Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 82 / 205
4094 résultats taggé EN  ✕
Mandiant says hackers stole a 'significant volume of data' from Snowflake customers https://techcrunch.com/2024/06/10/mandiant-hackers-snowflake-stole-significant-volume-data-customers/
11/06/2024 06:43:43
QRCode
archive.org
thumbnail

The security firm said the attacks targeting Snowflake customers is "ongoing," suggesting the number of affected companies may rise.

techcrunch EN 2024 Mandiant Snowflake customers
Apple’s AI promise: “Your data is never stored or made accessible to Apple” https://arstechnica.com/ai/2024/06/apples-ai-promise-your-data-is-never-stored-or-made-accessible-by-apple/
11/06/2024 06:42:41
QRCode
archive.org
thumbnail

And publicly reviewable server code means experts can "verify this privacy promise."

arstechnica EN 2024 Apple AI data privacy WWDC
Private Cloud Compute: A new frontier for AI privacy in the cloud https://security.apple.com/blog/private-cloud-compute/
11/06/2024 06:41:58
QRCode
archive.org

Secure and private AI processing in the cloud poses a formidable new challenge. To support advanced features of Apple Intelligence with larger foundation models, we created Private Cloud Compute (PCC), a groundbreaking cloud intelligence system designed specifically for private AI processing. Built with custom Apple silicon and a hardened operating system, Private Cloud Compute extends the industry-leading security and privacy of Apple devices into the cloud, making sure that personal user data sent to PCC isn’t accessible to anyone other than the user — not even to Apple. We believe Private Cloud Compute is the most advanced security architecture ever deployed for cloud AI compute at scale.

apple EN 2024 WWDC Apple Security Research cloud AI PCC privacy architecture
La SSR sur ses gardes face à l'éventualité de cyberattaques pendant le sommet du Bürgenstock https://www.rts.ch/info/suisse/2024/article/la-ssr-sur-ses-gardes-face-a-l-eventualite-de-cyberattaques-pendant-le-sommet-du-burgenstock-28528499.html
10/06/2024 09:04:24
QRCode
archive.org
thumbnail

Si la Russie ne participera pas à la conférence sur la paix en Ukraine du Bürgenstock, l'Office fédéral de la cybersécurité met en garde contre d'éventuelles actions perturbatrices de sa part. Première responsable de la transmission d'informations, la SSR est sur le qui-vive.

rts Suisse EN 2024 Russie cyberattaques Bürgenstock SSR
Malicious VSCode extensions with millions of installs discovered https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-with-millions-of-installs-discovered/
10/06/2024 09:00:09
QRCode
archive.org
thumbnail

A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to

bleepingcomputer EN 2024 Extensions Microsoft Scanner VSCode
Russia-linked 'Lumma' crypto stealer now targets Python devs https://www.sonatype.com/blog/crytic-compilers-typosquats-known-crypto-library-drops-windows-trojan
09/06/2024 16:32:39
QRCode
archive.org
thumbnail

Sonatype's automated malware detection systems identified a malicious PyPI package called crytic-compilers, connected to Russia-linked Lumma Windows stealer, and named very closely after a well-known legitimate Python library that is used by cryptocurrency developers.

sonatype EN 2024 PyPI Lumma Python cryptocurrency developers
Menace Unleashed: Excel File Deploys Cobalt Strike at Ukraine | Fortinet Blog https://www.fortinet.com/blog/threat-research/menace-unleashed-excel-file-deploys-cobalt-strike-at-ukraine
09/06/2024 16:31:33
QRCode
archive.org
thumbnail

FortiGuard Labs has recently identified a sophisticated cyberattack involving an Excel file embedded with a VBA macro designed to deploy a DLL file. Learn more.

fortinet EN 2024 excel FortiGuard-Labs-Threat-Research ukraine Cobalt-Strike
Microsoft hit with EU privacy complaints over schools' use of 365 Education suite https://techcrunch.com/2024/06/04/microsoft-hit-with-eu-privacy-complaints-over-schools-use-of-365-education-suite/
09/06/2024 16:30:38
QRCode
archive.org
thumbnail

Microsoft's education-focused flavor of its cloud productivity suite, Microsoft 365 Education, is facing investigation in the European Union. Privacy

techcrunch EN 2024 Microsoft privacy schools cloud EU noyb Austri GDPR
Major London hospitals disrupted by Synnovis ransomware attack https://www.bleepingcomputer.com/news/security/major-london-hospitals-disrupted-by-synnovis-ransomware-attack/
09/06/2024 16:28:25
QRCode
archive.org
thumbnail

A ransomware attack affecting pathology and diagnostic services provider Synnovis has impacted healthcare services at multiple major NHS hospitals in London.

bleepingcomputer EN 2024 UK Cyberattack Hospital London Ransomware Synlab Synnovis United-Kingdom Healthcare
Keeping GenAI technologies secure is a shared responsibility https://blog.mozilla.org/en/mozilla/keeping-genai-technologies-secure-is-a-shared-responsibility/
09/06/2024 14:49:08
QRCode
archive.org
thumbnail

Today, we are investing in the next generation of GenAI security with the 0Day Investigative Network (0Din) by Mozilla, a bug bounty program for large language models (LLMs) and other deep learning technologies. 0Din expands the scope to identify and fix GenAI security by delving beyond the application layer with a focus on emerging classes of vulnerabilities and weaknesses in these new generations of models.

mozilla EN BugBounty LLMs 0Din GenAI
Howling at the Inbox: Sticky Werewolf's Latest Malicious Aviation Attacks https://blog.morphisec.com/sticky-werewolfs-aviation-attacks
09/06/2024 14:46:00
QRCode
archive.org
thumbnail

In this analysis, Morphisec Threat Labs details the latest Sticky Werewolf cyber threat group campaign targeting the aviation industry.

morphisec EN 2024 Russia Aviation StickyWerewolf Belarus
Revealed: Russian legal foundation linked to Kremlin activities in Europe | Russia | The Guardian https://www.theguardian.com/world/article/2024/jun/02/revealed-russian-legal-defence-foundation-pravfond-europe
08/06/2024 09:48:51
QRCode
archive.org
thumbnail

Leaked internal documents have exposed the activities of a Russian state-backed legal defence foundation that European intelligence agencies and analysts say is in fact a Kremlin influence operation active in 48 countries across Europe and around the world.

Internal documents from the Fund for Support and Protection of the Rights of Compatriots Living Abroad (Pravfond) indicate that the foundation finances propaganda websites targeted at Europeans, helped pay for the legal defence of the convicted arms trafficker Viktor Bout and the assassin Vadim Krasikov, and has employed a number of former intelligence officers as the directors of its operations in European countries.

theguardian EN 2024 Leaked internal documents Russia EU Pravfond intelligence
The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/
07/06/2024 21:25:09
QRCode
archive.org
thumbnail

The number of alleged hacks targeting the customers of cloud storage firm Snowflake appears to be snowballing into one of the biggest data breaches of all time.

wired EN 2024 hacks Snowflake Largest Data-Breach
Security Alert: CVE-2024-4577 - PHP CGI Argument Injection Vulnerability https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/?ref=labs.watchtowr.com
07/06/2024 13:50:51
QRCode
archive.org
thumbnail

While implementing PHP, the team did not notice the Best-Fit feature of encoding conversion within the Windows operating system. This oversight allows unauthenticated attackers to bypass the previous protection of CVE-2012-1823 by specific character sequences. Arbitrary code can be executed on remote PHP servers through the argument injection attack.

devco.re EN 2024 CVE-2024-4577 PHP CVE-2012-1823 php-cgi
No Way, PHP Strikes Again! (CVE-2024-4577) https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/
07/06/2024 13:50:05
QRCode
archive.org
thumbnail

Orange Tsai tweeted a few hours ago about “One of [his] PHP vulnerabilities, which affects XAMPP by default”, and we were curious to say the least. XAMPP is a very popular way for administrators and developers to rapidly deploy Apache, PHP, and a bunch of other tools, and any bug

watchtowr EN 2024 CVE-2024-4577 PHP windows
Operation Crimson Palace: A Technical Deep Dive – Sophos News https://news.sophos.com/en-us/2024/06/05/operation-crimson-palace-a-technical-deep-dive/
06/06/2024 20:40:09
QRCode
archive.org
thumbnail

Sophos Managed Detection and Response initiated a threat hunt across all customers after the detection of abuse of a vulnerable legitimate VMware executable (vmnat.exe) to perform dynamic link library (DLL) side-loading on one customer’s network. In a search for similar incidents in telemetry, MDR ultimately uncovered a complex, persistent cyberespionage campaign targeting a high-profile government organization in Southeast Asia. As described in the first part of this report, we identified at least three distinct clusters of intrusion activity present in the organization’s network from at least March 2023 through December 2023.

The three security threat activity clusters—which we designated as Alpha (STAC1248), Bravo (STAC1870), and Charlie (STAC1305) – are assessed with high confidence to operate on behalf of Chinese state interests. In this continuation of our report, we will provide deeper technical analysis of the three activity clusters, including the tactics, techniques, and procedures (TTPs) used in the campaign, aligned to activity clusters where possible. We also provide additional technical details on prior compromises within the same organization that appear to be connected to the campaign.

sophos EN 2024 TTPs VMware cyberespionage Alpha STAC1248 Bravo STAC1870 Charlie STAC1305
Europe's cybersecurity chief says disruptive attacks have doubled in 2024, sees Russia behind many https://apnews.com/article/europe-election-cybersecurity-russia-ukraine-5b0cca725d17a028dd458df77a60440c
06/06/2024 09:29:32
QRCode
archive.org
thumbnail

The top European Union cybersecurity official says that disruptive digital attacks have doubled in the 27-member bloc in recent months and election-related services are also being targeted.

apnews EN 2024 Juhan-Lepassaar election-related EU cyberattack Parliament Europe Russian-backed Russia-Ukraine-war
Vulnerability in Cisco Webex cloud service exposed government authorities, companies https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/
05/06/2024 22:46:17
QRCode
archive.org
thumbnail

A previously discovered vulnerability affecting self-hosted Cisco Webex instances similarly affected the Webex cloud service.

helpnetsecurity EN 2024 Vulnerability Cisco Webex cloud service exposed government
Cyberattack on telecom giant Frontier claimed by RansomHub https://therecord.media/frontier-communications-cyberattack-ransomhub
05/06/2024 09:39:06
QRCode
archive.org
thumbnail

The Dallas-based company had said in a regulatory filing in April that a cybercrime group was responsible for a data breach. The gang added Frontier to its leak site on June 1.

therecord.media EN 2024 US Frontier RansomHub Cyberattack telecom
CVE-2024-27822: macOS PackageKit Privilege Escalation https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html
05/06/2024 08:41:53
QRCode
archive.org

Another fun exploit! This time with local privilege escalation through Apple’s PackageKit.framework when running ZSH-based PKGs 🎉.

khronokernel CVE-2024-27822 EN 2024 ZSH macos package pkg
page 82 / 205
4670 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio