Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 249 / 253
Une faille vulnérabilise le gestionnaire de paquets Snap pour Linux https://www.lemondeinformatique.fr/actualites/lire-une-faille-vulnerabilise-le-gestionnaire-de-paquets-snap-pour-linux-85889.html
22/02/2022 10:47:41
QRCode
archive.org
thumbnail

Découverte dans le gestionnaire de paquets Snap pour systèmes Linux développé par Canonical, une faille expose les utilisateurs à de l'escalade de privilèges. Un risque qui peut déboucher jusqu'à de l'accès root.

lemondeinformatique FR 2022 snap linux CVE-2021-44731 CVE-2021-44730
Oh Snap! More Lemmings (Local Privilege Escalation in snap-confine) https://www.qualys.com/2022/02/17/cve-2021-44731/oh-snap-more-lemmings.txt
22/02/2022 10:45:56
QRCode
archive.org

We recently audited snap-confine (a SUID-root program that is installed
by default on Ubuntu) and discovered two vulnerabilities (two Local
Privilege Escalations, from any user to root): CVE-2021-44730 and
CVE-2021-44731.

qualys EN 2022 CVE-2021-44730 CVE-2021-44731 snap ubuntu audit
Cosa sappiamo di sLoad e perchè è così elusivo? – https://cert-agid.gov.it/news/cosa-sappiamo-di-sload-e-perche-e-cosi-elusivo/
21/02/2022 15:26:09
QRCode
archive.org
thumbnail

Cosa sappiamo di sLoad e perchè è così elusivo?

CERTAGID IT 2022 sLoad PEC Italy
Boosting your Organisation's Cyber Resilience - Joint Publication https://www.enisa.europa.eu/publications/boosting-your-organisations-cyber-resilience
21/02/2022 10:46:00
QRCode
archive.org

ENISA and CERT-EU strongly encourage all public and private sector organisations in the EU to adopt a minimum set of cybersecurity best practices
PDF Document

enisa EU EN 2022 bestpractices CERTEU Publication pdf
Pegasus spyware scandal uncovered by fake image file on an iPhone https://appleinsider.com/articles/22/02/19/pegasus-spyware-scandal-uncovered-by-fake-image-file-on-an-iphone
20/02/2022 20:10:22
QRCode
archive.org
thumbnail

The scandal over NSO Group's Pegasus spyware was uncovered by a single fake image file mistakenly left on an activist's iPhone, a report states, a discovery that prompted international outcry over privacy.

appleinsider Pegasus Spyware NSO EN 2022 iphone
Who Is Behind QAnon? Linguistic Detectives Find Fingerprints https://www.nytimes.com/2022/02/19/technology/qanon-messages-authors.html
20/02/2022 10:39:46
QRCode
archive.org
thumbnail

Using machine learning, separate teams of computer scientists identified the same two men as likely authors of messages that fueled the viral movement.

nytimes 2022 EN qanon linguistic forensic machinelearning
Cyberattack targets Vodafone Portugal, disrupts services https://apnews.com/article/technology-business-europe-hacking-telecommunications-24b6daae9237b1d394f781b7e6497b04
19/02/2022 18:50:03
QRCode
archive.org
thumbnail

Vodafone Portugal, one of the country’s leading telecommunications companies, said Tuesday it had been hacked though no confidential customer data was compromised

apnews EN 2022 Vodafone Portugal attack cyberattack mobile
‘Zero-Click’ Hacks Are Growing in Popularity. There’s Practically No Way to Stop Them https://www.bloombergquint.com/technology/-zero-click-hacks-by-nso-group-and-others-growing-in-popularity
19/02/2022 14:01:39
QRCode
archive.org
thumbnail

As a journalist working for the Arab news network Alaraby, Rania Dridi said she’s taken precautions to avoid being targeted by hackers, keeping an eye out for suspicious messages and avoiding clicking on links or opening attachments from people she doesn’t know.

Bloomberg EN 2022 zeroclick spyware NSO governement spy privacy attack
Une cyberattaque met à genou l’Université de Neuchâtel https://www.letemps.ch/node/1307331
19/02/2022 11:37:34
QRCode
archive.org
thumbnail

L’institution a été victime jeudi soir de ce qui semble être un rançongiciel. Ses services informatiques travaillent d’arrache-pied pour restaurer ses systèmes avant la rentrée de lundi

letemps FR 2022 CH paywall NE EDU Ransomware cyberattaque rançongiciel
Kazakhstan's Internet Shutdowns Could Be a Warning for Ukraine https://www.nytimes.com/2022/02/18/technology/kazakhstan-internet-russia-ukraine.html
19/02/2022 01:32:21
QRCode
archive.org
thumbnail

Control of the internet is increasingly part of any modern conflict.

nytimes Politics Censorship Cyberwarfare Kazakhstan Ukraine Russia EN 2022 Internet
VMware Horizon servers are under active exploit by Iranian state hackers https://arstechnica.com/information-technology/2022/02/iranian-state-hackers-are-using-log4shell-to-infect-unpatched-vmware-servers/?s=09
18/02/2022 18:24:25
QRCode
archive.org
thumbnail

Hackers aligned with the government of Iran are exploiting the critical Log4j vulnerability to infect unpatched VMware users with ransomware, researchers said on Thursday.

arstechnica log4shell EN 2022 TunnelVision Iranian VMware Horizon CVE-2021-44228
The Elite Hackers of the FSB https://interaktiv.br.de/elite-hacker-fsb/en/index.html
18/02/2022 13:16:26
QRCode
archive.org
thumbnail

For almost two decades, hackers with Snake have been forcing their way into government networks. They are considered one of the most dangerous hacker groups in the world. Who they work for, though, has always been a matter of pure speculation. But reporters with the German public broadcasters BR and WDR  have discovered some clues, and they all lead to the Russian secret service FSB.

FSB turla hackers osint recherche EN 2022 BR german attribution
Passware parvient à trouver le mot de passe des Mac T2 par force brute https://www.macg.co/mac/2022/02/passware-parvient-trouver-le-mot-de-passe-des-mac-t2-par-force-brute-127283
17/02/2022 20:00:54
QRCode
archive.org
thumbnail

La société Passware, qui s'est fait une spécialité des solutions de déverrouillage des Mac et des PC par force brute, est parvenue à « craquer » la puce T2. Mais attention, le processus nécessite de 10 heures à… plusieurs milliers d'années, en fonction du mot de passe et de sa longueur. Mais cela reste possible grâce à une vulnérabilité exploitée par l'entreprise, dont les clients sont principalement les forces de l'ordre mais aussi des entreprises.

macg FR 2022 passware T2 cracking apple police forcebrute
Twitter cans 2FA service provider over surveillance claims https://blog.malwarebytes.com/privacy-2/2022/02/twitter-cans-2fa-service-provider-over-surveillance-claims/
17/02/2022 15:17:27
QRCode
archive.org
thumbnail

Twitter is changing its 2FA service provider after allegations emerged that it sold access to its networks to surveillance companies.

malwarebytes 2FA Mitto Twitter surveillance EN 2022
Red Cross traces hack back to unpatched Zoho vulnerability https://www.zdnet.com/article/red-cross-traces-hack-back-to-zoho-vulnerability/
17/02/2022 08:48:33
QRCode
archive.org
thumbnail

The Red Cross said the attack began on November 9 and involved an authentication bypass vulnerability in Zoho ManageEngine ADSelfService Plus.

ZDNet ManageEngine ICRC CVE-2021-40539 EN 2022
Cyberattaque : la Croix-Rouge confirme l’exploitation d’une vulnérabilité non corrigée https://www.lemagit.fr/actualites/252513510/Cyberattaque-la-Croix-Rouge-confirme-lexploitation-dune-vulnerabilite-non-corrigee
17/02/2022 08:46:33
QRCode
archive.org

Le comité international de la Croix-Rouge vient de confirmer que la cyberattaque dont il a été victime courant janvier a commencé par l’exploitation d’une vulnérabilité critique affectant un serveur Zoho ManageEngine, pour laquelle le correctif n’avait pas été appliqué.

lemagit ICRC FR 2022 CroixRouge cyberattaque ManageEngine CVE-2021-40539
Assurances cyber : vers une « jurisprudence NotPetya » ? https://www.silicon.fr/assurances-cyber-jurisprudence-notpetya-430633.html
17/02/2022 08:31:45
QRCode
archive.org
thumbnail

Aux États-Unis, un groupe pharmaceutique victime de NotPetya l'a emporté en première instance face à plusieurs de ses (ré)assureurs. Retour sur l'affaire.

merck notpetya juridique régulations siliconfr FR legal 2022 assurances cyberguerre
New ‘cyber war’ exclusion language raises concerns https://www.marsh.com/uk/services/cyber-risk/insights/new-cyber-war-exclusion-language-raises-concerns.html
17/02/2022 08:14:53
QRCode
archive.org

Marsh analysis, insights, and ideas, regarding new cyber insurance policy exclusion language related to war, cyber war, cyber operations, and catastrophic risk.

marsh EN 2022 cyberwar actofwar insurance exclusion language definition legal
Merck’s $1.4 Billion Insurance Win Splits Cyber From ‘Act of War’ https://news.bloomberglaw.com/privacy-and-data-security/mercks-1-4-billion-insurance-win-splits-cyber-from-act-of-war
17/02/2022 08:09:45
QRCode
archive.org
thumbnail

Merck & Co.‘s victory in a legal dispute with insurers over coverage for $1.4 billion in losses from malware known as NotPetya is expected to force insurance policies to more clearly confront responsibility for the fallout from nation-state cyberattacks.

bloomberglaw legal EN 2022 NotPetya actofwar insurance responsibility attribution
Chrome Zero-Day Under Active Attack: Patch ASAP | Threatpost https://threatpost.com/google-chrome-zero-day-under-attack/178428/
16/02/2022 20:38:31
QRCode
archive.org
thumbnail

The year's 1st Chrome zero-day can lead to all sorts of misery, ranging from data corruption to the execution of arbitrary code on vulnerable systems.

malware threatpost EN 2022 Chrome 0-day CVE-2022-0609
page 249 / 253
5049 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn