Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 46 / 76
1513 résultats taggé 2024  ✕
Vulnerability in Cisco Webex cloud service exposed government authorities, companies https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/
05/06/2024 22:46:17
QRCode
archive.org
thumbnail

A previously discovered vulnerability affecting self-hosted Cisco Webex instances similarly affected the Webex cloud service.

helpnetsecurity EN 2024 Vulnerability Cisco Webex cloud service exposed government
Cyberattack on telecom giant Frontier claimed by RansomHub https://therecord.media/frontier-communications-cyberattack-ransomhub
05/06/2024 09:39:06
QRCode
archive.org
thumbnail

The Dallas-based company had said in a regulatory filing in April that a cybercrime group was responsible for a data breach. The gang added Frontier to its leak site on June 1.

therecord.media EN 2024 US Frontier RansomHub Cyberattack telecom
CVE-2024-27822: macOS PackageKit Privilege Escalation https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html
05/06/2024 08:41:53
QRCode
archive.org

Another fun exploit! This time with local privilege escalation through Apple’s PackageKit.framework when running ZSH-based PKGs 🎉.

khronokernel CVE-2024-27822 EN 2024 ZSH macos package pkg
Ransomware attack hits major London hospitals https://www.theregister.com/2024/06/04/suspected_cyberattack_hits_major_london/
04/06/2024 21:43:31
QRCode
archive.org
thumbnail

Pathology lab provider targeted, affecting blood transfusions and surgeries

theregister EN 2024 Pathology lab provider Ransomware health London UK Synlab
Analysts join the call for Microsoft to recall Recall https://www.theregister.com/2024/06/04/microsoft_analysts_recall/
04/06/2024 16:29:18
QRCode
archive.org
thumbnail

If Microsoft intended the 2024 Build event to be overshadowed by controversy then it succeeded as calls intensify for the company to rethink its strategy around Recall.

The Windows Recall feature, still in preview, takes a snapshot of a Copilot+ PC user's screen every couple of seconds and then sends it to disk, letting the user scroll the archive of snapshots when looking for something or use an AI system to recall screenshots by text.

theregister EN 2024 Microsoft Recall
Un prestataire externe de la Ville d'Yverdon-les-Bains victime d'une cyberattaque https://www.rts.ch/info/regions/vaud/2024/article/un-prestataire-externe-de-la-ville-d-yverdon-les-bains-victime-d-une-cyberattaque-28526457.html
04/06/2024 13:12:07
QRCode
archive.org
thumbnail

Un prestataire externe du Service des énergies de la ville d'Yverdon-les-Bains (VD) a été victime fin mai d'une cyberattaque. Près de 12'300 particuliers et entreprises pourraient être concernés. Mais à ce stade, rien n'indique que des données aient été consultées ou copiées.

rts EN 2024 prestataire Suisse Yverdon data-leak cyberattaque
PikaBot: a Guide to its Deep Secrets and Operations - Sekoia.io Blog https://blog.sekoia.io/pikabot-a-guide-to-its-deep-secrets-and-operations/
04/06/2024 11:15:28
QRCode
archive.org
thumbnail

Uncover an in-depth analysis of PikaBot, a malware loader used by Initial Access Brokers for network compromise and ransomware deployment.

sekoia EN 2024 PikaBot malware analysis TA577 BlackBasta
TikTok fails 'disinformation test' before EU vote, study shows https://www.euractiv.com/section/elections/news/tiktok-fails-disinformation-test-before-eu-vote-study-shows/
04/06/2024 09:49:47
QRCode
archive.org
thumbnail

Wildly popular social network TikTok approved adverts containing political disinformation ahead of European polls, a report showed Tuesday (4 June), flouting its own guidelines and raising questions about its ability to detect election falsehoods.

euractiv EN 2024 TikTok disinformation EU vote
Live Nation confirms Ticketmaster breach after hackers hawk stolen info of 560 million https://therecord.media/live-nation-confirms-ticketmaster-breach-snowflake
04/06/2024 09:34:36
QRCode
archive.org
thumbnail

The company has confirmed that the leaked data was from a database hosted on Snowflake — one of the largest cloud storage companies.

therecord.media EN 2024 Ticketmaster Data-Breach Snowflake
Crooks threaten to leak 2.9B records of personal info https://www.theregister.com/2024/06/03/usdod_data_dump/
04/06/2024 07:19:11
QRCode
archive.org
thumbnail

Billions of records detailing people's personal information may soon be dumped online after being allegedly obtained from a Florida firm that handles background checks and other requests for folks' private info.

A criminal gang that goes by the handle USDoD put the database up for sale for $3.5 million on an underworld forum in April, and rather incredibly claimed the trove included 2.9 billion records on all US, Canadian, and British citizens. It's believed one or more miscreants using the handle SXUL was responsible for the alleged exfiltration, who passed it onto USDoD, which is acting as a broker.

theregister EN 2024 USDoD database US Florida leak
Hacking Millions of Modems (and Investigating Who Hacked My Modem) https://samcurry.net/hacking-millions-of-modems
03/06/2024 21:53:52
QRCode
archive.org
thumbnail

Two years ago, something very strange happened to me while working from my home network. I was exploiting a blind XXE vulnerability that required an external HTTP server to smuggle out files, so I spun up an AWS box and ran a simple Python webserver to receive the traffic from the vulnerable server:

samcurry EN 2024 modem cox investigation
Telegram Combolists and 361M Email Addresses https://www.troyhunt.com/telegram-combolists-and-361m-email-addresses/
03/06/2024 21:48:52
QRCode
archive.org
thumbnail

Last week, a security researcher sent me 122GB of data scraped out of thousands of Telegram channels. It contained 1.7k files with 2B lines and 361M unique email addresses of which 151M had never been seen in HIBP before. Alongside those addresses were passwords and, in many cases, the website the data pertains to. I've loaded it into Have I Been Pwned (HIBP) today because there's a huge amount of previously unseen email addresses and based on all the checks I've done, it's legitimate data. That's the high-level overview, now here are the details:

troyhunt EN 2024 Telegram Combolists 361M Email Addresses 122GB HIBP infostealer
Google Leak Reveals Thousands of Privacy Incidents https://www.404media.co/google-leak-reveals-thousands-of-privacy-incidents/?ref=daily-stories-newsletter
03/06/2024 21:33:14
QRCode
archive.org
thumbnail

An internal Google database obtained by 404 Media shows Google recording childrens' voices, saving license plates from Street View, and many other self-reported incidents, large and small.

404media EN 2024 Google Leak Privacy database
Detecting and Preventing Unauthorized User Access: Instructions https://community.snowflake.com/s/article/Communication-ID-0108977-Additional-Information
03/06/2024 21:30:31
QRCode
archive.org

Snowflake recently observed and is investigating an increase in cyber threat activity targeting some of our customers’ accounts. We believe this is the result of ongoing industry-wide, identity-based attacks with the intent to obtain customer data. Research indicates that these types of attacks are performed with our customers’ user credentials that were exposed through unrelated cyber threat activity. To date, we do not believe this activity is caused by any vulnerability, misconfiguration, or malicious activity within the Snowflake product. Throughout the course of our ongoing investigation, we have promptly informed the limited number of customers who we believe may have been impacted.

This post will assist with investigating any potential threat activity within Snowflake customer accounts and provide guidance in the “Recommended Actions” section below.

Snowflake EN 2024 IoCs Instructions investigating
Molding lies into reality || Exploiting CVE-2024-4358 https://summoning.team/blog/progress-report-server-rce-cve-2024-4358-cve-2024-1800/
03/06/2024 13:05:23
QRCode
archive.org
thumbnail

Progress Report Server Unauthenticated Remote Code Execution Chain

summoning.team EN 2024 CVE-2024-4358 Telerik Report Server
Cyber house of cards – Politicians’ personal details exposed online https://proton.me/blog/politicians-exposed-dark-web
03/06/2024 09:47:24
QRCode
archive.org
thumbnail

We searched the dark web for politicians’ official email addresses, and roughly 40% of them appeared, along with other sensitive information. This is a scandal waiting to happen.

proton.me EN 2024 darkweb politicians PI exposed marketplace
Ticketmaster confirms massive breach after stolen data for sale online https://www.bleepingcomputer.com/news/security/ticketmaster-confirms-massive-breach-after-stolen-data-for-sale-online/#google_vignette
03/06/2024 08:41:00
QRCode
archive.org
thumbnail

Live Nation has confirmed that Ticketmaster suffered a data breach after its data was stolen from a third-party cloud database provider, which is believed to be Snowflake.

bleepingcomputer EN 2024 Cyberattack Data-Breach ShinyHunters Snowflake Ticketmaster
Shalev Hulio Made Pegasus Spyware, Now He’s King of Israeli AI https://theintercept.com/2024/05/23/israel-spyware-pegasus-shalev-hulio-ai-inteleye/
02/06/2024 12:18:19
QRCode
archive.org
thumbnail

Shalev Hulio is remaking his image but is still involved in a web of cybersecurity ventures with his old colleagues from NSO Group.

theintercept EN 2024 Shalev-Hulio Spyware Israel AI Pegasus NSO
NIST Getting Outside Help for National Vulnerability Database https://www.securityweek.com/nist-getting-outside-help-for-national-vulnerability-database/
01/06/2024 14:04:01
QRCode
archive.org

NIST announced on Wednesday that it will be receiving outside help to get the National Vulnerability Database (NVD) back on track within the next few months.

The organization informed the cybersecurity community in February that it should expect delays in the analysis of Common Vulnerabilities and Exposures (CVE) identifiers in the NVD, saying that it was working to establish a consortium to improve the program.

securityweek EN 2024 NIST CVE National Vulnerability Database NVD
How AI Will Change Democracy https://www.schneier.com/blog/archives/2024/05/how-ai-will-change-democracy.html
01/06/2024 13:53:35
QRCode
archive.org

I don’t think it’s an exaggeration to predict that artificial intelligence will affect every aspect of our society. Not by doing new things. But mostly by doing things that are already being done by humans, perfectly competently.

Replacing humans with AIs isn’t necessarily interesting. But when an AI takes over a human task, the task changes.

schneier EN 2024 AI risk Democracy Change analysis
page 46 / 76
4580 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio