Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 216 / 239
Russia Released a Ukrainian App for Hacking Russia That Was Actually Malware https://www.vice.com/en/article/bvmnxd/russia-released-a-ukrainian-app-for-hacking-russia-that-was-actually-malware
20/07/2022 22:19:28
QRCode
archive.org
thumbnail

Google researchers said the app was designed to figure out who may want to use this kind of app.

vice 2022 EN malware Russia Russia-Ukraine-war app spy cyberwarefare
China: Declaration by the Minister for Foreign Affairs on behalf of the Belgian Government urging Chinese authorities to take action against malicious cyber activities undertaken by Chinese actors https://diplomatie.belgium.be/en/news/declaration-minister-foreign-affairs-malicious-cyber-activities?fbclid=IwAR2KVRIkiaeO-ZGXpKh-rPUdy9cfAQA765RlwuiCmFdpXrwwm4lN_Vji88E&fs=e&s=cl
20/07/2022 08:31:21
QRCode
archive.org
thumbnail

Declaration by the Minister for Foreign Affairs on behalf of the Belgian Government urging Chinese authorities to take action against malicious cyber activities undertaken by Chinese actors.

Belgium EN 2022 Minister Foreign Affairs China APT APT27 APT30 APT31 attribution official statement
I see what you did there: A look at the CloudMensis macOS spyware https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
19/07/2022 22:37:56
QRCode
archive.org
thumbnail

ESET uncovers CloudMensis, a macOS backdoor that spies on users of Mac devices and communicates with its operators via public cloud storage services.

WeLiveSecurity EN 2022 macOS spyware CloudMensis ESET
Pegasus used to spy on protesters, a popular actress, and dozens more in Thailand, report shows https://restofworld.org/2022/pegasus-thailand-report-citizen-lab/
19/07/2022 21:49:09
QRCode
archive.org
thumbnail

Forensic analysis by CitizenLab says government is the likeliest perpetrator.

Restofworld EN 2022 Pegasus spyware Thailand CitizenLab
Busting browser fails: What attackers see when they hack your employees’ browser https://blog.detectify.com/2022/07/18/what-attackers-see-when-they-hack-your-browser/
19/07/2022 19:09:56
QRCode
archive.org
thumbnail

Hackad hacker outlines why a browser is so vital in the cybercrime ecosystem and what CISOs can do to protect employees against browser hacks

detectify EN 2022 browser attacker hacks HackBrowserData recommendations
CVE-2020-3433 : élévation de privilèges sur le client VPN Cisco AnyConnect https://connect.ed-diamond.com/MISC/misc-112/cve-2020-3433-elevation-de-privileges-sur-le-client-vpn-cisco-anyconnect
19/07/2022 11:33:56
QRCode
archive.org

Cet article explique comment trois vulnérabilités supplémentaires ont été découvertes dans le client VPN Cisco AnyConnect pour Windows. Elles ont été trouvées suite au développement d’un exploit pour la CVE-2020-3153 (une élévation de privilèges, étudiée dans MISC n°111). Après un rappel du fonctionnement de ce logiciel, nous étudierons chacune de ces nouvelles vulnérabilités.

ed-diamond FR 2020 CVE-2020-3433 Cisco AnyConnect analysis
Joker, Facestealer and Coper banking malwares on Google Play store https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store
19/07/2022 08:43:01
QRCode
archive.org
thumbnail

Joker, Facestealers and Banker swarming Google Play store

zscaler EN 2022 Android Joker FaceStealer Coper Exobot Malware GooglePlay store apps analysis
How I Hacked my Car Guides: Creating Custom Firmware https://programmingwithstyle.com/tags/d-audio2/
19/07/2022 08:27:32
QRCode
archive.org
thumbnail

Making Software I am a programmer by nature. I now had root access to a cool new linux box so now I must develop software for it. The Goal While looking through many of the IVI’s files, I found tons of really cool C++ header files relating to ccOS in /usr/include. ccOS is the Connected Car Operating System, an OS developed by Nvidia and Hyundai which is supposed to power all Hyundai vehicles from 2022 onwards, but I guess some of the underlying system was in previous Hyundai vehicles for quite some time.

programmingwithstyle greenluigi1 EN 2022 Nvidia d-audio d-audio2 hyundai kia hacking car IVI guides
CVE-2022-30333 https://attackerkb.com/topics/RCa4EIZdbZ/cve-2022-30333/rapid7-analysis
19/07/2022 08:06:09
QRCode
archive.org
thumbnail

On May 6, 2022, Rarlab released version 6.17, which addresses CVE-2022-30333, a path traversal vulnerability reported to them by Sonar, who posted a write-up about it. Sonar specifically calls out Zimbra Collaboration Suite’s usage of unrar as vulnerable (specifically, the amavisd component, which is used to inspect incoming emails for spam and malware). Zimbra addressed this issue in 9.0.0 patch 25 and 8.5.15 patch 32 by replacing unrar with 7z.

attackerkb CVE-2022-30333 analysis zimbra Rapid7
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware/
18/07/2022 21:15:49
QRCode
archive.org
thumbnail

A group of actors originating from North Korea that MSTIC tracks as DEV-0530 has been developing and using ransomware in attacks since June 2021. This group, which calls itself H0lyGh0st, utilizes a ransomware payload with the same name.

microsoft EN 2022 H0lyGh0st north-korea ransomware
Un malware, un cochon et un APT chinois https://blog.ilearned.eu/xorddos.html
18/07/2022 09:06:42
QRCode
archive.org

Par un heureux hasard, un fichier nommé libudev.so, apparemment malveillant, est apparu dans notre dossier Téléchargements, nous avons donc voulu en savoir plus. Entre reverse engineering, analyse réseau et OSINT, c’est cette quête d’information qui nous mènera à découvrir un mystérieux pirate, vouant une adoration à ses cochons, que nous allons relater dans cet article

ilearned FR analyse formation maltego xorddos
Did You Know Your Browser’s Autofill Credentials Could Be Stolen via Cross-Site Scripting (XSS) https://www.gosecure.net/blog/2022/06/29/did-you-know-your-browsers-autofill-credentials-could-be-stolen-via-cross-site-scripting-xss/
18/07/2022 08:43:00
QRCode
archive.org
thumbnail

Cross-Site Scripting (XSS) is a well-known vulnerability that has been around for a long time and can be used to steal sessions, create fake logins and carry out actions as someone else, etc.

In addition, many users are unaware of the potential dangers associated with their browser’s credential autofill feature. This attack vector is not new, but it is unknown to many people and as we investigated further we found that the dangers were extensive. In this post, the GoSecure Titan Labs team will demonstrate that using a browser password manager with autofill could expose your credentials in a web application vulnerable to XSS.

gosecure EN 2022 browsers XSS password-autofill credentials
Google Play hides app permissions in favor of developer-written descriptions https://arstechnica.com/gadgets/2022/07/google-plays-new-privacy-section-actually-hides-app-permissions/
17/07/2022 22:11:23
QRCode
archive.org
thumbnail

Let's hope nobody lies about what permissions their app uses.

arstechnica EN 2022 google-play app permissions developer-written
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/
17/07/2022 21:33:46
QRCode
archive.org
thumbnail

A large-scale phishing campaign that attempted to target over 10,000 organizations since September 2021 used adversary-in-the-middle (AiTM) phishing sites to steal passwords, hijack a user’s sign-in session, and skip the authentication process, even if the user had enabled multifactor authentication (MFA).

microsoft EN 2022 phishing MFA AiTM hijack session
Ongoing phishing campaign can hack you even when you’re protected with MFA https://arstechnica.com/information-technology/2022/07/microsoft-details-phishing-campaign-that-can-hijack-mfa-protected-accounts/
17/07/2022 21:30:40
QRCode
archive.org
thumbnail

Campaign that steals email has targeted at least 10,000 organizations since September.

arstechnica EN 2022 phishing microsoft MFA campaign
European Central Bank head targeted in hacking attempt https://apnews.com/article/technology-angela-merkel-european-central-bank-4cd599a7502d9617a401155abf054502
17/07/2022 21:14:04
QRCode
archive.org
thumbnail

BERLIN (AP) — The European Central Bank said Tuesday that its president, Christine Lagarde, was targeted in a hacking attempt but no information was compromised. The attempt took place “recently,” the Frankfurt-based central bank for the 19 countries that use the euro said in an emailed response to a query about a report by Business Insider.

apnews EN 2022 whaling Christine-Lagarde Europe Angela-Merkel European-Central-Bank WhatsApp
ChromeLoader: New Stubborn Malware Campaign https://unit42.paloaltonetworks.com/chromeloader-malware/
17/07/2022 08:47:41
QRCode
archive.org

In January 2022, a new browser hijacker/adware campaign named ChromeLoader (also known as Choziosi Loader and ChromeBack) was discovered. Despite using simple malicious advertisements, the malware became widespread, potentially leaking data from thousands of users and organizations.

unit42 EN 2022 ChromeLoader malware browser hijacker adware extension
The Trojan Horse Malware & Password “Cracking” Ecosystem Targeting Industrial Operators https://www.dragos.com/blog/the-trojan-horse-malware-password-cracking-ecosystem-targeting-industrial-operators/
16/07/2022 21:08:50
QRCode
archive.org

Learn more about Dragos's discovery of an exploit introduced through password "cracking" software that targets industrial engineers and operators.

dragos EN 2022 ICS password-cracker trojan industrial
Vice Society: a discreet but steady double extortion ransomware group https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group/
15/07/2022 22:47:27
QRCode
archive.org
thumbnail

Vice Society is a little-known double extortion group that exfiltrates its victims' data and threatens its victims to leak their information.

sekoia EN 2022 vice-society extortion leak
Why organizations should (and should not) worry about… https://intel471.com/blog/killnet-xaknet-legion-ddos-attacks
15/07/2022 22:44:12
QRCode
archive.org
thumbnail

KillNet will continue to grow as the war in Ukraine continues, but the group is limited in its capabilities.

Intel471 killnet Russia TTPs
page 216 / 239
4762 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio