Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 78 / 205
4082 résultats taggé EN  ✕
Chinese Cyberspies Employ Ransomware in Attacks for Diversion https://www.bleepingcomputer.com/news/security/chinese-cyberspies-employ-ransomware-in-attacks-for-diversion/
27/06/2024 08:26:45
QRCode
archive.org
thumbnail

Cyberespionage groups have been using ransomware as a tactic to make attack attribution more challenging, distract defenders, or for a financial reward as a secondary goal to data theft.

bleepingcomputer EN 2024 APT BitLocker CatB ChamelGang Cyber-espionage Ransomware
ChamelGang & Friends | Cyberespionage Groups Attacking Critical Infrastructure with Ransomware https://www.sentinelone.com/labs/chamelgang-attacking-critical-infrastructure-with-ransomware/
27/06/2024 08:26:03
QRCode
archive.org
thumbnail

Threat actors in the cyberespionage ecosystem are using ransomware for financial gain, disruption, distraction, misattribution, and the removal of evidence.

sentinelone EN 2024 ChamelGang Cyberespionage Critical-infrastructure Ransomware
Microsoft employee accidentally publishes PlayReady code https://borncity.com/win/2024/06/26/microsoft-employee-accidentally-publishes-playready-code/
26/06/2024 15:06:57
QRCode
archive.org

[German]A Microsoft software developer has accidentally shared internal PlayReady source code with the public (a developer forum). The data leak of 4 GByte is sufficient to compile the required DLL from the source code. This could be a real boon for people who want to reverse engineering or crack PlayReady. What is PlayReady? PlayReady is...

borncity.com EN 2024 Microsoft employee PlayReady leak
UEFIcanhazbufferoverflow: Widespread Impact from Vulnerability in Popular PC and Server Firmware https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/
26/06/2024 13:51:38
QRCode
archive.org
thumbnail

Summary Eclypsium Automata, our automated binary analysis system, has identified a high impact vulnerability (CVE-2024-0762 with a reported CVSS of 7.5) in the Phoenix SecureCore UEFI firmware that runs on multiple families of Intel Core desktop and mobile processors. The issue involves an unsafe variable in the Trusted Platform Module (TPM) configuration that could lead […]

eclypsium.com EN 2024 UEFIcanhazbufferoverflow Vulnerability Phoenix CVE-2024-0762 SecureCore UEFI
The inside view of spyware’s 'dirty interference,' from two recent Pegasus victims https://therecord.media/pegasus-spyware-victims-sannikov-erlikh
26/06/2024 11:42:21
QRCode
archive.org
thumbnail

Andrei Sannikov and Evgeny Erlikh discuss the effects of discovering their devices had been infected with Pegasus — making them part of a rapidly expanding list of civil-society figures targeted with the commercial spyware.

therecord.media EN 2024 spyware Pegasus effects civil-society
CDK Begins Restoring Systems Amid Ransomware Payment Reports https://www.databreachtoday.eu/cdk-begins-restoring-systems-amid-ransomware-payment-reports-a-25605
26/06/2024 11:01:08
QRCode
archive.org
thumbnail

CDK Global, the auto dealership software solutions firm that supplies services to an estimated 15,000 dealerships in the U.S. and Canada, said it has begun the

databreachtoday EN 2024 CDK-Global CDK car-dealership cyberattack auto-dealerships ransomware
Neiman Marcus says 64,000 affected by breach of Snowflake customer account https://therecord.media/neiman-marcus-snowflake-breach-thousands
26/06/2024 08:40:35
QRCode
archive.org
thumbnail

Neiman Marcus is the latest large company affected by a run of attacks on customers of the data cloud storage provider Snowflake.

therecord.media EN 2024 Snowflake NeimanMarcus breach
South Africa’s national health lab hit with ransomware attack amid mpox outbreak https://therecord.media/south-africa-lab-ransomware-mpox-outbreak
26/06/2024 08:39:34
QRCode
archive.org
thumbnail

South Africa’s National Health Laboratory Service (NHLS) was hit by hackers on Saturday, with the dissemination of lab results severely impacted.

therecord.media EN 2024 South-Africa Healthcare NHLS ransomware impact
GrimResource - Microsoft Management Console for initial access and evasion https://www.elastic.co/security-labs/grimresource
25/06/2024 16:40:55
QRCode
archive.org
thumbnail

Elastic researchers uncovered a new technique, GrimResource, which allows full code execution via specially crafted MSC files. It underscores a trend of well-resourced attackers favoring innovative initial access methods to evade defenses.

elastic.co EN 2024 GrimResource MSC technique evasion initial-access
Stop Using cdn.polyfill.io Now https://blog.huli.tw/2024/06/25/en/stop-using-polyfill-io/
25/06/2024 16:38:13
QRCode
archive.org
thumbnail

Polyfill.io is a service that automatically provides front-end polyfills, making it very convenient to use. You just need to select the functionality you want to polyfill and then include a JavaScript

huli.tw EN 2024 polyfill Polyfill.io cdn
Recent Zyxel NAS Vulnerability Exploited by Botnet https://www.securityweek.com/recent-zyxel-nas-vulnerability-exploited-by-botnet/
25/06/2024 15:25:56
QRCode
archive.org

A recently disclosed critical-severity vulnerability in discontinued Zyxel NAS devices is already exploited in botnet attacks, the Shadowserver Foundation warns.

Tracked as CVE-2024-29973, the issue is described as a code injection flaw that can be exploited remotely without authentication. It was introduced last year, when Zyxel patched CVE-2023-27992, a similar code injection bug.

“While patching this vulnerability, they added a new endpoint which uses the same approach as the old ones, and while doing so, implemented the same mistakes as its predecessors,” explains Outpost24 security researcher Timothy Hjort, who discovered and reported the security defect.

securityweek EN 2024 Mirai-like CVE-2024-29973 Zyxel
Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine (part 1) https://www.ambionics.io/blog/iconv-cve-2024-2961-p1
25/06/2024 09:19:25
QRCode
archive.org
thumbnail

A few months ago, I stumbled upon a 24 years old buffer overflow in the glibc, the base library for linux programs. Despite being reachable in multiple well-known libraries or executables, it proved rarely exploitable — while it didn't provide much leeway, it required hard-to-achieve preconditions. Looking for targets lead mainly to disappointment. On PHP however, the bug shone, and proved useful in exploiting its engine in two different ways.

ambionics EN 2024 cve-2024-2961 glibc linux PHP
CISA confirms hackers may have accessed data from chemical facilities during January incident https://therecord.media/cisa-confirms-hackers-chemical-facilities
25/06/2024 09:03:06
QRCode
archive.org
thumbnail

The agency found no evidence that hackers exfiltrated information but noted the intrusion “may have resulted in the potential unauthorized access” to security plans, vulnerability assessments and user accounts within a national system to protect the chemicals sector.

therecord.media EN 2024 CISA confirms hackers CSAT Critical-infrastructure
New attack uses MSC files and Windows XSS flaw to breach networks https://www.bleepingcomputer.com/news/security/new-grimresource-attack-uses-msc-files-and-windows-xss-flaw-to-breach-networks/
25/06/2024 09:01:37
QRCode
archive.org
thumbnail

A novel command execution technique dubbed 'GrimResource' uses specially crafted MSC (Microsoft Saved Console) and an unpatched Windows XSS flaw to perform code execution via the Microsoft Management Console.

bleepingcomputer EN 2024 Attack GrimResource Microsoft MSC Windows XSS
Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) https://www.wiz.io/blog/probllama-ollama-vulnerability-cve-2024-37032
25/06/2024 08:51:44
QRCode
archive.org
thumbnail

Wiz Research discovered CVE-2024-37032, an easy-to-exploit Remote Code Execution vulnerability in the open-source AI Infrastructure project Ollama.

wiz EN 2024 CVE-2024-37032 Overview Mitigations Ollama AI Infrastructure easy-to-exploit RCE
Malvertising Campaign Leads to Execution of Oyster Backdoor https://www.rapid7.com/blog/post/2024/06/17/malvertising-campaign-leads-to-execution-of-oyster-backdoor/
25/06/2024 00:00:43
QRCode
archive.org
thumbnail

Rapid7 observed a recent malvertising campaign luring users to download malicious installers for popular software like Google Chrome and Microsoft Teams.

rapid7 EN 2024 Malvertising Oyster Backdoor
RansomHub Draws in Affiliates with Multi-OS Capability and High Commission Rates https://www.recordedfuture.com/ransomhub-draws-in-affiliates-with-multi-os-capability-and-high-commission-rates
24/06/2024 20:15:50
QRCode
archive.org
thumbnail

Discover how RansomHub's ransomware-as-a-service targets Windows, Linux, and ESXi systems.

recordedfuture EN 2024 analysis RansomHub ESXi Linux Multi-OS
XZ backdoor behavior inside OpenSSH https://securelist.com/xz-backdoor-part-3-hooking-ssh/113007/
24/06/2024 16:44:07
QRCode
archive.org
thumbnail

In this article, we analyze XZ backdoor behavior inside OpenSSH, after it has achieved RSA-related function hook.

securelist EN 2024 Backdoor Cyber-espionage Linux Malware Malware-Descriptions Malware-Technologies SSH Targeted-attacks XZ
Cyber attack compromised Indonesia data centre, ransom sought https://www.reuters.com/technology/cybersecurity/cyber-attack-compromised-indonesia-data-centre-ransom-sought-reports-antara-2024-06-24/
24/06/2024 15:14:29
QRCode
archive.org

A cyber attacker compromised Indonesia's national data centre, disrupting immigration checks at airports, and asked for an $8 million ransom, the country's communications minister told Reuters on Monday.
The attack disrupted several government services, most notably at airports last week, with long lines forming at immigration desks. Automated passport machines were now functioning, the communications ministry said.

reuters EN 2024 Indonesia LockBit3.0 airports
Levi Strauss notifies customers of cyberattack https://cybernews.com/news/levi-strauss-jeans-cyberattack/
24/06/2024 12:56:29
QRCode
archive.org

Personal information, including partial payment details, may have been obtained by bad actors during an automated credential-stuffing attack on Levi’s online store.

The maker of the famous Levi’s denim jeans reported that over 72,000 accounts were affected during a “security incident” that was detected on July 13th.

cybernews EN 2024 Levi's incident data-breach credential-stuffing
page 78 / 205
4653 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio