Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 57 / 76
1513 résultats taggé 2024  ✕
Romania-linked ‘Rubycarp’ hackers look for cryptomining, phishing DDoS opportunities https://therecord.media/romania-linked-rubycarp-cryptomining-phishing?_hsenc=p2ANqtz-9HLeh2NKX9YD8v6Rfw_YGWT9zf3p7rORXktQ5wNPQyt1AHa2bq5Pj7rmBv1zUT1d8_YLC4QKFG2VDEEKJoZQrzHzqjfA&_hsmi=302087305
11/04/2024 09:08:18
QRCode
archive.org
thumbnail

Rubycarp has been in operation for at least a decade, and its campaigns appear to overlap with other cybercrime groups, according to researchers at Sysdig.

therecord EN 2024 Rubycarp gang Romania DDoS cryptomining
France Bracing for Cyberattacks During Summer Olympics https://www.nytimes.com/2024/04/08/us/politics/france-cyberattacks-summer-olympics.html?mid=1#cid=1774108
10/04/2024 10:09:37
QRCode
archive.org

French officials are visiting Washington for cybersecurity consultations as President Emmanuel Macron predicts Moscow will try to target the Games.

nytimes EN 2024 Cyberwarfare France Russia Summer-Olympics
Round 2: Change Healthcare Targeted in Second Ransomware Attack https://www.darkreading.com/cyberattacks-data-breaches/round-2-change-healthcare-targeted-second-ransomware-attack
10/04/2024 10:05:51
QRCode
archive.org
thumbnail

RansomHub, which is speculated to have some connection to ALPHV, has stolen 4TB of sensitive data from the beleaguered healthcare company.

darkreading 2024 Change-Healthcare ALPHV Ransomware Attack
Vulnerabilities Identified in LG WebOS https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/?ref=news.risky.biz%2F
10/04/2024 09:05:53
QRCode
archive.org
thumbnail

As the creator of the world’s first smart home cybersecurity hub, Bitdefender regularly audits popular IoT hardware for vulnerabilities. This research paper is part of a broader program that aims to shed light on the security of the world’s best-sellers in the IoT space. This report covers vulnerabilities discovered while researching the LG WebOS TV operating system.

bitdefender EN 2024 LG WebOS TV iot vulnerability CVE-2023-6317 CVE-2023-6318 CVE-2023-6319 CVE-2023-6320
Security Advisory YSA-2024-01 https://www.yubico.com/support/security-advisories/ysa-2024-01/
10/04/2024 09:05:30
QRCode
archive.org
thumbnail

A security issue has been identified in YubiKey Manager GUI which could lead to unexpected privilege escalation on Windows. If a user runs the YubiKey Manager GUI as Administrator, browser windows opened by YubiKey Manager GUI may be opened as Administrator which could be exploited by a local attacker to perform actions as Administrator. Under this circumstance, some browsers like Edge for example, have additional mitigations to prevent opening as Administrator.

yubico EN 2024 Advisory YubiKey-Manager privilege-escalation YSA-2024-01
SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile https://csrc.nist.gov/pubs/sp/800/61/r3/ipd
10/04/2024 09:03:01
QRCode
archive.org

Incident response is a critical part of cybersecurity risk management and should be integrated across organizational operations. The six Functions of the NIST Cybersecurity Framework (CSF) 2.0 all play vital roles in incident response.

NIST is releasing the initial public draft of Special Publication (SP) 800-61r3 (Revision 3), Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, for public comment. This publication seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities, as described by CSF 2.0. Doing so can help organizations prepare for incident responses, reduce the number and impact of incidents that occur, and improve the efficiency and effectiveness of their incident detection, response, and recovery activities.

NIST 2024 EN Recommendations Incident-response risk-management SP-800-61
PSG : le système de billetterie du club attaqué https://www.leparisien.fr/sports/football/psg/psg-le-systeme-de-billetterie-du-club-attaque-08-04-2024-ZO4E7C55CRFZ5NET6HRRTYO3KE.php?ref=news.risky.biz
10/04/2024 09:01:19
QRCode
archive.org
thumbnail

Le club parisien a informé ses abonnés ce lundi qu’un « acte malveillant » avait visé le système de billetterie, ciblant des données d’identité.

leparisien FR 2024 PSG billetterie CNIL
Muddled Libra’s Evolution to the Cloud https://unit42.paloaltonetworks.com/muddled-libra-evolution-to-cloud/
09/04/2024 22:35:41
QRCode
archive.org
thumbnail

Unit 42 researchers have discovered that the Muddled Libra group now actively targets software-as-a-service (SaaS) applications and cloud service provider (CSP) environments. Organizations often store a variety of data in SaaS applications and use services from CSPs. The threat actors have begun attempting to leverage some of this data to assist with their attack progression, and to use for extortion when trying to monetize their work.

unit42 EN 2024 paloaltonetworks MuddledLibra research CSP software-as-a-service
April’s Patch Tuesday Brings Record Number of Fixes https://krebsonsecurity.com/2024/04/aprils-patch-tuesday-brings-record-number-of-fixes/
09/04/2024 22:33:33
QRCode
archive.org

If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.

krebsonsecurity EN 2024 April-patchtuesday patch-tuesday
Critical Security Flaw Found in Popular LayerSlider WordPress Plugin https://thehackernews.com/2024/04/critical-security-flaw-found-in-popular.html
07/04/2024 21:59:57
QRCode
archive.org

A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashes.

The flaw, designated as CVE-2024-2879, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of SQL injection impacting versions from 7.9.11 through 7.10.0.

The issue has been addressed in version 7.10.1 released on March 27, 2024, following responsible disclosure on March 25. "This update includes important security fixes," the maintainers of LayerSlider said in their release notes.

LayerSlider is a visual web content editor, a graphic design software, and a digital visual effects that allows users to create animations and rich content for their websites. According to its own site, the plugin is used by "millions of users worldwide."

thehackernews EN 2024 WordPress LayerSlider CVE-2024-2879
SurveyLama, plateforme de sondages en ligne française, a subi une attaque exposant les données de plus de 4 millions d'utilisateurs https://www.clubic.com/actualite-523272-surveylama-plateforme-de-sondages-en-ligne-francaise-a-subi-une-attaque-exposant-les-donnees-de-plus-de-4-millions-d-utilisateurs.html
07/04/2024 21:57:46
QRCode
archive.org
thumbnail

La violation des données a été signalée par Have I Been Pwned, une application qui avertit les utilisateurs que leurs données personnelles ont été piratées.

clubic FR 2024 SurveyLama Data-Breach
+92,000 Internet-facing D-Link NAS devices can be easily hacked https://securityaffairs.com/161549/hacking/d-link-nas-flaw.html
07/04/2024 21:47:16
QRCode
archive.org
thumbnail

A researcher disclosed an arbitrary command injection and hardcoded backdoor issue in multiple end-of-life D-Link NAS models.

securityaffairs EN 2024 D-Link NAS devices backdoor
Help us to take down the parasite website | Notepad++ https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/
07/04/2024 11:48:01
QRCode
archive.org

I’ve received numerous complaints via email, social media, and forums regarding a website that poses a significant threat to our community. The site in question is https://notepad.plus/ which appears prominently when users google for “download Notepad++”.

notepad-plus-plus EN 2024 impersonation parasite website Notepad++ announce help
DSoS attacks statistics and observations https://qrator.net/blog/details/2023-ddos-attacks-statistics-and-observations
07/04/2024 11:46:27
QRCode
archive.org

he year 2023 turned out to be quite rich in events and trends in the field of cybersecurity. We witnessed a new term "white noise", the development of artificial intelligence led to increased bot activity, which significantly affected commercial companies. We detected signs of a resurgence in popularity of commercial DDoS attacks. The implementation of "remote office" technologies led to the expansion of communication channels and, as a result, increased intensity of attacks. But first things first.

DDoS Attacks by Vectors
The fourth quarter of the past year didn't bring any surprises in terms of the distribution of mixed attacks by vectors. UDP flood once again topped the list with a rate of 60.20%. IP flood came in second at 16.86%. Multivector attacks also made it into the top three with 13.36%. Overall, the distribution was as follows:

UDP flood - 60.20%
SYN flood - 7.26%
IP flood - 16.86%
Multivector attacks - 13.36%

qrator EN 2024 DDoS Attacks Statistics 2023 Year-in-Review
Price of zero-day exploits rises as companies harden products against hackers https://techcrunch.com/2024/04/06/price-of-zero-day-exploits-rises-as-companies-harden-products-against-hackers/
06/04/2024 20:17:37
QRCode
archive.org
thumbnail

Tools that allow government hackers to break into iPhones and Android phones, popular software like the Chrome and Safari browsers, and chat apps like

techcrunch EN 2024 spyware zero-days zerodium price
Over 92,000 exposed D-Link NAS devices have a backdoor account https://www.bleepingcomputer.com/news/security/over-92-000-exposed-d-link-nas-devices-have-a-backdoor-account/
06/04/2024 20:13:31
QRCode
archive.org
thumbnail

A threat researcher has disclosed a new arbitrary command injection and hardcoded backdoor flaw in multiple end-of-life D-Link Network Attached Storage (NAS) device models.

bleepingcomputer En 2024 Backdoor Command-Injection D-Link EOL NAS Remote-Code-Execution Vulnerability
Bringing process injection into view(s): exploiting all macOS apps using nib files · Sector 7 https://sector7.computest.nl/post/2024-04-bringing-process-injection-into-view-exploiting-all-macos-apps-using-nib-files/
05/04/2024 15:45:54
QRCode
archive.org
thumbnail

In a previous blog post we described a process injection vulnerability affecting all AppKit-based macOS applications. This research was presented at Black Hat USA 2022, DEF CON 30 and Objective by the Sea v5. This vulnerability was actually the second universal process injection vulnerability we reported to Apple, but it was fixed earlier than the first. Because it shared some parts of the exploit chain with the first one, there were a few steps we had to skip in the earlier post and the presentations. Now that the first vulnerability has been fixed in macOS 13.0 (Ventura) and improved in macOS 14.0 (Sonoma), we can detail the first one and thereby fill in the blanks of the previous post.

This vulnerability was independently found by Adam Chester and written up here under the name “DirtyNIB”. While the exploit chain demonstrated by Adam shares a lot of similarity to ours, our attacks trigger automatically and do not require a user to click a button, making them a lot more stealthy. Therefore we decided to publish our own version of this write-up as well.

sector7 EN 2024 macos nib exploit research vulnerability DirtyNIB
Researchers Observed Visual Studio Code Extensions Steals https://gbhackers.com/researchers-observed-visual-studio/
05/04/2024 09:14:17
QRCode
archive.org
thumbnail

ReversingLabs has uncovered a series of VS Code extensions that designed to siphon off sensitive information from unsuspecting users.

gbhackers EN 2024 VSCode extensions stealers
Qakbot Strikes Back: Understanding the Threat https://www.binarydefense.com/resources/blog/qakbot-strikes-back-understanding-the-threat/
05/04/2024 09:11:03
QRCode
archive.org
thumbnail

Binary Defense threat researchers analyzed the reemergence of the QakBot botnet. The new QakBot DLL has undergone some minor changes.

binarydefense EN 2024 Qakbot analysis botnet
Distinctive Campaign Evolution of Pikabot Malware https://www.mcafee.com/blogs/other-blogs/mcafee-labs/distinctive-campaign-evolution-of-pikabot-malware/
05/04/2024 09:10:00
QRCode
archive.org
thumbnail

Authored by Anuradha and Preksha Introduction PikaBot is a malicious backdoor that has been active since early 2023. Its modular design is comprised of a

mcafee EN 2024 analysis Pikabot Malware
page 57 / 76
4617 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio