Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 7 / 76
1513 résultats taggé 2024  ✕
Tuta has suffered multiple DDoS attacks in one week – but it claims privacy has not been compromised https://www.techradar.com/computing/cyber-security/tuta-has-suffered-multiple-ddos-attacks-in-one-week-but-it-claims-privacy-has-not-been-compromised
09/12/2024 11:19:41
QRCode
archive.org
thumbnail

Some users are still lamenting issues in using the encrypted email service

techradar EN 2024 DDoS attacks Tuta mail
Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows https://www.cadosecurity.com/blog/meeten-malware-threat
09/12/2024 11:15:19
QRCode
archive.org
thumbnail

Cado Security Labs details the discovery of a new cross-platform information stealer malware dubbed "Meeten" targeting macOS and Windows users.

cadosecurity EN 2024 Cross-Platform Threat Meeten EN 2024 macOS Windows
Ransomware hackers target NHS hospitals with new cyberattacks https://techcrunch.com/2024/12/04/ransomware-hackers-target-nhs-hospitals-with-new-cyberattacks/
09/12/2024 11:03:43
QRCode
archive.org
thumbnail

Two NHS trusts in England have been hacked in recent weeks, the latest attacks to hit the national health service.

techcrunch EN 2024 INCRansomware NHS UK health ransomware
8 US telcos compromised, FBI advises Americans to use encrypted communications - Help Net Security https://www.helpnetsecurity.com/2024/12/05/us-telcos-compromised-fbi-advises-use-of-encrypted-communications/
09/12/2024 10:54:13
QRCode
archive.org
thumbnail

FBI and CISA officials have advised Americans to use encrypted call and messaging apps to protect their communications from threat actors.

helpnetsecurity EN 2024 telcos US encrypted call advise FBI CISA
Enhanced Visibility and Hardening Guidance for Communications Infrastructure https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
09/12/2024 08:46:37
QRCode
archive.org

This guide provides network engineers and defenders of communications infrastructure with best practices to strengthen their visibility and harden their network

cisa EN 2024 guide visibility Hardening US Communications Infrastructure
2023 Anna Jaques Hospital data breach impacted +310K people https://securityaffairs.com/171801/data-breach/anna-jaques-hospital-data-breach.html
09/12/2024 07:32:06
QRCode
archive.org
thumbnail

Anna Jaques Hospital revealed that the ransomware attack it suffered last year has exposed sensitive health data for over 316,000 patients.

securityaffairs EN 2024 health Hospital AnnaJaques
zizmor would have caught the Ultralytics workflow vulnerability https://blog.yossarian.net/2024/12/06/zizmor-ultralytics-injection
08/12/2024 15:42:01
QRCode
archive.org
thumbnail

TL;DR: zizmor would have caught the vulnerability that caused this…mostly. Read on for details.

yossarian EN 2024 Supply-Chain-Attack zizmor Ultralytics vulnerability workflow
Ultralytics AI model hijacked to infect thousands with cryptominer https://www.bleepingcomputer.com/news/security/ultralytics-ai-model-hijacked-to-infect-thousands-with-cryptominer/
08/12/2024 15:40:38
QRCode
archive.org
thumbnail

The popular Ultralytics YOLO11 AI model was compromised in a supply chain attack to deploy cryptominers on devices running versions 8.3.41 and 8.3.42 from the Python Package Index (PyPI)  

bleepingcomputer EN 2024 Artificial-Intelligence Open-Source Supply-Chain Supply-Chain-Attack Ultralytics
Unveiling Celular 007: An In-Depth Analysis of Brazilian Stalkerware and Strategies for Collective Protection https://interseclab.org/en/unveiling-celular-007-an-in-depth-analysis-of-brazilian-stalkerware-and-strategies-for-collective-protection-2/
08/12/2024 10:28:19
QRCode
archive.org

Key findings from our analysis include:

Advanced Surveillance Capabilities:

  • Utilizes technologies like WebRTC for real-time audio and video streaming.
  • Abuses Accessibility Services to intercept user interactions.

Comprehensive Data Exfiltration:

  • Collects and transmits a wide range of personal data, including messages, call logs, and location information.

Persistence Mechanisms:

  • Employs techniques to remain active on the device, such as auto-start on boot and misuse of device administrator privileges.

Abuse of Legitimate Services:

  • Utilizes Firebase Cloud Messaging to establish command and control channels, disguising its communications as legitimate traffic.

Indicators of Compromise (IoCs):

  • Identified specific URLs, IP addresses, file hashes, and other artifacts associated with Celular 007.

Need for Collective Protection:

  • Highlights the importance of collective defense strategies and community awareness to combat such invasive tools.
interseclab EN 2024 spyware Celular007 Stalkerware Brazil
Roumanie : la Cour constitutionnelle annule le premier tour de l’élection présidentielle du fait de graves manipulations sur TikTok https://www.lemonde.fr/international/article/2024/12/06/roumanie-la-cour-constitutionnelle-annule-le-premier-tour-de-l-election-presidentielle-apres-de-graves-manipulations-sur-tiktok_6433720_3210.html?lmd_medium=al&lmd_campaign=envoye-par-appli&lmd_creation=android&lmd_source=default
08/12/2024 01:37:37
QRCode
archive.org
thumbnail

Cette décision est prise au lendemain de la déclassification de documents du renseignement national faisant état d’une opération d’envergure sur TikTok en faveur du candidat prorusse, Calin Georgescu, arrivé en tête du premier tour de l’élection présidentielle, à la surprise générale.

lemonde FR 2024 Roumanie Cour constitutionnelle annule déclassification TikTok Russie influence campagne prorusse CalinGeorgescu
Protecting Undersea Internet Cables: A Tech Challenge https://spectrum.ieee.org/undersea-internet-cables-protection-tech
08/12/2024 00:51:58
QRCode
archive.org
thumbnail

A recent, alleged Baltic Sea sabotage highlights the system’s fragility

spectrum.ieee.org EN 2024 fiber-optic-cables undersea-cables internet-security reliability technology-and-society maritime-technology underwater-robots
Veeam warns of critical RCE bug in Service Provider Console https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-rce-bug-in-service-provider-console/
07/12/2024 09:55:40
QRCode
archive.org
thumbnail

​Veeam released security updates today to address two Service Provider Console (VSPC) vulnerabilities, including a critical remote code execution (RCE) discovered during internal testing.

VSPC, described by the company as a remote-managed BaaS (Backend as a Service) and DRaaS (Disaster Recovery as a Service) platform, is used by service providers to monitor the health and security of customer backups, as well as manage their Veeam-protected virtual, Microsoft 365, and public cloud workloads.

bleepingcomputer EN 2024 RCE bug DRaaS VSPC Veeam
Cisco warns of continued exploitation of 10-year-old ASA bug https://www.scworld.com/news/cisco-warns-of-continued-exploitation-of-10-year-old-asa-bug
07/12/2024 09:54:14
QRCode
archive.org
thumbnail

Cisco on Dec. 2 updated an advisory from March 18 about a 10-year-old vulnerability in the WebVPN login page of Cisco’s Adaptive Security Appliance (ASA) software that could let an unauthenticated remote attacker conduct a cross-site scripting (XSS) attack.
In its recent update, the Cisco Product Security Incident Response Team (PSIRT) said it became aware of additional attempted exploitation of this vulnerability in the wild last month.

scworld EN 2024 10-year-old ASA bug Cisco CVE-2014-2120
FBI, CISA urge Americans to use secure messaging apps in wake of massive cyberattack https://www.zdnet.com/article/fbi-cisa-urge-americans-to-use-secure-messaging-apps-in-wake-of-massive-cyberattack/
07/12/2024 09:48:34
QRCode
archive.org
thumbnail
zdnet EN 2024 advse CISA FBI US telcos cyberattack secure messaging encrypted
Train de mesures sur la cybersécurité: le Conseil adopte de nouvelles dispositions législatives pour renforcer les capacités de l'UE en matière de cybersécurité https://www.consilium.europa.eu/fr/press/press-releases/2024/12/02/cybersecurity-package-council-adopts-new-laws-to-strengthen-cybersecurity-capacities-in-the-eu/
05/12/2024 17:28:10
QRCode
archive.org

Afin de renforcer la solidarité et les capacités dans l'UE en matière de détection, de préparation et de réaction face aux menaces et incidents de cybersécurité, le Conseil a adopté ce jour deux nouveaux actes législatifs dans le cadre du "paquet" législatif sur la cybersécurité, à savoir le "règlement sur la cybersolidarité" et une modification ciblée du règlement sur la cybersécurité.

europa.eu FR 2024 cybersolidarité cybersécurité SOC UE
Cloudflare’s developer domains increasingly abused by threat actors https://www.bleepingcomputer.com/news/security/cloudflares-developer-domains-increasingly-abused-by-threat-actors/
05/12/2024 17:10:58
QRCode
archive.org
thumbnail

Cloudflare's 'pages.dev' and 'workers.dev' domains, used for deploying web pages and facilitating serverless computing, are being increasingly abused by cybercriminals for phishing and other malicious activities.

bleepingcomputer EN 2024 Abuse Cloudflare Cloudflare-Pages Cloudflare-Workers Cybercrime Phishing
Black Basta ransomware gang hit BT Group https://securityaffairs.com/171668/breaking-news/black-basta-ransomware-attack-bt-group.html
05/12/2024 16:54:18
QRCode
archive.org
thumbnail

BT Group (formerly British Telecom)'s Conferencing division shut down some of its servers following a Black Basta ransomware attack.

securityaffairs EN 2024 BT Group BlackBasta ransomware
Where There’s Smoke, There’s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/
05/12/2024 16:50:05
QRCode
archive.org
thumbnail
watchtowr EN 2024 Mitel MiCollab CVE-2024-3528 CVE-2024-41713 0day PoC
At least 8 US telcos, dozens of countries impacted by Salt Typhoon breaches, White House says | The Record from Recorded Future News https://therecord.media/eight-telcos-breached-salt-typhoon-nsc
05/12/2024 16:49:26
QRCode
archive.org
thumbnail

Senators briefed on the wide-ranging breaches by Chinese hackers called for action on Wednesday to protect the country's telecommunications networks.

therecord.media EN 2024 telcos US Salt-Typhoon China breaches
Lateral Movement on macOS: Unique and Popular Techniques and In-the-Wild Examples https://unit42.paloaltonetworks.com/unique-popular-techniques-lateral-movement-macos/
05/12/2024 16:44:03
QRCode
archive.org
thumbnail

We uncover macOS lateral movement tactics, such as SSH key misuse and AppleScript exploitation. Strategies to counter this attack trend are also discussed. We uncover macOS lateral movement tactics, such as SSH key misuse and AppleScript exploitation. Strategies to counter this attack trend are also discussed.

unit42 EN 2024 macOS ARD AppleScript attacks lateral-movement tactics
page 7 / 76
4508 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio