Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 60 / 76
1513 résultats taggé 2024  ✕
Key Lesson from Microsoft's Password Spray Hack: Secure Every Account https://thehackernews.com/2024/03/key-lesson-from-microsofts-password.html
30/03/2024 17:26:24
QRCode
archive.org

In January 2024, Microsoft discovered they'd been the victim of a hack orchestrated by Russian-state hackers Midnight Blizzard (sometimes known as Nobelium). The concerning detail about this case is how easy it was to breach the software giant. It wasn't a highly technical hack that exploited a zero-day vulnerability – the hackers used a simple password spray attack to take control of an old, inactive account. This serves as a stark reminder of the importance of password security and why organizations need to protect every user account.

thehackernews EN 2024 Microsoft MidnightBlizzard lesson-learned password-spray
Details and Lessons Learned From the Ransomware Attack on the British Library https://www.securityweek.com/details-and-lessons-learned-from-the-ransomware-attack-on-the-british-library/
30/03/2024 17:24:12
QRCode
archive.org

The British Library has shared details on the destructive ransomware attack it experienced in October 2023. Although the attack on the national library of the UK occurred five months ago, the Library’s infrastructure won’t be rebuilt until mid-April 2024, and then the full restoration of systems and data can begin.

securityweek EN 2024 lesson-learned British-Library UK
XZ Utils backdoor https://tukaani.org/xz-backdoor/
30/03/2024 16:28:24
QRCode
archive.org

This page is short for now but it will get updated as I learn more about the incident. Most likely it will be during the first week of April 2024.

The Git repositories of XZ projects are on git.tukaani.org.

xz.tukaani.org DNS name (CNAME) has been removed. The XZ projects currently don’t have a home page. This will be fixed in a few days.

tukaani EN 2024 XZ backdoor linux CVE-2024-3094
Les attaques informatiques contre les ENT continuent dans le Nord ... https://www.zdnet.fr/actualites/les-attaques-informatiques-contre-les-ent-continuent-dans-le-nord-39965140.htm
30/03/2024 14:17:22
QRCode
archive.org
thumbnail

La semaine dernière, des menaces d'attentats ont été envoyés aux élèves, aux personnels et aux familles suite au piratage de l'environnement numérique de travail de la région Ile de France. Cette fois, c'est l'académie de Lille qui est touchée, et ce dans un contexte sécuritaire inquiétant.

zdnet.fr FR 2024 Phishing Cybercriminalité ETN écoles Éducation piratage terrorisme
PHP Obfuscator with Backdoor https://www.andreadraghetti.it/php-obfuscator-with-backdoor/
30/03/2024 14:01:19
QRCode
archive.org
thumbnail

An online tool offers a service to obfuscate PHP code, but it also silently inserts a backdoor into the code that allows any other PHP code to be executed!

andreadraghetti EN 2024 php obfuscation backdoor online
Easy privilege escalation exploit lands for Linux kernels https://www.theregister.com/2024/03/29/linux_kernel_flaw/
29/03/2024 22:49:16
QRCode
archive.org
thumbnail

CVE-2024-1086 turns the page tables on system admins

theregister EN 2024 CVE-2024-1086 Local-Privilege-Escalation Linux PoC Kernel
Urgent security alert for Fedora 41 and Fedora Rawhide users https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users
29/03/2024 19:26:40
QRCode
archive.org
thumbnail

Red Hat Information Risk and Security and Red Hat Product Security learned that the latest versions of the “xz” tools and libraries contain malicious code that appears to be intended to allow unauthorized access.

redhat EN 2024 xz backdoor linux CVE-2024-3094
Ransomware gang leaks stolen Scottish healthcare patient data in extortion bid https://therecord.media/healthcare-ransomware-data-breach-nhs-scotland
29/03/2024 14:55:55
QRCode
archive.org
thumbnail

A cybercrime group has published information stolen from NHS Dumfries and Galloway.

therecord.media EN 2024 Scotland NHS helath Ransomware published data-breach
AI bots hallucinate software packages and devs download them https://www.theregister.com/2024/03/28/ai_bots_hallucinate_software_packages/
29/03/2024 10:27:01
QRCode
archive.org
thumbnail

Not only that but someone, having spotted this reoccurring hallucination, had turned that made-up dependency into a real one, which was subsequently downloaded and installed thousands of times by developers as a result of the AI's bad advice, we've learned. If the package was laced with actual malware, rather than being a benign test, the results could have been disastrous.

theregister EN 2024 AI bots Hallucinations Supply-chain-attack
Cybercriminals Transform Raspberry Pi into a Tool for Fraud and Anonymization: GEOBOX Discovery https://www.resecurity.com/blog/article/cybercriminals-transform-raspberry-pi-into-a-tool-for-fraud-and-anonymization-geobox-discovery?ref=news.risky.biz
29/03/2024 10:26:20
QRCode
archive.org
resecurity EN 2024 Raspberry-Pi GEOBOX analysis tool Fraud Anonymization
Decade-old Linux ‘wall’ bug helps make fake SUDO prompts, steal passwords https://www.bleepingcomputer.com/news/security/decade-old-linux-wall-bug-helps-make-fake-sudo-prompts-steal-passwords/
28/03/2024 22:50:21
QRCode
archive.org
thumbnail

A vulnerability has been discovered in the 'util-linux' library that could allow unprivileged users to put arbitrary text on other users' terminals using the 'wall' command.

bleepingcomputer EN 2024 Clipboard-Hijacker Library Linux Passwords Terminal WallEscape
PyPI halted new users and projects while it fended off supply-chain attack https://arstechnica.com/security/2024/03/pypi-halted-new-users-and-projects-while-it-fended-off-supply-chain-attack/
28/03/2024 22:45:47
QRCode
archive.org
thumbnail

Automation is making attacks on open source code repositories harder to fight.

arstechnica EN 2024 PyPI Automation malicious packages attack
Jeffrey Epstein's Island Visitors Exposed by Data Broker https://www.wired.com/story/jeffrey-epstein-island-visitors-data-broker-leak/
28/03/2024 19:24:13
QRCode
archive.org
thumbnail

A WIRED investigation uncovered coordinates collected by a controversial data broker that reveal sensitive information about visitors to an island once owned by Epstein, the notorious sex offender.

wired EN 2024 privacy crime data-privacy data-broker
Diving Deeper into AI Package Hallucinations https://www.lasso.security/blog/ai-package-hallucinations
28/03/2024 19:07:30
QRCode
archive.org
thumbnail

Lass Security's recent research on AI Package Hallucinations extends the attack technique to GPT-3.5-Turbo, GPT-4, Gemini Pro (Bard), and Coral (Cohere).

lasso EN 2024 AI Package Hallucinations GPT-4 Bard Cohere analysis LLM
Lighter Ransomware Locks Users Out of System https://blog.sonicwall.com/en-us/2024/03/lighter-ransomware-locks-users-out-of-system/
28/03/2024 15:26:57
QRCode
archive.org
thumbnail

Overview This week, the Sonicwall Capture Labs threat research team analyzed a ransomware calling itself Lighter Ransomware. Upon execution, it opens up a window with a countdown timer instructing the victim to reach out immediately […]

SonicWall EN 2024 Ransomware Locks lighter-ransomware
US offers $10 million bounty for info on 'Blackcat' hackers who hit UnitedHealth https://www.reuters.com/technology/cybersecurity/us-offers-10-million-bounty-info-blackcat-hackers-who-hit-unitedhealth-2024-03-27/
28/03/2024 14:53:41
QRCode
archive.org

The U.S. State Department on Wednesday offered up to $10 million for information on the "Blackcat" ransomware gang who hit the UnitedHealth Group's tech unit and snarled insurance payments across America.
"The ALPHV Blackcat ransomware-as-a-service group compromised computer networks of critical infrastructure sectors in the United States and worldwide," the department said in a statement announcing the reward offer.

reuters EN 2024 US bounty ALPHV Blackcat
As Threats in Space Mount, U.S. Lags in Protecting Key Services https://www.nytimes.com/2024/03/28/world/asia/as-threats-in-space-mount-us-lags-in-protecting-key-services.html
28/03/2024 12:27:07
QRCode
archive.org

The United States and China are locked in a new race, in space and on Earth, over a fundamental resource: time itself.

And the United States is losing.

Global positioning satellites serve as clocks in the sky, and their signals have become fundamental to the global economy — as essential for telecommunications, 911 services and financial exchanges as they are for drivers and lost pedestrians.

nytimes EN 2024 threat satellites US China space
Seven Hackers Associated with Chinese Government Charged with Computer Intrusions Targeting Perceived Critics of China and U.S. Businesses and Politicians https://www.justice.gov/opa/pr/seven-hackers-associated-chinese-government-charged-computer-intrusions-targeting-perceived
28/03/2024 10:06:21
QRCode
archive.org

Defendants Operated as Part of the APT31 Hacking Group in Support of China’s Ministry of State Security’s Transnational Repression, Economic Espionage and Foreign Intelligence Objectives

justice.gov EN 2024 APT31 China US Charged Espionage
Out of the shadows - ’darcula’ iMessage and RCS smishing attacks target USPS and global postal services https://www.netcraft.com/blog/darcula-smishing-attacks-target-usps-and-global-postal-services/
28/03/2024 09:02:01
QRCode
archive.org
thumbnail

Chinese-language Phishing-as-a-Service platform ‘darcula’ targets organizations in 100+ countries with sophisticated techniques using more than 20,000 phish ...

netcraft EN 2024 Phishing-as-a-Service Darcula PhasS iMessage RCS USPS
Thousands of servers hacked in ongoing attack targeting Ray AI framework https://arstechnica.com/security/2024/03/thousands-of-servers-hacked-in-ongoing-attack-targeting-ray-ai-framework/?comments=1&comments-page=1
28/03/2024 00:21:11
QRCode
archive.org
thumbnail

Researchers say it's the first known in-the-wild attack targeting AI workloads.

arstechnica EN 2024 Ray AI framework attack ongoing servers
page 60 / 76
4662 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio