Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 211 / 239
EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
05/09/2022 14:06:10
QRCode
archive.org

Following the recent Twilio hack leading to the leakage of 2FA (OTP) codes, cybercriminals continue to upgrade their attack arsenal to orchestrate advanced phishing campaigns targeting users worldwide. Resecurity has recently identified a new Phishing-as-a-Service (PhaaS) called EvilProxy advertised in the Dark Web. On some sources the alternative name is Moloch, which has some connection to a phishing-kit developed by several notable underground actors who targeted the financial institutions and e-commerce sector before.

Resecurity EN 2022 EvilProxy Phishing-as-a-Service MFA Bypass 2FA
Malicious Cookie Stuffing Chrome Extensions with 1.4 Million Users https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/
05/09/2022 10:11:08
QRCode
archive.org
thumbnail

A few months ago, we blogged about malicious extensions redirecting users to phishing sites and inserting affiliate IDs into cookies of eCommerce sites. Since that time, we have investigated several other malicious extensions and discovered 5 extensions with a total install base of over 1,400,000
"...the extensions also track the user’s browsing activity."

mcafee 2022 EN malicious extensions Chrome Analysis privacy browser cookie Stuffing
Sharkbot is back in Google Play https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play/
05/09/2022 10:04:50
QRCode
archive.org
thumbnail

Authored by Alberto Segura (main author) and Mike Stokkel (co-author) Introduction After we discovered in February 2022 the SharkBotDropper in Google Play posing as a fake Android antivirus and cleaner, now we have detected a new version of this dropper active in the Google Play and dropping a new version of Sharkbot.This new dropper doesn't…

fox-it EN 2022 sharkbot SharkBotDropper GooglePlay antivirus cleaner fake
Peut-on encore, en Suisse, recourir à des services cloud offerts par Microsoft ? https://swissprivacy.law/165/
05/09/2022 09:04:24
QRCode
archive.org

Dans une prise de position publiée le 13 juin 2022, le Préposé fédéral à la protection des données et à la transparence a estimé que le recours aux services cloud M365 de Microsoft serait susceptible de violer la Loi fédérale sur la protection des données, quand bien même le projet de la Caisse nationale suisse d'assurance en cas d'accidents (SUVA) envisage que les données soient hébergées en Suisse et que le cocontractant du responsable du traitement soit une entité européenne du Groupe Microsoft.

swissprivacy FR 2022 CH Suisse Préposé-fédéral Microsoft cloud protection données Cloud-Act
Stealing Clouds https://www.reuters.com/investigates/special-report/china-cyber-cloudhopper/
04/09/2022 12:56:29
QRCode
archive.org
thumbnail

Reuters shows how Chinese hackers invaded myriad global companies, exposing entrenched weaknesses in Western cyber defenses.

Reuters 2019 Chinese APT10 Cloud attack Cloud-Hopper Ericsson IBM HP
Adoption de l’OPDo et confirmation de l’entrée en vigueur de la nLPD https://smetille.ch/2022/09/02/adoption-de-lordonnance-sur-la-protection-des-donnees/?s=09
03/09/2022 14:12:01
QRCode
archive.org

Comme cela était attendu, le Conseil fédéral a adopté les projets d’Ordonnance sur la protection des données (OPDo) et d’Ordonnance sur les certifications en matière de protection des données (OCPD) Plus rien ne s’oppose donc à l’entrée en vigueur de la Loi sur la protection des données révisée (nLPD) le 1er septembre 2023. Le Conseil fédéral a en effet souhaité laisser encore un peu de temps aux petites et moyennes entreprises pour se mettre en conformité.

smetille CH FR 2022 legal nLPD lois protection OPDo données Suisse Switzerland law
Hackers Create Traffic Jam in Moscow by Ordering Dozens of Taxis at Once Through App https://www.vice.com/en/article/y3pbgy/hackers-create-traffic-jam-in-moscow-by-ordering-dozens-of-taxis-at-once-through-app
03/09/2022 12:55:00
QRCode
archive.org
thumbnail

Attackers attempted to disrupt ride-hailing app service on Thursday, the company confirmed.

vice EN 2022 Yandex Moscow Taxis app hacked traffic jam Hackers
PyPI Phishing Campaign | JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks/
03/09/2022 11:24:16
QRCode
archive.org
thumbnail

A new threat actor is spreading infostealer malware through targeted attacks on developers and fraudulent cryptotrading applications.

sentinelone EN 2022 PyPI JuiceLedger infostealer malware ANALYSIS
Tech tool offers police ‘mass surveillance on a budget’ https://apnews.com/article/technology-police-government-surveillance-d395409ef5a8c6c3f6cdab5b1d0e27ef
03/09/2022 10:11:06
QRCode
archive.org
thumbnail

Local law enforcement agencies from suburban Southern California to rural North Carolina have been using an obscure cellphone tracking tool, at times without search warrants, that gives them the power to follow people’s movements months back in time, according to public records and internal emails obtained by The Associated Press.

ApNews EN 2022 AP-Investigations Technology Police California Arkansas Weekend-Reads North-Carolina privacy Government-surveillance Law-enforcement-agencies Criminal-investigations
Researchers found one-click exploits in Discord and Teams https://www.malwarebytes.com/blog/news/2022/08/researchers-found-one-click-exploits-in-discord-and-teams
31/08/2022 16:58:02
QRCode
archive.org
thumbnail

A group of security researchers found a series of vulnerabilities in the software underlying popular apps like Discord, Microsoft Teams, Spotify and many others

malwarebytes EN 2022 Electron vulnerability
Zimbra Open Bucket Data Leak – Responsible Disclosure https://members.backbox.org/zimbra-open-bucket-data-leak-responsible-disclosure/
31/08/2022 10:14:16
QRCode
archive.org

Hundreds of millions use Zimbra, an all-in-one business productivity suite for micro, small, medium & enterprise in-office and remote work teams. The Zimbra Inc company was acquired by Synacor Inc

backbox EN 2022 Leak Zimbra Disclosure Bucket
Traffers: a deep dive into the information stealer ecosystem https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem/
31/08/2022 08:42:44
QRCode
archive.org
thumbnail

Traffers are responsible for redirecting user traffic to malicious content (malware, fraud, phishing, scam) exploited by other threat actors.

sekoia EN 2022 Traffers traffic web stealer
Cette entreprise vend des données aussi sensibles que des visites dans des centres IVG - Numerama https://www.numerama.com/cyberguerre/1092470-cette-societe-revend-les-informations-de-centaines-de-millions-dutilisateurs-dans-le-monde.html
31/08/2022 08:28:10
QRCode
archive.org
thumbnail

La Federal Trade Commission, l'agence responsables des bonnes pratiques commerciales aux États-Unis, a lancé une procédure judiciaire contre Kocheva, un groupe chargé du traitement de données de milliers d'entreprises, dont Googles Ads, TikTok ou Tinder. Cette société est accusée de revendre des informations très

numerama FR 2022 Ftc US Kochava data-broker privacy
FTC says data broker sold consumers’ precise geolocation, including presence at sensitive healthcare facilities https://www.ftc.gov/business-guidance/blog/2022/08/ftc-says-data-broker-sold-consumers-precise-geolocation-including-presence-sensitive-healthcare
31/08/2022 08:26:24
QRCode
archive.org
thumbnail

When people seek medical care or visit other sensitive locations, they may think their presence is confidential.

ftc US EN 2022 Kochava data-broker locations privacy
EU and Greece veer toward standoff over wiretapping scandal – POLITICO https://www.politico.eu/article/eu-and-greece-near-standoff-over-phone-tapping-scandal/
31/08/2022 08:17:19
QRCode
archive.org
thumbnail

‘Democracy and rule of law are at stake,’ says MEP Saskia Bricmont.

politico EN EU Greece spyware wiretapping Predator
5G Networks Are Worryingly Hackable https://spectrum.ieee.org/5g-virtualization-increased-hackability
30/08/2022 15:00:11
QRCode
archive.org
thumbnail

Mobile operators have traditionally relied on proprietary hardware from vendors like Ericsson, Nokia and Huawei to build their networks. And now with 5G comes the push to “virtualize” network functions, replicating key elements in software so they can run on generic hardware, or even in the cloud.

ieee telecommunications Open-RAN 5g Hackable
Notice of Recent Security Incident https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/
29/08/2022 10:26:34
QRCode
archive.org

We have no evidence that this incident involved any access to customer data or encrypted password vaults. Our products and services are operating normally.

lastpass EN 2022 incident unauthorized access
Detecting Scatter Swine: Insights into a relentless phishing campaign https://sec.okta.com/scatterswine
29/08/2022 10:25:04
QRCode
archive.org

Twilio recently identified unauthorized access to information related to 163 Twilio customers, including Okta.

okta 2022 EN unauthorized access Twilio phishing
Kimsuky’s GoldDragon cluster and its C2 operations | Securelist https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258/
28/08/2022 16:28:02
QRCode
archive.org
thumbnail

Kimsuky is a prolific and active threat actor primarily targeting Korea-related entities. In early 2022, we observed this group was attacking the media and a think-tank in South Korea.

securelist 2022 EN APT Keyloggers Kimsuky Malware-Descriptions Microsoft-Word Spear-phishing Targeted-attacks North-Korea
Spyware italiano nel mondo. https://telegra.ph/Spyware-italiano-nel-mondo-08-28
28/08/2022 12:46:56
QRCode
archive.org

La sorveglianza europea parte da un’azienda italiana

investigation spyware Italia IT 2022 Hermit Tykelab
page 211 / 239
4762 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio