Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 63 / 76
1513 résultats taggé 2024  ✕
Top 5 Russian-Speaking Dark Web Forums https://socradar.io/top-5-russian-speaking-dark-web-forums/
20/03/2024 13:49:46
QRCode
archive.org
thumbnail

...Among these, russian-speaking dark web forums hold a unique position due to their extensive user base and the intricate of their operations.

socradar EN 2024 Russian-Speaking DarkWeb Forums
Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762 https://www.assetnote.io/resources/research/two-bytes-is-plenty-fortigate-rce-with-cve-2024-21762
20/03/2024 11:55:25
QRCode
archive.org
thumbnail

Early this February, Fortinet released an advisory for an "out-of-bounds write vulnerability" that could lead to remote code execution. The issue affected the SSL VPN component of their FortiGate network appliance and was potentially already being exploited in the wild. In this post we detail the steps we took to identify the patched vulnerability and produce a working exploit.

assetnote EN 2024 exploitation patch-diff FortiGate RCE CVE-2024-21762
Tech Giant Linked to France’s Cybersecurity Tumbles in Value https://www.nytimes.com/2024/03/20/business/atos-france-stocks.html?unlocked_article_code=1.eE0.DrOv.PCC4dBke9jQ3&smid=url-share
20/03/2024 11:36:02
QRCode
archive.org

The French government said it would seek “a national solution” to protect Atos, a debt-burdened company that serves nuclear programs and the military.

nytimes EN 2024 France Atos nuclear Critical-infrastructure government
Misconfigured Firebase instances leaked 19 million plaintext passwords https://www.bleepingcomputer.com/news/security/misconfigured-firebase-instances-leaked-19-million-plaintext-passwords/
20/03/2024 11:28:11
QRCode
archive.org
thumbnail

Three cybersecurity researchers discovered close to 19 million plaintext passwords exposed on the public internet by misconfigured instances of Firebase, a Google platform for hosting databases, cloud computing, and app development.

bleepingcomputer EN 2024 Data-Leak Database Firebase Misconfiguration Passwords Plaintext-Password User-Record
CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-company-onerep-com-founded-dozens-of-people-search-firms/
20/03/2024 11:25:51
QRCode
archive.org

The data privacy company Onerep.com bills itself as a Virginia-based service for helping people remove their personal information from almost 200 people-search websites. However, an investigation into the history of onerep.com finds this company is operating out of Belarus and…

krebsonsecurity EN 2024 CEO Onerep.com People-Search privacy
New Attack Techniques Bypassing ML Security https://slashnext.com/blog/new-attack-techniques-to-bypass-machine-learning-security-controls/
19/03/2024 19:14:38
QRCode
archive.org
thumbnail

Threat actors are exercising new attack techniques to bypass machine learning security controls.

slashnext EN 2024 conversation-overflow email-security phishing email-protection
Finland, Germany, Ireland, Japan, Poland, South Korea added to US-led spyware agreement https://therecord.media/international-spyware-agreement-new-members
19/03/2024 17:19:28
QRCode
archive.org
thumbnail

The signees, which already included about a dozen other nations, agree to establish “robust guardrails and procedures" around spyware, while preventing the export of technology that will be used for malicious cyber activity.

therecord.media EN 2024 Finland Germany Ireland Japan Poland South-Korea US-led spyware agreement
Interesting Multi-Stage StopCrypt Ransomware Variant Propagating in the Wild https://blog.sonicwall.com/en-us/2024/03/new-multi-stage-stopcrypt-ransomware/
19/03/2024 17:14:35
QRCode
archive.org
thumbnail

Overview The SonicWall Capture Labs threat research team recently observed an interesting variant of StopCrypt ransomware. The ransomware executes its malicious activities by utilizing multi-stage shellcodes before launching a final payload that contains the file […]

SonicWall EN 2024 StopCrypt ransomware analysis
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks | Trend Micro (US) https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html
19/03/2024 15:51:23
QRCode
archive.org
thumbnail

Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.

trendmicro EN 2024 targeted-attacks research report Earth-Krahang i-soon
Researchers spot updated version of malware that hit Viasat https://cyberscoop.com/viasat-malware-wiper-acidrain/
19/03/2024 15:49:21
QRCode
archive.org
thumbnail

Russian hackers have added new capabilities to the malware used to disable satellite modems at the outset of the invasion of Ukraine.

cyberscoop EN 2024 viasat Russia AcidRain Wiper Russia-Ukraine-war
IT helpdeskers increasingly targeted by cybercriminals https://www.theregister.com/2024/03/15/it_helpdeskers_under_increased_threat
18/03/2024 18:34:22
QRCode
archive.org
thumbnail

Wave of Okta attacks mark what researchers are calling the biggest security trend of the year

theregister EN 2024 helpdeskers target trend help-desk
Elon Musk's SpaceX builds spy satellite network for U.S. intelligence https://qz.com/spacex-starlink-spy-satellite-us-intelligence-elon-musk-1851342193
18/03/2024 14:36:54
QRCode
archive.org
thumbnail

SpaceX’s dominance in the satellite internet market has given Musk enormous power in matters of war and geopolitics

qz.com En 2024 Starlink internet Starshield SpaceX Satellite Musk spy US
What a Cluster: Local Volumes Vulnerability in Kubernetes https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges
18/03/2024 09:02:18
QRCode
archive.org
  • Akamai security researcher Tomer Peled recently discovered a high-severity vulnerability in Kubernetes that was assigned CVE-2023-5528 with a CVSS score of 7.2.

  • The vulnerability allows remote code execution with SYSTEM privileges on all Windows endpoints within a Kubernetes cluster. To exploit this vulnerability, the attacker needs to apply malicious YAML files on the cluster.

  • This vulnerability can lead to full takeover on all Windows nodes in a cluster.

  • This vulnerability can be exploited on default installations of Kubernetes (earlier than version 1.28.4), and was tested against both on-prem deployments and Azure Kubernetes Service.

  • In this blog post, we provide a proof-of-concept YAML file as well as an Open Policy Agent (OPA) rule for blocking this vulnerability.

akamai EN 2024 CVE-2023-5528 Kubernetes Windows vulnerability
'GhostRace' Speculative Execution Attack Impacts All CPU, OS Vendors https://www.darkreading.com/cyber-risk/ghostrace-speculative-execution-attack-cpu-os-vendors
18/03/2024 08:32:01
QRCode
archive.org
thumbnail

Like Spectre, the new exploit could give attackers a way to access sensitive information from system memory, and take other malicious actions.

darkreading EN 2024 speculative CPU CVE-2024-2193 GhostRace vulnerability
APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme https://thehackernews.com/2024/03/apt28-hacker-group-targeting-europe.html?m=1
18/03/2024 07:24:03
QRCode
archive.org

The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.

"The uncovered lures include a mixture of internal and publicly available documents, as well as possible actor-generated documents associated with finance, critical infrastructure, executive engagements, cyber security, maritime security, healthcare, business, and defense industrial production," IBM X-Force said in a report published last week.

thehackernews EN 2024 APT28 Russia-linked Widespread Phishing Scheme
National Vulnerability Database: Opaque changes and unanswered questions https://anchore.com/blog/national-vulnerability-database-opaque-changes-and-unanswered-questions/
17/03/2024 17:04:57
QRCode
archive.org
thumbnail

Anchore engineers are investigating why as of February 15, 2024, NIST has almost completely stopped updating NVD with analysis for CVE IDs.

anchore EN 2024 NVD CVE backlog NIST
Google Paid Out $10 Million via Bug Bounty Programs in 2023 https://www.securityweek.com/google-paid-out-10-million-via-bug-bounty-programs-in-2023
17/03/2024 16:58:48
QRCode
archive.org

Google on Tuesday announced that it paid out a total of $10 million through its bug bounty programs in 2023, bringing the total amount awarded by the tech giant for vulnerabilities found in its products since 2010 to $59 million.

The total paid out in 2023 is less than the $12 million handed out in 2022, but it’s still a significant amount. The money was earned last year by 632 researchers from 68 countries. The highest single reward was $113,337.

securityweek EN 2024 Google bugbounty 2023 paid
Why hackers are targeting young public school students https://www.npr.org/2024/03/12/1237497833/students-schools-cybersecurity-hackers-credit
17/03/2024 16:51:40
QRCode
archive.org
thumbnail

Districts store all kinds of sensitive student data, which means the consequences of a school cyberattack can follow pupils well into adulthood. And it's not just their credit that's at risk.

npr EN 2024 US students Districts school target
Loi sur l’IA https://digital-strategy.ec.europa.eu/fr/policies/regulatory-framework-ai
17/03/2024 16:06:58
QRCode
archive.org

La loi sur l’IA est le tout premier cadre juridique en matière d’IA, qui traite des risques liés à l’IA et positionne l’Europe pour qu’elle joue un rôle de premier plan à l’échelle mondiale.

digital-strategy.ec.europa.eu FR 2024 IA loi legal juridique Europe EU regulatory
Linux Foundation Launches Tazama: A Revolutionary Open Source Solution for Real-Time Fraud Management https://www.linuxfoundation.org/press/linux-foundation-launches-tazama-for-real-time-fraud-management
17/03/2024 14:48:34
QRCode
archive.org
thumbnail

Tazama is the first open source platform for financial monitoring and fraud detection.

linuxfoundation EN 2024 Linux Foundation Tazama Open-Source fraud detection
page 63 / 76
4670 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio