QRCode
archive.org
thumbnail

A high-severity Palo Alto Networks denial-of-service (DoS) vulnerability has been exploited by miscreants looking to launch DDoS attacks, and several of the affected products won't have a patch until next week

theregister EN 2022 paloaltonetworks bug DDoS CVE-2022-0028
The internet is not ready for the flood of AI-generated text https://mondaynote.com/the-internet-is-not-ready-for-the-flood-of-ai-generated-text-a082976c6186
12/08/2022 19:45:55
QRCode
archive.org

The way that many of our systems currently focus on engagement makes them particularly vulnerable to the incoming wave of content from bots like GPT-3

mondaynote EN 2022 GPT-3 bot content internet text AI AI-generated
The Hacking of Starlink Terminals Has Begun https://www.wired.com/story/starlink-internet-dish-hack/
12/08/2022 12:21:57
QRCode
archive.org
thumbnail

It cost a researcher only $25 worth of parts to create a tool that allows custom code to run on the satellite dishes.

wired EN 2022 hack Starlink
CISA warns of Windows and UnRAR flaws exploited in the wild https://www.bleepingcomputer.com/news/security/cisa-warns-of-windows-and-unrar-flaws-exploited-in-the-wild/
12/08/2022 07:43:58
QRCode
archive.org
thumbnail

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two more flaws to its catalog of Known Exploited Vulnerabilities, based on evidence of active exploitation.

bleepingcomputer EN 2022 CISA DogWalk UnRAR CVE-2022-34713 MSDT CVE-2022-30333
Comprehensive Threat Intelligence: Cisco Talos shares insights related to recent cyber attack on Cisco https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html?m=1
11/08/2022 20:22:21
QRCode
archive.org
thumbnail
  • On May 24, 2022, Cisco became aware of a potential compromise. Since that point, Cisco Security Incident Response (CSIRT) and Cisco Talos have been working to remediate.
  • During the investigation, it was determined that a Cisco employee’s credentials were compromised after an attacker gained control of a personal Google account where credentials saved in the victim’s browser were being synchronized.
talosintelligence EN 2022 Cisco attack Google sync password insights
A new botnet Orchard Generates DGA Domains with Bitcoin Transaction Information https://blog.netlab.360.com/a-new-botnet-orchard-generates-dga-domains-with-bitcoin-transaction-information/
09/08/2022 13:07:41
QRCode
archive.org

DGA is one of the classic techniques for botnets to hide their C2s, attacker
only needs to selectively register a very small number of C2 domains, while for
the defenders, it is difficult to determine in advance which domain names will
be generated and registered.

netlab360 EN 2022 Orchard botnet C2 bitcoin domains
So RapperBot, What Ya Bruting For? https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery
07/08/2022 21:24:01
QRCode
archive.org
thumbnail

In June 2022, FortiGuard Labs encountered IoT malware samples with SSH-related strings, something not often seen in other IoT threat campaigns. What piqued our interest more was the size of the code referencing these strings in relation to the code used for DDoS attacks, which usually comprises most of the code in other variants.

fortinet EN 2022 RapperBot research threat IoT Mirai SSH-2.0-HELLOWORLD botnet
Greek intelligence service admits spying on journalist https://www.reuters.com/world/europe/greek-intelligence-service-admits-spying-journalist-sources-2022-08-03/
07/08/2022 12:32:54
QRCode
archive.org
thumbnail

The head of Greek intelligence told a parliamentary committee his agency had spied on a journalist, two sources present said, in a disclosure that coincides with growing pressure on the government to shed light on the use of surveillance malware.

Reuters EN 2022 spyware Greece intelligence surveillance
page 21 / 41
4832 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn