Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 29 / 76
1513 résultats taggé 2024  ✕
Litespeed Cache bug exposes millions of WordPress sites to takeover attacks https://www.bleepingcomputer.com/news/security/litespeed-cache-bug-exposes-millions-of-wordpress-sites-to-takeover-attacks/
21/08/2024 19:24:37
QRCode
archive.org
thumbnail

A critical vulnerability in the LiteSpeed Cache WordPress plugin can let attackers take over millions of websites after creating rogue admin accounts.
#Admin #Cache #Computer #InfoSec #LiteSpeed #Plugin #Security #Takeover #Website #WordPress

bleepingcomputer EN 2024 Plugin Computer LiteSpeed InfoSec Takeover WordPress Cache Security Website Admin
Iran Reportedly Grapples With Major Cyberattack on Banking Systems https://www.darkreading.com/cyberattacks-data-breaches/iran-reportedly-grapples-with-major-cyberattack-on-banking-systems
21/08/2024 12:08:11
QRCode
archive.org
thumbnail

The last known cyberattack waged against Iranian infrastructure took place last December with blame placed on Israel and the US.

darkreading EN 2024 Iran cyberattack Banking Systems
Widespread Cloud Exposure: Extortion Campaign Used Exposed AWS ENV Files To Target 110,000 Domains https://cyble.com/blog/widespread-cloud-exposure/
21/08/2024 09:22:52
QRCode
archive.org
thumbnail

A cloud extortion campaign exploited misconfigured AWS .env files to target 110,000 domains, stealing credentials and ransoming cloud storage data.

cyble EN 2024 Cloud Exposure env AWS extortion
Microchip August 20, 2024 https://www.sec.gov/Archives/edgar/data/827054/000082705424000153/mchp-20240820.htm
21/08/2024 08:51:09
QRCode
archive.org
sec.gov EN 2024 SEC filing Microchip
Chipmaker Microchip reveals cyber attack https://www.theregister.com/2024/08/21/microchip_technology_security_incident/
21/08/2024 08:30:03
QRCode
archive.org
thumbnail

Defense contractor gets hacked – what's the worst that could happen

theregister EN 2024 SEC Microchip cyber-attack hacked defense-contractor
MITRE Marks Major Milestone, Minting 400 CNAs as NVD Backlog Grows - Socket https://socket.dev/blog/mitre-marks-major-milestone-minting-400-cnas-as-nvd-backlog-grows?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
21/08/2024 08:29:06
QRCode
archive.org
thumbnail

MITRE has just minted its 400th CNA, as the NVD struggles to tame its backlog of CVEs awaiting analysis, which has increased by 30% since June.

socket.dev EN 2024 MITRE Backlog CNA
Data Exfiltration from Slack AI via indirect prompt injection https://promptarmor.substack.com/p/data-exfiltration-from-slack-ai-via
20/08/2024 21:40:04
QRCode
archive.org

This vulnerability can allow attackers to steal anything a user puts in a private Slack channel by manipulating the language model used for content generation. This was responsibly disclosed to Slack (more details in Responsible Disclosure section at the end).

promptarmor EN 2024 Slack prompt-injection LLM vulnerability steal indirect-prompt injection
The Abuse of ITarian RMM by Dolphin Loader https://russianpanda.com/The-Abuse-of-ITarian-RMM-by-Dolphin-Loader
20/08/2024 19:28:49
QRCode
archive.org
thumbnail

Looking into the abuse of ITarian RMM and introducing Dolphin Loader

russianpanda EN 2024 DolphinLoader ITarian-RMM analysis
Toyota confirms breach after stolen data leaks on hacking forum https://www.bleepingcomputer.com/news/security/toyota-confirms-breach-after-stolen-data-leaks-on-hacking-forum/
20/08/2024 09:55:05
QRCode
archive.org
thumbnail

Toyota confirmed that its network was breached after a threat actor leaked an archive of 240GB of data stolen from the company's systems on a hacking forum.

bleepingcomputer EN 2024 Data-Breach Data-Leak Toyota
Routers from China-based TP-Link a national security threat, US lawmakers claim https://therecord.media/routers-from-tp-link-security-commerce-department
20/08/2024 09:16:28
QRCode
archive.org
thumbnail

The two members of Congress called on the Commerce Department to investigate risks related to TP-Link routers amid concerns over state-backed Chinese hacking operations.

therecord.media EN 2024 TP-Link US China national-threat threat state-backed
How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/
20/08/2024 09:14:14
QRCode
archive.org
thumbnail

An adversary could exploit these vulnerabilities by injecting malicious libraries into Microsoft's applications to gain their entitlements and user-granted permissions.

talosintelligence EN 2024 vulnerabilities Microsoft apps macos Outlook
Windows driver zero-day exploited by Lazarus hackers to install rootkit https://www.bleepingcomputer.com/news/microsoft/windows-driver-zero-day-exploited-by-lazarus-hackers-to-install-rootkit/
20/08/2024 07:11:59
QRCode
archive.org
thumbnail

The notorious North Korean Lazarus hacking group exploited a zero-day flaw in the Windows AFD.sys driver to elevate privileges and install the FUDModule rootkit on targeted systems.
#BYOVD #Bring #CVE-2024-38193 #Driver #Group #Lazarus #Microsoft #Own #Vulnerability #Your #Zero-Day

bleepingcomputer EN 2024 Your Lazarus Own BYOVD Driver Zero-Day Vulnerability Bring CVE-2024-38193 Group Microsoft
stardom dreams, stalking devices and the secret conglomerate selling both https://maia.crimew.gay/posts/gps-track-deez-nuts/
19/08/2024 08:41:02
QRCode
archive.org
thumbnail

people frequently reach out to me with companies to look into. usually it takes me about 10 minutes before i move on for one reason or another—it's not interesting for a story or has good security, for example. i didnt expect anything different when an acquaintance told me about Tracki, a self-proclaimed "world leader in GPS tracking" that they suspected could be used nefariously.

at first glance, Tracki appeared to be a serious company, maybe even one that cared about security. we could never have guessed what was about to unfold before us.

half a year into our investigation, we'd found it all: a hidden conglomerate posing as five independent companies, masked from governments and customers alike through the use of dozens of false identities, US letterbox companies, and an undeclared owner. a 90s phone sex scheme that, through targeting by one of hollywood's most notorious fixers, spiraled into a collection of almost a hundred domains advertising everything from online dating to sore throat remedies. a slew of device-assisted murder cases, on top of potential data breaches affecting almost 12 million users, ranging from federal government officials to literal infants. and most importantly, a little-known Snoop Dogg song. how in the world did we get here?

starting our descent

maia.crimew.gay EN 2024 Tracki shady business investigation stalkerware security analysis sqli leak exploit nyancrimew maia-arson-crimew switzerland hacktivism developer
Post-Quantum Cryptography Standards Officially Announced by NIST – a History and Explanation - SecurityWeek https://www.securityweek.com/post-quantum-cryptography-standards-officially-announced-by-nist-a-history-and-explanation/?is=09685296f9ea1fb2ee0963f2febaeb3a55d8fb1eddbb11ed4bd2da49d711f2c7
17/08/2024 11:09:06
QRCode
archive.org

NIST has formally published three post-quantum cryptography standards from the competition it held to develop cryptography able to withstand the anticipated quantum computing decryption of current asymmetric encryption.

securityweek EN 2024 NIST post-quantum cryptography
Disrupting a covert Iranian influence operation https://openai.com/index/disrupting-a-covert-iranian-influence-operation/
17/08/2024 02:49:59
QRCode
archive.org

We banned accounts linked to an Iranian influence operation using ChatGPT to generate content focused on multiple topics, including the U.S. presidential campaign. We have seen no indication that this content reached a meaningful audience.

openai EN 2024 chatgpt Iran influence-operation US disrupted report
Beyond the wail: deconstructing the BANSHEE infostealer https://www.elastic.co/security-labs/beyond-the-wail
16/08/2024 17:35:09
QRCode
archive.org
thumbnail

The BANSHEE malware is a macOS-based infostealer that targets system information, browser data, and cryptocurrency wallets.

elastic.co EN 2024 macOS BANSHEE infostealer
DDoS attack volume rises, peak power reaches 1.7 Tbps https://www.helpnetsecurity.com/2024/08/15/ddos-attacks-h1-2024-increase/
16/08/2024 12:00:09
QRCode
archive.org
thumbnail

The total number of DDoS attacks during H1 2024 amounted to 830,000, an increase of 46% when compared to H1 2023, according to Gcore.

helpnetsecurity EN 2024 DDoS attack Statistics report
Geopolitical Tensions Drive Explosion in DDoS Attacks https://www.infosecurity-magazine.com/news/geopolitical-tensions-drive-ddos/
16/08/2024 11:59:20
QRCode
archive.org
thumbnail

Radware found that Web DDoS attacks rose by 265% in H1 2024, driven by hacktivist groups amid rising geopolitical tensions

infosecurity-magazine EN 2024 DDoS attacks statistcs report
SolarWinds fixes critical RCE bug affecting all Web Help Desk versions https://www.bleepingcomputer.com/news/security/solarwinds-fixes-critical-rce-bug-affecting-all-web-help-desk-versions/
16/08/2024 11:01:30
QRCode
archive.org
thumbnail

A critical vulnerability in SolarWinds' Web Help Desk solution for customer support could be exploited to achieve remote code execution, the American business software developer warns in a security advisory today.

bleepingcomputer EN 2024 Hotfix Remote-Command-Execution SolarWinds Vulnerability Web-Help-Desk
Zabbix Server Vulnerability Lets Attacker Execute Arbitrary Code https://cybersecuritynews.com/zabbix-server-vulnerability/
16/08/2024 11:00:10
QRCode
archive.org
thumbnail

A critical security vulnerability, identified as CVE-2024-22116, has been patched in Zabbix, a popular monitoring solution.

cybersecuritynews EN 2024 CVE-2024-22116 Zabbix critical
page 29 / 76
4534 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio