Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 35 / 41
817 résultats taggé 2022  ✕
Apple and Meta Gave User Data to Hackers Who Used Forged Legal Requests https://www.bloomberg.com/news/articles/2022-03-30/apple-meta-gave-user-data-to-hackers-who-forged-legal-requests
31/03/2022 14:49:05
QRCode
archive.org
thumbnail

Apple Inc. and Meta Platforms Inc., the parent company of Facebook, provided customer data to hackers who masqueraded as law enforcement officials, according to three people with knowledge of the matter.

Apple and Meta provided basic subscriber details, such as a customer’s address, phone number and IP address, in mid-2021 in response to the forged “emergency data requests.” Normally, such requests are only provided with a search warrant or subpoena signed by a judge, according to the people. However, the emergency requests don’t require a court order.

bloomberg EN 2022 RecursionTeam Lapsus$ Apple Meta privacy forged datarequest
Lapsus$ and SolarWinds hackers both use the same old trick to bypass MFA https://arstechnica.com/information-technology/2022/03/lapsus-and-solar-winds-hackers-both-use-the-same-old-trick-to-bypass-mfa/
29/03/2022 09:10:49
QRCode
archive.org
thumbnail

Not all MFA is created equal, as script kiddies and elite hackers have shown recently.

arstechnica 2022 EN MFA prompt-bombing
New Lapsus$ Hack Documents Make Okta’s Response Look More Bizarre https://www.wired.com/story/lapsus-okta-hack-sitel-leak/
29/03/2022 07:47:47
QRCode
archive.org
thumbnail

Documents shed some light on how Okta and its subprocessor Sitel reacted to a breach, but they don’t explain the apparent lack of urgency.

WIRED EN 2022 LAPSUS$ Okta leak notification
Sophos patches critical remote code execution vulnerability in Firewall https://www.zdnet.com/article/sophos-patches-critical-remote-code-execution-vulnerability-in-firewall-defense-product/
28/03/2022 15:35:01
QRCode
archive.org
thumbnail

Sophos Firewall is a network protection solution for the enterprise market.

Sophos EN 2022 Firewall critical RCE zdnet CVE-2022-1040
When Nokia Pulled Out of Russia, a Vast Surveillance System Remained https://www.nytimes.com/2022/03/28/technology/nokia-russia-surveillance-system-sorm.html
28/03/2022 14:27:10
QRCode
archive.org
thumbnail

The Finnish company played a key role in enabling Russia’s cyberspying, documents show, raising questions of corporate responsibility.

2022 EN Russia Nokia Surveillance Politics cyberspy nytimes MTS SORM
Chrome Releases: Stable Channel Update for Desktop https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html?m=1
28/03/2022 12:46:45
QRCode
archive.org
thumbnail

High CVE-2022-1096: Type Confusion in V8. Reported by anonymous on 2022-03-23
We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.
Google is aware that an exploit for CVE-2022-1096 exists in the wild.

CVE-2022-1096 chrome update EN 2022
Behold, a password phishing site that can trick even savvy users https://arstechnica.com/information-technology/2022/03/behold-a-password-phishing-site-that-can-trick-even-savvy-users/
27/03/2022 21:13:38
QRCode
archive.org
thumbnail

Just when you thought you'd seen every phishing trick out there, BitB comes along.

Behold password arstechnica EN 2022 phishing BitB
Lapsus$: Oxford teen accused of being multi-millionaire cyber-criminal https://www.bbc.com/news/technology-60864283
25/03/2022 09:22:19
QRCode
archive.org
thumbnail

Police say they've arrested seven teenagers as part of their investigation into a hacking group.

Lapsus$ EN 2022 bbc Oxford teenagers
Storm Cloud on the Horizon: GIMMICK Malware Strikes at macOS https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/
24/03/2022 09:04:44
QRCode
archive.org
thumbnail
GIMMICK macos EN 2022 StormCloud volexity China malware
A Closer Look at the LAPSUS$ Data Extortion Group https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/
24/03/2022 07:08:28
QRCode
archive.org

Microsoft and identity management platform Okta both this week disclosed breaches involving LAPSUS$, a relatively new cybercrime group that specializes in stealing data from big companies and threatening to publish it unless a ransom demand is paid. Here’s a closer look at LAPSUS$, and some of the low-tech but high-impact methods the group uses to gain access to targeted organizations.

krebsonsecurity EN 2022 Lapsus$ group Okta
Lapsus$: when kiddies play in the big league https://www.sekoia.io/en/lapsus-when-kiddies-play-in-the-big-league/
23/03/2022 18:05:52
QRCode
archive.org
thumbnail

You may not have missed all the noises recently caused by Lapsus$, a group that seems to specialize in extortion without necessarily leveraging ransomware.

At first glance, Lapsus$ check marks all elements that would make researchers put them in the low priority threats, especially considering their readiness to make dramas and OpSec failures. Except that the group has successfully managed to significantly enrich its victim list with high profile corporations, thus drawing all our attention.

In the following, we will describe the threat actor profile that was drawn by our investigations based either on OSINT, dark web or infrastructure analysis.

sekoia EN 2022 analysis Lapsus$ group
Cloudflare’s investigation of the January 2022 Okta compromise https://blog.cloudflare.com/cloudflare-investigation-of-the-january-2022-okta-compromise/
23/03/2022 15:18:52
QRCode
archive.org

Today, March 22, 2022 at 03:30 UTC we learnt of a compromise of Okta. We use Okta internally for employee identity as part of our authentication stack. We have investigated this compromise carefully and do not believe we have been compromised as a result. We do not use Okta for customer accounts; customers do not need to take any action unless they themselves use Okta.

cloudflare Okta EN 2022 compromise investigation
Piratage Okta : 375 des clients concernés par l'attaque de Lapsus$ https://www.zdnet.fr/actualites/piratage-okta-375-des-clients-concernes-par-l-attaque-de-lapsus-39939331.htm
23/03/2022 10:55:42
QRCode
archive.org
thumbnail

La société affirme qu'un "petit pourcentage" de clients, 2,5 %, aurait pu voir ses données consultées ou faire l'objet d'une action de la part des pirates spécialisés dans le ransomware.

Piratage Okta Lapsus$ FR 2022 zdnetfr
Updated Okta Statement on LAPSUS$ https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
23/03/2022 10:54:33
QRCode
archive.org
thumbnail

This update was posted at 6:31 PM, Pacific Time.
As we shared earlier today, we are conducting a thorough investigation into the recent LAPSUS$ claims and any impact on our valued customers. The Okta service is fully operational, and there are no corrective actions our customers need to take.

Okta Statement LAPSUS$ EN 2022 investigation
DEV-0537 criminal actor targeting organizations for data exfiltration and destruction https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
23/03/2022 10:22:59
QRCode
archive.org
thumbnail

The activity we have observed has been attributed to a threat group that Microsoft tracks as DEV-0537, also known as LAPSUS$. DEV-0537 is known for using a pure extortion and destruction model without deploying ransomware payloads.

microsoft EN 2022 LAPSUS$ DEV-0537 extortion research activity threat group
Anonymous Takes Anti-Putin Battle To Russian People With Printer Attack To Disrupt Kremlin's Propaganda https://www.ibtimes.com/anonymous-takes-anti-putin-battle-russian-people-printer-attack-disrupt-kremlins-3444590
22/03/2022 12:00:21
QRCode
archive.org
thumbnail

The latest is a printer hack, which allows the collective to send a message across the transcontinental country.

anonymous russia-ukraine-war hacking oprussia ibtimes printer cyberwar EN 2022
Lapsus$ hackers leak 37GB of Microsoft's alleged source code https://www.bleepingcomputer.com/news/microsoft/lapsus-hackers-leak-37gb-of-microsofts-alleged-source-code/
22/03/2022 11:10:44
QRCode
archive.org
thumbnail

The Lapsus$ hacking group claims to have leaked the source code for Bing, Cortana, and other projects stolen from Microsoft's internal Azure DevOps server.

Bing Cortana Extortion Lapsus$ Microsoft Source-Code EN 2022 leak
Piratage d'Okta : l'entreprise admet enquêter, LAPSUS$ revendique https://www.zdnet.fr/actualites/piratage-d-okta-l-entreprise-admet-enqueter-lapsus-revendique-39939261.htm
22/03/2022 09:37:39
QRCode
archive.org
thumbnail

Le groupe cybercriminel LAPSUS$ a publié des captures d'écran montrant ce qu'il prétend être des éléments de l'environnement informatique interne de l'entreprise.

LAPSUS$ FR 2022 zdnetfr Okta piratage
Protestware : l’open source n’échappe pas au conflit russo-ukrainien https://www.zdnet.fr/actualites/protestware-l-open-source-n-echappe-pas-au-conflit-russo-ukrainien-39939233.htm
21/03/2022 21:32:14
QRCode
archive.org
thumbnail

A travers plusieurs mises à jour de projets open source, des développeurs ont manifesté leur opposition à l’invasion russe de l’Ukraine. Si dans certains cas, l’impact se limite à des messages de sensibilisation, certains projets vont jusqu’à inclure des logiciels malveillants.

Protestware FR 2022 zdnetfr Ukraine sabotage opensource sensibilisation
Activists are targeting Russians with open-source "protestware" https://www.technologyreview.com/2022/03/21/1047489/activists-are-targeting-russians-with-open-source-protestware/
21/03/2022 21:29:30
QRCode
archive.org
thumbnail

The volunteers who run open-source software projects are changing the code so that they display anti-war messages—or even wipe entire files.

technologyreview EN 2022 volunteers protestware sabotage Ukraine cyberwar
page 35 / 41
4836 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn