Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 243 / 253
En Russie, des informations sur la police secrète fuitent à cause d'une appli de livraison https://www.journaldugeek.com/2022/04/04/en-russie-des-informations-sur-la-police-secrete-fuitent-a-cause-dune-appli-de-livraison/
04/04/2022 11:33:31
QRCode
archive.org
thumbnail

Après une fuite de données massive, l'une des applications de livraison de repas les plus populaires de Russie a révélé d'importantes informations sur les membres de la police secrète du pays.

journaldugeek 2022 FR Russie Kremlin YandexFood Yandex leak fuite
Complete dissection of an APK with a suspicious C2 Server https://lab52.io/blog/complete-dissection-of-an-apk-with-a-suspicious-c2-server/
02/04/2022 12:06:04
QRCode
archive.org

During our analysis of the Penquin-related infrastructure we reported in our previous post, we paid special attention to the malicious binaries contacting these IP addresses, since as we showed in the analysis, they had been used as C2 of other threats used by Turla.

turla apk android analysis EN 2022 lab52 c2
Lapsus$: Two UK teenagers charged with hacking for gang https://www.bbc.com/news/technology-60953527
02/04/2022 11:51:11
QRCode
archive.org
thumbnail

The actions of the relatively new group have led to an international police hunt.

bbc Lapsus$ teenagers gang EN 2022 arrest police UK
Apple releases macOS 12.3.1, iOS 15.4.1, watchOS 8.5.1 and more - The Mac Security Blog https://www.intego.com/mac-security-blog/apple-releases-macos-12-3-1-ios-15-4-1-watchos-8-5-1-and-more/
01/04/2022 22:30:45
QRCode
archive.org
thumbnail

Apple has just released fixes for two actively exploited vulnerabilities affecting macOS Monterey, iOS 15, and iPadOS 15.

intego EN 2022 macOS CVE-2022-22675 CVE-2022-22674
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit https://thehackernews.com/2022/04/chinese-hackers-target-vmware-horizon.html?m=1&s=09
01/04/2022 12:44:09
QRCode
archive.org
thumbnail

A Chinese advanced persistent threat tracked as Deep Panda has been observed exploiting the Log4Shell vulnerability in VMware Horizon servers to deploy a backdoor and a novel rootkit on infected machines with the goal of stealing sensitive data.

Chine VMware Horizon Log4Shell Rootkit DeepPanda EN 2022
New Python-based Ransomware Targeting JupyterLab Web Notebooks https://thehackernews.com/2022/03/new-python-based-ransomware-targeting.html
31/03/2022 15:19:22
QRCode
archive.org

Researchers have disclosed what they say is the first-ever Python-based ransomware strain specifically designed to target exposed Jupyter notebooks, a web-based interactive computing platform that allows editing and running programs via a browser.

"The attackers gained initial access via misconfigured environments, then ran a ransomware script that encrypts every file on a given path on the server and deletes itself after execution to conceal the attack," Assaf Morag, a data analyst at Aqua Security, said in a report.

thehackernews EN 2022 Python Ransomware JupyterLab Notebooks
QNAP warns severe OpenSSL bug affects most of its NAS devices https://www.bleepingcomputer.com/news/security/qnap-warns-severe-openssl-bug-affects-most-of-its-nas-devices/
31/03/2022 15:05:09
QRCode
archive.org
thumbnail

Taiwan-based network-attached storage (NAS) maker QNAP warned on Tuesday that most of its NAS devices are impacted by a high severity OpenSSL bug disclosed two weeks ago.

Attackers can exploit the vulnerability, tracked as CVE-2022-0778, to trigger a denial of service state and remotely crash unpatched devices.

QNAP bleepingcomputer EN 2022 OpenSSL bug CVE-2022-0778 NAS
Putin's hackers gained full access to Hungary's foreign ministry networks, the Orbán government has been unable to stop them https://www.direkt36.hu/en/putyin-hekkerei-is-latjak-a-magyar-kulugy-titkait-az-orban-kormany-evek-ota-nem-birja-elharitani-oket/
31/03/2022 14:59:02
QRCode
archive.org
thumbnail

On December 30, 2021, in Moscow, Russian Foreign Minister Sergey Lavrov pinned the Order of Friendship on the suit of his Hungarian counterpart Péter Szijjártó. Although the medal was presented by Lavrov, it was Russian President Vladimir Putin himself who decided to award it. Not coincidentally, the medal, which is in the form of a wreath of olive branches encircling a globe, includes the inscription “Peace and Friendship” in Cyrillic on the back, is the highest Russian state decoration that can be awarded to a foreigner.

Direkt36 Hungary EN 2022 Russia cyberattack FSB ministry
Apple and Meta Gave User Data to Hackers Who Used Forged Legal Requests https://www.bloomberg.com/news/articles/2022-03-30/apple-meta-gave-user-data-to-hackers-who-forged-legal-requests
31/03/2022 14:49:05
QRCode
archive.org
thumbnail

Apple Inc. and Meta Platforms Inc., the parent company of Facebook, provided customer data to hackers who masqueraded as law enforcement officials, according to three people with knowledge of the matter.

Apple and Meta provided basic subscriber details, such as a customer’s address, phone number and IP address, in mid-2021 in response to the forged “emergency data requests.” Normally, such requests are only provided with a search warrant or subpoena signed by a judge, according to the people. However, the emergency requests don’t require a court order.

bloomberg EN 2022 RecursionTeam Lapsus$ Apple Meta privacy forged datarequest
Lapsus$ and SolarWinds hackers both use the same old trick to bypass MFA https://arstechnica.com/information-technology/2022/03/lapsus-and-solar-winds-hackers-both-use-the-same-old-trick-to-bypass-mfa/
29/03/2022 09:10:49
QRCode
archive.org
thumbnail

Not all MFA is created equal, as script kiddies and elite hackers have shown recently.

arstechnica 2022 EN MFA prompt-bombing
New Lapsus$ Hack Documents Make Okta’s Response Look More Bizarre https://www.wired.com/story/lapsus-okta-hack-sitel-leak/
29/03/2022 07:47:47
QRCode
archive.org
thumbnail

Documents shed some light on how Okta and its subprocessor Sitel reacted to a breach, but they don’t explain the apparent lack of urgency.

WIRED EN 2022 LAPSUS$ Okta leak notification
Sophos patches critical remote code execution vulnerability in Firewall https://www.zdnet.com/article/sophos-patches-critical-remote-code-execution-vulnerability-in-firewall-defense-product/
28/03/2022 15:35:01
QRCode
archive.org
thumbnail

Sophos Firewall is a network protection solution for the enterprise market.

Sophos EN 2022 Firewall critical RCE zdnet CVE-2022-1040
When Nokia Pulled Out of Russia, a Vast Surveillance System Remained https://www.nytimes.com/2022/03/28/technology/nokia-russia-surveillance-system-sorm.html
28/03/2022 14:27:10
QRCode
archive.org
thumbnail

The Finnish company played a key role in enabling Russia’s cyberspying, documents show, raising questions of corporate responsibility.

2022 EN Russia Nokia Surveillance Politics cyberspy nytimes MTS SORM
Google's WiFi snoop - who knew and who didn't? https://www.theregister.com/2010/05/18/google_street_view_wifi_analysis/
28/03/2022 14:24:56
QRCode
archive.org

The meaning of 'mistake'

theregister EN 2010 WiFi Google snoop privacy personal-data
Fake sites stealing Steam credentials https://www.zscaler.com/blogs/security-research/fake-sites-stealing-steam-credentials
28/03/2022 14:19:53
QRCode
archive.org
thumbnail

Recently, the Zscaler ThreatLabZ team came across multiple fake Counter-Strike: Global Offensive (CS:GO) skin websites aimed at stealing Steam credentilsa.

Zscaler 2020 EN stealing BitB Steam Fake credentials
Chrome Releases: Stable Channel Update for Desktop https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html?m=1
28/03/2022 12:46:45
QRCode
archive.org
thumbnail

High CVE-2022-1096: Type Confusion in V8. Reported by anonymous on 2022-03-23
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Google is aware that an exploit for CVE-2022-1096 exists in the wild.

CVE-2022-1096 chrome update EN 2022
Behold, a password phishing site that can trick even savvy users https://arstechnica.com/information-technology/2022/03/behold-a-password-phishing-site-that-can-trick-even-savvy-users/
27/03/2022 21:13:38
QRCode
archive.org
thumbnail

Just when you thought you'd seen every phishing trick out there, BitB comes along.

Behold password arstechnica EN 2022 phishing BitB
Lapsus$: Oxford teen accused of being multi-millionaire cyber-criminal https://www.bbc.com/news/technology-60864283
25/03/2022 09:22:19
QRCode
archive.org
thumbnail

Police say they've arrested seven teenagers as part of their investigation into a hacking group.

Lapsus$ EN 2022 bbc Oxford teenagers
Storm Cloud on the Horizon: GIMMICK Malware Strikes at macOS https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/
24/03/2022 09:04:44
QRCode
archive.org
thumbnail
GIMMICK macos EN 2022 StormCloud volexity China malware
A Closer Look at the LAPSUS$ Data Extortion Group https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/
24/03/2022 07:08:28
QRCode
archive.org

Microsoft and identity management platform Okta both this week disclosed breaches involving LAPSUS$, a relatively new cybercrime group that specializes in stealing data from big companies and threatening to publish it unless a ransom demand is paid. Here’s a closer look at LAPSUS$, and some of the low-tech but high-impact methods the group uses to gain access to targeted organizations.

krebsonsecurity EN 2022 Lapsus$ group Okta
page 243 / 253
5049 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn