Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 244 / 253
Lapsus$: when kiddies play in the big league https://www.sekoia.io/en/lapsus-when-kiddies-play-in-the-big-league/
23/03/2022 18:05:52
QRCode
archive.org
thumbnail

You may not have missed all the noises recently caused by Lapsus$, a group that seems to specialize in extortion without necessarily leveraging ransomware.

At first glance, Lapsus$ check marks all elements that would make researchers put them in the low priority threats, especially considering their readiness to make dramas and OpSec failures. Except that the group has successfully managed to significantly enrich its victim list with high profile corporations, thus drawing all our attention.

In the following, we will describe the threat actor profile that was drawn by our investigations based either on OSINT, dark web or infrastructure analysis.

sekoia EN 2022 analysis Lapsus$ group
Cloudflare’s investigation of the January 2022 Okta compromise https://blog.cloudflare.com/cloudflare-investigation-of-the-january-2022-okta-compromise/
23/03/2022 15:18:52
QRCode
archive.org

Today, March 22, 2022 at 03:30 UTC we learnt of a compromise of Okta. We use Okta internally for employee identity as part of our authentication stack. We have investigated this compromise carefully and do not believe we have been compromised as a result. We do not use Okta for customer accounts; customers do not need to take any action unless they themselves use Okta.

cloudflare Okta EN 2022 compromise investigation
Piratage Okta : 375 des clients concernés par l'attaque de Lapsus$ https://www.zdnet.fr/actualites/piratage-okta-375-des-clients-concernes-par-l-attaque-de-lapsus-39939331.htm
23/03/2022 10:55:42
QRCode
archive.org
thumbnail

La société affirme qu'un "petit pourcentage" de clients, 2,5 %, aurait pu voir ses données consultées ou faire l'objet d'une action de la part des pirates spécialisés dans le ransomware.

Piratage Okta Lapsus$ FR 2022 zdnetfr
Updated Okta Statement on LAPSUS$ https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
23/03/2022 10:54:33
QRCode
archive.org
thumbnail

This update was posted at 6:31 PM, Pacific Time.
As we shared earlier today, we are conducting a thorough investigation into the recent LAPSUS$ claims and any impact on our valued customers. The Okta service is fully operational, and there are no corrective actions our customers need to take.

Okta Statement LAPSUS$ EN 2022 investigation
DEV-0537 criminal actor targeting organizations for data exfiltration and destruction https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
23/03/2022 10:22:59
QRCode
archive.org
thumbnail

The activity we have observed has been attributed to a threat group that Microsoft tracks as DEV-0537, also known as LAPSUS$. DEV-0537 is known for using a pure extortion and destruction model without deploying ransomware payloads.

microsoft EN 2022 LAPSUS$ DEV-0537 extortion research activity threat group
Anonymous Takes Anti-Putin Battle To Russian People With Printer Attack To Disrupt Kremlin's Propaganda https://www.ibtimes.com/anonymous-takes-anti-putin-battle-russian-people-printer-attack-disrupt-kremlins-3444590
22/03/2022 12:00:21
QRCode
archive.org
thumbnail

The latest is a printer hack, which allows the collective to send a message across the transcontinental country.

anonymous russia-ukraine-war hacking oprussia ibtimes printer cyberwar EN 2022
Lapsus$ hackers leak 37GB of Microsoft's alleged source code https://www.bleepingcomputer.com/news/microsoft/lapsus-hackers-leak-37gb-of-microsofts-alleged-source-code/
22/03/2022 11:10:44
QRCode
archive.org
thumbnail

The Lapsus$ hacking group claims to have leaked the source code for Bing, Cortana, and other projects stolen from Microsoft's internal Azure DevOps server.

Bing Cortana Extortion Lapsus$ Microsoft Source-Code EN 2022 leak
Piratage d'Okta : l'entreprise admet enquêter, LAPSUS$ revendique https://www.zdnet.fr/actualites/piratage-d-okta-l-entreprise-admet-enqueter-lapsus-revendique-39939261.htm
22/03/2022 09:37:39
QRCode
archive.org
thumbnail

Le groupe cybercriminel LAPSUS$ a publié des captures d'écran montrant ce qu'il prétend être des éléments de l'environnement informatique interne de l'entreprise.

LAPSUS$ FR 2022 zdnetfr Okta piratage
Protestware : l’open source n’échappe pas au conflit russo-ukrainien https://www.zdnet.fr/actualites/protestware-l-open-source-n-echappe-pas-au-conflit-russo-ukrainien-39939233.htm
21/03/2022 21:32:14
QRCode
archive.org
thumbnail

A travers plusieurs mises à jour de projets open source, des développeurs ont manifesté leur opposition à l’invasion russe de l’Ukraine. Si dans certains cas, l’impact se limite à des messages de sensibilisation, certains projets vont jusqu’à inclure des logiciels malveillants.

Protestware FR 2022 zdnetfr Ukraine sabotage opensource sensibilisation
Activists are targeting Russians with open-source "protestware" https://www.technologyreview.com/2022/03/21/1047489/activists-are-targeting-russians-with-open-source-protestware/
21/03/2022 21:29:30
QRCode
archive.org
thumbnail

The volunteers who run open-source software projects are changing the code so that they display anti-war messages—or even wipe entire files.

technologyreview EN 2022 volunteers protestware sabotage Ukraine cyberwar
Ukraine warns of InvisiMole attacks tied to state-sponsored Russian hackers https://www.zdnet.com/article/ukraine-warns-of-invisimole-attacks-tied-to-state-sponsored-russian-hackers/
21/03/2022 21:02:35
QRCode
archive.org
thumbnail

InvisiMole has been collaborating with the Gamaredon APT for years.

InvisiMole APT EN 2022 Russia state-sponsored ukraine zdnet phishing cyberwar
Exposing initial access broker with ties to Conti https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/
20/03/2022 10:48:30
QRCode
archive.org
thumbnail

Threat Analysis Group (TAG) observed a financially motivated threat actor we refer to as EXOTIC LILY, exploiting a 0day in Microsoft MSHTML (CVE-2021-40444). Investigating this group's activity, we determined they are an Initial Access Broker (IAB) who appear to be working with the Russian cyber crime gang known as FIN12 (Mandiant, FireEye) / WIZARD SPIDER (CrowdStrike).

GoogleTAG EXOTICLILY CVE-2021-40444 0day reseller Conti IAB
Gas Is Too Expensive; Let’s Make It Cheap! https://securelist.com/expensive-gas/83542/
20/03/2022 00:08:33
QRCode
archive.org
thumbnail

A search online lead me to a discovery I didn’t think was possible nowadays. I realized almost immediately that critical security issues were probably involved. I found that out of the many tens of thousands of gas stations the company claimed to have installed their product in, 1,000 are remotely hackable.

Internet-of-Things securelist gas-station EN 2022 shodan IoT research hacking
Sabotage: Code added to popular NPM package wiped files in Russia and Belarus | Ars Technica https://arstechnica.com/information-technology/2022/03/sabotage-code-added-to-popular-npm-package-wiped-files-in-russia-and-belarus/
20/03/2022 00:02:22
QRCode
archive.org
thumbnail

When code with millions of downloads nukes user files, bad things can happen.

Sabotage arstechnica EN 2022 NPM Russia cyberwar node-ipc package CVE-2022-23812
OpenSSL plombé par une importante faille de sécurité https://www.lemondeinformatique.fr/actualites/lire-openssl-plombe-par-une-importante-faille-de-securite-86156.html
19/03/2022 23:57:27
QRCode
archive.org
thumbnail

La bibliothèque de chiffrement web open source OpenSSL est affectée par une vulnérabilité pouvant servir à des attaques par déni de service. Les versions 1.0.2, 1.1.1 et 3.0 doivent être mises à jour dès que possible.

lemondeinformatique FR 2022 OpenSSL DoS CVE-2022-0778 vulnérabilité
Popular NPM Package Updated to Wipe Russia, Belarus Systems to Protest Ukraine Invasion https://thehackernews.com/2022/03/popular-npm-package-updated-to-wipe.html
19/03/2022 23:54:09
QRCode
archive.org

In what's an act of deliberate sabotage, the developer behind the popular "node-ipc" NPM package shipped a new tampered version to condemn Russia's invasion of Ukraine, raising concerns about security in the open-source and the software supply chain.

thehackernews EN 2022 node-ipc developer cyberwar NPM supplychain sabotage CVE-2022-23812
L’Ukraine reconnaît « une énorme perte de communication » après la cyberattaque contre le satellite KA-SAT https://www.lemonde.fr/pixels/article/2022/03/15/l-ukraine-reconnait-une-enorme-perte-de-communication-apres-la-cyberattaque-contre-le-satellite-ka-sat_6117632_4408996.html#xtor=AL-32280270-%5Btwitter%5D-%5Bios%5D
16/03/2022 11:40:00
QRCode
archive.org
thumbnail

Lors d’une conférence de presse, un responsable ukrainien a, pour la première fois, donné des détails sur les conséquences de cette cyberattaque.

lemonde cyberattaque satellite KASAT FR 2022 Ukraine cyberwar
PROPHET SPIDER Exploits Citrix ShareFile https://www.crowdstrike.com/blog/prophet-spider-exploits-citrix-sharefile/
16/03/2022 08:46:41
QRCode
archive.org
thumbnail

At the start of 2022, CrowdStrike Intelligence and CrowdStrike Services investigated an incident in which PROPHET SPIDER exploited CVE-2021-22941 — a remote code execution (RCE) vulnerability impacting Citrix ShareFile Storage Zones Controller — to compromise a Microsoft Internet Information Services (IIS) web server. The adversary exploited the vulnerability to deploy a webshell that enabled the downloading of additional tools. This incident highlights how PROPHET SPIDER continues to evolve their tradecraft while continuing to exploit known web-server vulnerabilities.

CrowdStrike PROPHETSPIDER EN 2022 CVE-2021-22941RCE webshell ShareFile vulnerability Citrix
The Discovery and Exploitation of CVE-2022-25636 https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/
14/03/2022 16:04:52
QRCode
archive.org

A few weeks ago, I found and reported CVE-2022-25636 - a heap out of bounds write in the Linux kernel. The bug is exploitable to achieve kernel code execution (via ROP), giving full local privilege escalation, container escape, whatever you want.

cve-2022-25636 nickgregory bug Linux Kernel escape
Cyber-attaques en Suisse sur des particuliers? «On ne peut rien exclure» https://www.watson.ch/fr/!564691503
14/03/2022 00:48:58
QRCode
archive.org
thumbnail

Interview | La Suisse doit s'attendre à des cyberattaques après les sanctions contre la Russie. Seot questions à Solange Ghernaouti, experte en cybersécurité.

guerre Russie Cybercrime Suisse Interview CH 2022 FR watson Ghernaouti
page 244 / 253
5049 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn