Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 26 / 76
1513 résultats taggé 2024  ✕
RPKI ROV Deployment Reaches Major Milestone https://www.kentik.com/blog/rpki-rov-deployment-reaches-major-milestone/
04/09/2024 07:31:20
QRCode
archive.org
thumbnail

In this blog post, BGP experts Doug Madory of Kentik and Job Snijders of Fastly review the latest RPKI ROV deployment metrics in light of a major milestone.

kentik EN 2024 BGP RPKI ROV
Dutch regulator slaps Clearview AI with $33 million fine, threatens executive liability - The Verge https://www.theverge.com/2024/9/3/24234879/dutch-regulator-gdpr-clearview-ai-fine
03/09/2024 19:23:08
QRCode
archive.org
thumbnail

The Dutch Data Protection Authority imposed the largest fine yet against facial recognition company Clearview AI under the GDPR.

theverge EN 2024 Netherlands Data Protection Authority GDPR fine facial-recognition legal fine EU ClearviewAI
Transport for London faces 'ongoing cyber security incident' https://www.bbc.com/news/articles/cd9dpek1883o
03/09/2024 19:10:54
QRCode
archive.org
thumbnail

Transport for London's (TfL) computer systems have been targeted in an ongoing cyber attack.
It said there was no evidence customer data had been compromised and there was currently no impact on TfL services.
Insiders have told BBC London they have been asked to work at home if possible, and that it is the transport provider's backroom systems at the corporate headquarters that are mainly affected.

bbc EN 2024 Transport London TfL cyberattack
Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail https://www.sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail/
03/09/2024 19:02:56
QRCode
archive.org
thumbnail
  • Sonar’s Vulnerability Research Team recently discovered a critical Cross-Site Scripting (XSS) vulnerability in Roundcube, a popular open-source webmail software.
  • When a victim views a malicious email in Roundcube sent by an attacker, the attacker can execute arbitrary JavaScript in the victim's browser.
  • Attackers can abuse the vulnerability to steal emails, contacts, and the victim's email password as well as send emails from the victim's account.
  • In October 2023, ESET Research reported that a similar vulnerability was actively used by the APT group Winter Vivern to attack European government entities.
  • Roundcube administrators should update to the patched version 1.6.8 or 1.5.8 as soon as possible.
  • All discovered issues are tracked as CVE-2024-42008, CVE-2024-42009, CVE-2024-42010.
sonarsource EN 2024 Roundcube Webmail CVE-2024-42008 CVE-2024-42009 CVE-2024-42010
North Korean threat actor Citrine Sleet exploiting Chromium zero-day https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/
03/09/2024 18:14:10
QRCode
archive.org
thumbnail

Microsoft observed North Korean threat actor Citrine Sleet exploiting the CVE-2024-7971 zero-day vulnerability in Chromium. Citrine Sleet targets the cryptocurrency sector for financial gain.

microsoft EN 2024 CVE-2024-7971 zero-day Chromium North-Korea cryptocurrency
Breaking down CVE-2024–38063: remote exploitation of the Windows kernel https://bi-zone.medium.com/breaking-down-cve-2024-38063-remote-exploitation-of-the-windows-kernel-bdae36f5f61d
03/09/2024 14:57:01
QRCode
archive.org

We have examined the Windows TCP/IP network stack flaw that could grant adversaries remote access with maximum privileges. Exploiting CVE-2024–38063 does not imply any action on the part of the user…

bi-zone.medium.com EN 2024 CVE-2024–38063 IPv6 PoC analysis
Owners of 1-Time Passcode Theft Service Plead Guilty https://krebsonsecurity.com/2024/09/owners-of-1-time-passcode-theft-service-plead-guilty/
03/09/2024 08:31:47
QRCode
archive.org

Three men in the United Kingdom have pleaded guilty to operating otp[.]agency, a once popular online service that helped attackers intercept the one-time passcodes (OTPs) that many websites require as a second authentication factor in addition to passwords. Launched in…

krebsonsecurity EN 2024 UK OTP Multi-Factor-Authentication One-time-Password OTP OTP.Agency MFA
Admins of MFA bypass service plead guilty to fraud https://www.bleepingcomputer.com/news/legal/admins-of-mfa-bypass-service-plead-guilty-to-fraud/
03/09/2024 08:28:47
QRCode
archive.org
thumbnail

Three men have pleaded guilty to running OTP.Agency, an online platform that provided social engineering help to obtain one-time passcodes from customers of various banks and services in the U.K.

bleepingcomputer EN 2024 Cybercrime Legal Multi-Factor-Authentication One-time-Password OTP OTP.Agency MFA
Cryptojacking via CVE-2023-22527: Dissecting a Full-Scale Cryptomining Ecosystem https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html
02/09/2024 18:37:02
QRCode
archive.org
thumbnail

We provide a technical analysis on how CVE-2023-22527 can be exploited by malicious actors for cryptojacking attacks that can spread across the victim’s system.

trendmicro EN 2024 Cryptojacking via CVE-2023-22527 Atlassian Confluence analysis
The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers “Voldemort” https://www.proofpoint.com/us/blog/threat-insight/malware-must-not-be-named-suspected-espionage-campaign-delivers-voldemort
02/09/2024 18:34:01
QRCode
archive.org
thumbnail

Key findings  Proofpoint researchers identified an unusual campaign delivering malware that the threat actor named “Voldemort”.   Proofpoint assesses with moderate confidence the goal of the activi...

proofpoint EN 2024 Voldemort campaign impots tax Malware Espionage
Identity of Notorious Hacker USDoD Revealed https://www.securityweek.com/true-identity-of-notorious-hacker-usdod-revealed/
02/09/2024 18:32:08
QRCode
archive.org

The notorious hacker USDoD, who is best known for high-profile data leaks, appears to be a man from Brazil, according to investigations conducted by CrowdStrike and others.

Over the past few years, USDoD, aka EquationCorp, has leaked vast amounts of information stolen from major organizations. His targets include the FBI’s InfraGard portal, Airbus, credit reporting firm TransUnion, background checking service National Public Data (NPD), and many others.

securityweek EN 2024 USDoD Identity EquationCorp
Behind the arrest of Telegram boss, a small Paris cybercrime unit with big ambitions https://www.reuters.com/world/europe/behind-arrest-telegram-boss-small-paris-cybercrime-unit-with-big-ambitions-2024-08-30/
02/09/2024 18:03:51
QRCode
archive.org
  • Durov's arrest marks a shift in dealing with tech chiefs
  • Brousse's unit goes after its biggest ever target
  • Legal experts question the prosecution's argument

The investigation into Telegram boss Pavel Durov that has fired a warning shot to global tech titans was started by a small cybercrime unit within the Paris prosecutor's office, led by 38-year-old Johanna Brousse.
The arrest of Durov, 39, last Saturday marks a significant shift in how some global authorities may seek to deal with tech chiefs reluctant to police illegal content on their platforms.
The arrest signalled the mettle of the J3 cybercrime unit, but the true test of its ambitions will be whether Brousse can secure a conviction based on a largely untested legal argument, lawyers said.

reuters EN 2024 Durov Telegram cybercrime J3
Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant https://unit42.paloaltonetworks.com/global-protect-vpn-spoof-distributes-wikiloader/
02/09/2024 16:28:57
QRCode
archive.org
thumbnail

Unit 42 discusses WikiLoader malware spoofing GlobalProtect VPN, detailing evasion techniques, malicious URLs, and mitigation strategies. Unit 42 discusses WikiLoader malware spoofing GlobalProtect VPN, detailing evasion techniques, malicious URLs, and mitigation strategies.

unit42 EN 2024 WikiLoader malware spoofing GlobalProtect VPN
Fake Google Authenticator Website Installs Malware https://any.run/cybersecurity-blog/fake-google-authenticator-campaign/
02/09/2024 11:46:48
QRCode
archive.org
thumbnail

See how adversaries are impersonating Google Authenticator in Google Ads to deliver the DeerStealer information-stealing malware. 

any.run EN 2024 Google Authenticator GoogleAds fake malvertising
Cicada 3301 - Ransomware-as-a-Service - Technical Analysis https://www.truesec.com/hub/blog/dissecting-the-cicada
02/09/2024 11:35:55
QRCode
archive.org
thumbnail

Discover the latest insights on the emerging ransomware group Cicada3301, first detected in June 2024. Truesec's investigation reveals key findings about this group, named after a famous cryptography game, now targeting multiple victims.

truesec EN 2024 Cicada3301 ransomware emerging cryptography Analysis
Docker-OSX image used for security research hit by Apple DMCA takedown https://www.bleepingcomputer.com/news/security/docker-osx-image-used-for-security-research-hit-by-apple-dmca-takedown/
02/09/2024 11:33:30
QRCode
archive.org
thumbnail

The popular Docker-OSX project has been removed from Docker Hub after Apple filed a DMCA (Digital Millennium Copyright Act) takedown request, alleging that it violated its copyright.

bleepingcomputer EN 2024 Apple DMCA Docker-Hub Legal macOS
Cybercriminals operating ransomware as a service from overseas continue to be responsible for most high-profile cybercrime attacks against the UK https://www.nationalcrimeagency.gov.uk/threats/nsa-cyber-2024
30/08/2024 11:23:23
QRCode
archive.org

The deployment of ransomware remains the greatest serious and organised cybercrime threat, the largest cybersecurity threat, and also poses a risk to the UK’s national security. Ransomware attacks can have a significant impact on victims due to financial, data, and service losses, which can lead to business closure, inaccessible public services, and compromised customer data. Threat actors are typically based in overseas jurisdictions where limited cooperation makes it challenging for UK law enforcement to disrupt their activities.

nationalcrimeagency.gov.uk EN 2024 ransomware report assassment cybercrime UK
Germany's Sovereign Tech Fund Puts Over $750K Into FreeBSD Infrastructure Projects https://fossforce.com/2024/08/germanys-sovereign-tech-fund-puts-over-750k-into-freebsd-infrastructure-projects/
30/08/2024 09:00:26
QRCode
archive.org
thumbnail

The FreeBSD Foundation will organize and manage the projects that STF is funding, which mainly focuses on security.

fossforce EN 2024 Germany FreeBSD security Sovereign
Fake Palo Alto GlobalProtect used as lure to backdoor enterprises https://www.bleepingcomputer.com/news/security/fake-palo-alto-globalprotect-used-as-lure-to-backdoor-enterprises/
30/08/2024 08:27:26
QRCode
archive.org
thumbnail

Threat actors target Middle Eastern organizations with malware disguised as the legitimate Palo Alto GlobalProtect Tool that can steal data and execute remote PowerShell commands to infiltrate internal networks further.

bleepingcomputer EN 2024 fake Malware Middle-East Palo-Alto-Networks
Dutch cabinet bans phones in meetings over espionage fears https://www.politico.eu/article/smartphones-banned-from-dutch-government-meetings-over-espionage-risk/
30/08/2024 08:21:10
QRCode
archive.org
thumbnail

Devices are kept in vault during weekly gatherings, prime minister said.

politico EN 2024 policy Intelligence Risk-and-compliance Netherlands espionage Smartphones cabinet
page 26 / 76
4532 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio