Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 212 / 220
4393 résultats taggé EN  ✕
Exploiting Scratch with a malicious image https://www.mnemonic.no/blog/exploiting-scratch-with-a-malicious-image/
12/04/2022 10:03:33
QRCode
archive.org

How handcrafted SVGs in applications can compromise applications and lead to full remote code execution in MIT’s Scratch.

2020 EN mnemonic SVG Scratch CVE-2020-7750 malicious image
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware https://www.trendmicro.com/en_id/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html
12/04/2022 08:57:37
QRCode
archive.org
thumbnail

Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965, which allows malicious actors to weaponize and execute the Mirai botnet malware. The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.

We began seeing malicious activities at the start of April 2022. We also found the malware file server with other variants of the sample for different CPU architectures.

CVE-2022-22965 trendmicro EN 2022 Spring4Shell Vulnerability SpringFramework Tomcat
Browser-in-the-Middle (BitM) attack https://link.springer.com/article/10.1007/s10207-021-00548-5
12/04/2022 08:52:43
QRCode
archive.org

Man-in-the-Middle (MitM), one of the best known attacks in the world of computer security, is among the greatest concerns for professionals in the field. Main goal of MitM is to compromise confidentiality, integrity and availability of data flowing between source and destination. However, most of its many variants involve difficulties that make it not always possible. The present paper aims at modelling and describing a new method of attack, named Browser-in-the-Middle (BitM) which, despite the similarities with MitM in the way it controls the data flow between a client and the service it accesses, bypasses some of MitM’s typical shortcomings. It could be started by phishing techniques and in some cases coupled to the well-known Man-in-the-Browser (MitB) attack. It will be seen how BitM expands the range of the possible attacker’s actions, at the same time making them easier to implement. Among its features, the absence of the need to install malware of any kind on the victim’s machine and the total control it allows the attacker are to be emphasized.
Document PDF

springer EN 2021 PDF paper BitM Browser-in-the-Middle
Police Records Show Women Are Being Stalked With Apple AirTags Across the Country https://www.vice.com/en/article/y3vj3y/apple-airtags-police-reports-stalking-harassment
10/04/2022 22:17:25
QRCode
archive.org
thumbnail

Motherboard obtained reports of stalking, harassment, and abuse using AirTags, targeting victims of intimate partner violence.

vice 2022 EN AirTags stalking harassment Women Apple police
FBI Disrupts Cyclops Blink Botnet Used by Russian Intelligence Directorate https://www.hackread.com/fbi-disrupts-cyclops-blink-botnet-russia-intel-directorate/
10/04/2022 21:38:02
QRCode
archive.org
thumbnail

The Cyclops Blink botnet was controlled by the Russian Fed. Intelligence Directorate (GRU) and compromised thousands of devices worldwide.

hackread 2022 EN CyclopsBlink Russia GRU bot FBI
DoS attacks hit Finnish websites during Zelenskyy address • The Register https://www.theregister.com/2022/04/09/dos_attacks_finland_russia/
09/04/2022 14:05:09
QRCode
archive.org
thumbnail

Cyberattacks took down Finnish government websites on Friday while Ukrainian President Volodymyr Zelenskyy addressed Finland's members of parliament (MPs).

theregister EN 2022 Finland Russia DDoS cyberwar
AcidRain | A Modem Wiper Rains Down on Europe https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/
08/04/2022 09:19:52
QRCode
archive.org
thumbnail

As the most impactful cyber attack of the Ukrainian invasion gets downplayed, SentinelLabs uncovers a more plausible explanation.

sentinelone EN AcidRain Wiper cyberwar Russia analysis
U.S. Says It Secretly Removed Malware Worldwide, Pre-empting Russian Cyberattacks - The New York Times https://www.nytimes.com/2022/04/06/us/politics/us-russia-malware-cyberattacks.html
08/04/2022 09:17:09
QRCode
archive.org
thumbnail

The operation is the latest effort by the Biden administration to thwart actions by Russia by making them public before Moscow can strike.

nytimes 2022 EN US Russia cyberwar cyberoperation preventive
Chinese hackers abuse VLC Media Player to launch malware loader https://www.bleepingcomputer.com/news/security/chinese-hackers-abuse-vlc-media-player-to-launch-malware-loader/
06/04/2022 10:17:20
QRCode
archive.org
thumbnail

Security researchers have uncovered a long-running malicious campaign from hackers associated with the Chinese government who are using VLC Media Player to launch a custom malware loader.

APT10 Backdoor China Cicada Microsoft-Exchange VLC VLC-Media-Player EN 2022 bleepingcomputer
MacOS SUHelper Root Privilege Escalation Vulnerability A Deep Dive Into CVE-2022-22639 https://www.trendmicro.com/en_us/research/22/d/macos-suhelper-root-privilege-escalation-vulnerability-a-deep-di.html
06/04/2022 10:11:02
QRCode
archive.org
thumbnail

We discovered a now-patched vulnerability in macOS SUHelper, designated as CVE-2022-22639. If exploited, the vulnerability could allow malicious actors to gain root privilege escalation.

trendmicro research reports EN 2022 MacOS CVE-2022-22639 SUHelper root
Hackers breach MailChimp's internal tools to target crypto customers https://www.bleepingcomputer.com/news/security/hackers-breach-mailchimps-internal-tools-to-target-crypto-customers/
05/04/2022 13:15:01
QRCode
archive.org
thumbnail

Email marketing firm MailChimp disclosed on Sunday that they had been hit by hackers who gained access to internal customer support and account management tools to steal audience data and conduct phishing attacks.

bleepingcomputer EN 2022 MailChimp Phishing Social-Engineering Trezor
Hackers Breach Mailchimp Email Marketing Firm to Launch Crypto Phishing Scams https://thehackernews.com/2022/04/hackers-breach-mailchimp-email.html
05/04/2022 13:14:00
QRCode
archive.org

Email marketing service Mailchimp on Monday revealed a data breach that resulted in the compromise of an internal tool to gain unauthorized access to customer accounts and stage phishing attacks.

thehackernews 2022 EN mailchimp insider social-engineering scam
Ongoing phishing attacks on Trezor users https://blog.trezor.io/ongoing-phishing-attacks-on-trezor-users-edd840b17304#4909
04/04/2022 17:35:23
QRCode
archive.org

Trezor users have reported being targeted by a malicious phishing attack on April 3.

Trezor EN 2022 phishing attack MailChimp
Explaining Spring4Shell: The Internet security disaster that wasn’t https://arstechnica.com/information-technology/2022/04/explaining-spring4shell-the-internet-security-disaster-that-wasnt/
04/04/2022 11:49:44
QRCode
archive.org
thumbnail

Vulnerability in the Spring Java Framework is important, but it's no Log4Shell.

arstechnica 2022 EN Spring4Shell Java
Complete dissection of an APK with a suspicious C2 Server https://lab52.io/blog/complete-dissection-of-an-apk-with-a-suspicious-c2-server/
02/04/2022 12:06:04
QRCode
archive.org

During our analysis of the Penquin-related infrastructure we reported in our previous post, we paid special attention to the malicious binaries contacting these IP addresses, since as we showed in the analysis, they had been used as C2 of other threats used by Turla.

turla apk android analysis EN 2022 lab52 c2
Lapsus$: Two UK teenagers charged with hacking for gang https://www.bbc.com/news/technology-60953527
02/04/2022 11:51:11
QRCode
archive.org
thumbnail

The actions of the relatively new group have led to an international police hunt.

bbc Lapsus$ teenagers gang EN 2022 arrest police UK
Apple releases macOS 12.3.1, iOS 15.4.1, watchOS 8.5.1 and more - The Mac Security Blog https://www.intego.com/mac-security-blog/apple-releases-macos-12-3-1-ios-15-4-1-watchos-8-5-1-and-more/
01/04/2022 22:30:45
QRCode
archive.org
thumbnail

Apple has just released fixes for two actively exploited vulnerabilities affecting macOS Monterey, iOS 15, and iPadOS 15.

intego EN 2022 macOS CVE-2022-22675 CVE-2022-22674
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit https://thehackernews.com/2022/04/chinese-hackers-target-vmware-horizon.html?m=1&s=09
01/04/2022 12:44:09
QRCode
archive.org
thumbnail

A Chinese advanced persistent threat tracked as Deep Panda has been observed exploiting the Log4Shell vulnerability in VMware Horizon servers to deploy a backdoor and a novel rootkit on infected machines with the goal of stealing sensitive data.

Chine VMware Horizon Log4Shell Rootkit DeepPanda EN 2022
New Python-based Ransomware Targeting JupyterLab Web Notebooks https://thehackernews.com/2022/03/new-python-based-ransomware-targeting.html
31/03/2022 15:19:22
QRCode
archive.org

Researchers have disclosed what they say is the first-ever Python-based ransomware strain specifically designed to target exposed Jupyter notebooks, a web-based interactive computing platform that allows editing and running programs via a browser.

"The attackers gained initial access via misconfigured environments, then ran a ransomware script that encrypts every file on a given path on the server and deletes itself after execution to conceal the attack," Assaf Morag, a data analyst at Aqua Security, said in a report.

thehackernews EN 2022 Python Ransomware JupyterLab Notebooks
QNAP warns severe OpenSSL bug affects most of its NAS devices https://www.bleepingcomputer.com/news/security/qnap-warns-severe-openssl-bug-affects-most-of-its-nas-devices/
31/03/2022 15:05:09
QRCode
archive.org
thumbnail

Taiwan-based network-attached storage (NAS) maker QNAP warned on Tuesday that most of its NAS devices are impacted by a high severity OpenSSL bug disclosed two weeks ago.

Attackers can exploit the vulnerability, tracked as CVE-2022-0778, to trigger a denial of service state and remotely crash unpatched devices.

QNAP bleepingcomputer EN 2022 OpenSSL bug CVE-2022-0778 NAS
page 212 / 220
5003 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn