Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 95 / 235
Molding lies into reality || Exploiting CVE-2024-4358 https://summoning.team/blog/progress-report-server-rce-cve-2024-4358-cve-2024-1800/
03/06/2024 13:05:23
QRCode
archive.org
thumbnail

Progress Report Server Unauthenticated Remote Code Execution Chain

summoning.team EN 2024 CVE-2024-4358 Telerik Report Server
Snowflake at centre of world’s largest data breach https://doublepulsar.com/snowflake-at-central-of-worlds-largest-data-breach-939fc400912e
03/06/2024 09:48:52
QRCode
archive.org

Cloud AI Data platform Snowflake are having a bad month. Due to teenager threat actors and cybersecurity of its own customers… and its own cybersecurity, too, in terms of optics.

There are several large data breaches playing out in the media currently. For example, Ticketmaster owner Live Nation filed an 8-K with the SEC for potentially the largest data breach ever, claimed to be 560 million customers.

doublepulsar EN 204 Snowflake Data-Breach analysis KevinBeaumont
Cyber house of cards – Politicians’ personal details exposed online https://proton.me/blog/politicians-exposed-dark-web
03/06/2024 09:47:24
QRCode
archive.org
thumbnail

We searched the dark web for politicians’ official email addresses, and roughly 40% of them appeared, along with other sensitive information. This is a scandal waiting to happen.

proton.me EN 2024 darkweb politicians PI exposed marketplace
Ticketmaster confirms massive breach after stolen data for sale online https://www.bleepingcomputer.com/news/security/ticketmaster-confirms-massive-breach-after-stolen-data-for-sale-online/#google_vignette
03/06/2024 08:41:00
QRCode
archive.org
thumbnail

Live Nation has confirmed that Ticketmaster suffered a data breach after its data was stolen from a third-party cloud database provider, which is believed to be Snowflake.

bleepingcomputer EN 2024 Cyberattack Data-Breach ShinyHunters Snowflake Ticketmaster
Shalev Hulio Made Pegasus Spyware, Now He’s King of Israeli AI https://theintercept.com/2024/05/23/israel-spyware-pegasus-shalev-hulio-ai-inteleye/
02/06/2024 12:18:19
QRCode
archive.org
thumbnail

Shalev Hulio is remaking his image but is still involved in a web of cybersecurity ventures with his old colleagues from NSO Group.

theintercept EN 2024 Shalev-Hulio Spyware Israel AI Pegasus NSO
Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster. https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e
01/06/2024 14:43:53
QRCode
archive.org

I wrote a piece recently about Copilot+ Recall, a new Microsoft Windows 11 feature which — in the words of Microsoft CEO Satya Nadella- takes “screenshots” of your PC constantly, and makes it into an…

doublepulsar EN Microsoft Copilot+ PC Windows Recall Stealing disaster KevinBeaumont
NIST Getting Outside Help for National Vulnerability Database https://www.securityweek.com/nist-getting-outside-help-for-national-vulnerability-database/
01/06/2024 14:04:01
QRCode
archive.org

NIST announced on Wednesday that it will be receiving outside help to get the National Vulnerability Database (NVD) back on track within the next few months.

The organization informed the cybersecurity community in February that it should expect delays in the analysis of Common Vulnerabilities and Exposures (CVE) identifiers in the NVD, saying that it was working to establish a consortium to improve the program.

securityweek EN 2024 NIST CVE National Vulnerability Database NVD
How AI Will Change Democracy https://www.schneier.com/blog/archives/2024/05/how-ai-will-change-democracy.html
01/06/2024 13:53:35
QRCode
archive.org

I don’t think it’s an exaggeration to predict that artificial intelligence will affect every aspect of our society. Not by doing new things. But mostly by doing things that are already being done by humans, perfectly competently.

Replacing humans with AIs isn’t necessarily interesting. But when an AI takes over a human task, the task changes.

schneier EN 2024 AI risk Democracy Change analysis
Hackers phish finance orgs using trojanized Minesweeper clone https://www.bleepingcomputer.com/news/security/hackers-phish-finance-orgs-using-trojanized-minesweeper-clone/
01/06/2024 13:47:13
QRCode
archive.org
thumbnail

Hackers are utilizing code from a Python clone of Microsoft's venerable Minesweeper game to hide malicious scripts in attacks on European and US financial organizations.

bleepingcomputer EN 2024 Minesweeper RAT Remote-Access Remote-Access-Trojan Ukraine
Space secrets security update https://huggingface.co/blog/space-secrets-disclosure
01/06/2024 13:35:04
QRCode
archive.org
thumbnail

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

huggingface EN 2024 incident breach secrets AI tokens
Ticketmaster confirms data breach with a SEC filing https://stackdiary.com/ticketmaster-confirms-data-breach-with-a-sec-filing/
01/06/2024 12:00:29
QRCode
archive.org
thumbnail

Live Nation Entertainment, also known as Ticketmaster, has submitted an official Form 8-K with the U.S. Securities and Exchange Commission (SEC),

stackdiary EN 2024 Ticketmaster SEC data-breach
Hacker Releases Jailbroken "Godmode" Version of ChatGPT https://futurism.com/hackers-jailbroken-chatgpt-godmode
01/06/2024 10:41:17
QRCode
archive.org
thumbnail

A hacker has released a jailbroken version of ChatGPT called "GODMODE GPT."

Earlier today, a self-avowed white hat operator and AI red teamer who goes by the name Pliny the Prompter took to X-formerly-Twitter to announce the creation of the jailbroken chatbot, proudly declaring that GPT-4o, OpenAI's latest large language model, is now free from its guardrail shackles.

futurism EN 2024 chatgpt jailbroken GODMODE
Zero Day Initiative — CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud https://www.zerodayinitiative.com/blog/2024/5/29/cve-2024-30043-abusing-url-parsing-confusion-to-exploit-xxe-on-sharepoint-server-and-cloud#/
31/05/2024 09:47:53
QRCode
archive.org
thumbnail

Yes, the title is right. This blog covers an XML eXternal Entity (XXE) injection vulnerability that I found in SharePoint. The bug was recently patched by Microsoft. In general, XXE vulnerabilities are not very exciting in terms of discovery and related technical aspects. They may sometimes be fun t

zerodayinitiative EN 2024 SharePoint XML eXternal vulnerability CVE-2024-30043
Spyware maker pcTattletale says it's 'out of business' and shuts down after data breach | TechCrunch https://techcrunch.com/2024/05/28/pctattletale-spyware-shutters-data-breach/?ref=news.risky.biz&guccounter=1
31/05/2024 09:39:21
QRCode
archive.org
thumbnail

The spyware maker's founder, Bryan Fleming, said pcTattletale is "out of business and completely done," following a data breach.

techcrunch EN 2024 spyware pcTattletale out-of-business data-breach
Exiled, then spied on: Civil society in Latvia, Lithuania, and Poland targeted with Pegasus spyware https://www.accessnow.org/publication/civil-society-in-exile-pegasus/?ref=news.risky.biz
31/05/2024 09:38:58
QRCode
archive.org
thumbnail

At least seven more Russian, Belarusian, Latvian, and Israeli journalists and activists have been targeted with Pegasus within the EU.

accessnow EN 2024 Pegasus EU spyware Belarusia Russia Latvia Israel
‘Operation Endgame’ Hits Malware Delivery Platforms https://krebsonsecurity.com/2024/05/operation-endgame-hits-malware-delivery-platforms/
31/05/2024 09:17:02
QRCode
archive.org

Law enforcement agencies in the United States and Europe today announced Operation Endgame, a coordinated action against some of the most popular cybercrime platforms for delivering ransomware and data-stealing malware. Dubbed "the largest ever operation against botnets," the international effort…

krebsonsecurity EN 2024 Operation-Endgame
Active exploitation of unauthenticated stored XSS vulnerabilities in WordPress Plugins https://www.fastly.com/blog/active-exploitation-unauthenticated-stored-xss-vulnerabilities-wordpress/
31/05/2024 09:16:16
QRCode
archive.org
thumbnail

We have observed active exploitation attempts targeting three high-severity CVEs: CVE-2024-2194, CVE-2023-6961, and CVE-2023-40000.

fastly EN 2024 Wordpress XSS exploitation CVE-2024-2194 CVE-2023-6961 CVE-2023-40000
La nouvelle identité électronique étatique suisse https://swissprivacy.law/302/
31/05/2024 09:12:58
QRCode
archive.org

Après avoir été rejetée aux urnes le 7 mars 2021, la réglementation sur l’identité électronique renaît de ses cendres avec une nouvelle approche qui donne le rôle principal à l’État comme exploitant d’une infrastructure de confiance et comme émetteur de l’e-ID. La nouvelle infrastructure permet également aux acteurs publics et privé d'émettre d'autres justificatifs électroniques. Le nouveau projet de loi est actuellement entre les mains du Parlement fédéral.

swissprivacy FR CH 2024 eid suisse identité-éléctronique legal
OpenAI finds Russian, Chinese propaganda campaigns used its tech https://www.washingtonpost.com/technology/2024/05/30/openai-disinfo-influence-operations-china-russia/?pwapi_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJyZWFzb24iOiJnaWZ0IiwibmJmIjoxNzE3MDQxNjAwLCJpc3MiOiJzdWJzY3JpcHRpb25zIiwiZXhwIjoxNzE4NDIzOTk5LCJpYXQiOjE3MTcwNDE2MDAsImp0aSI6IjZmZmEwZWIxLWJiZDItNDBmMi05ZTQ1LWZjYTI3N2U5ODE0MyIsInVybCI6Imh0dHBzOi8vd3d3Lndhc2hpbmd0b25wb3N0LmNvbS90ZWNobm9sb2d5LzIwMjQvMDUvMzAvb3BlbmFpLWRpc2luZm8taW5mbHVlbmNlLW9wZXJhdGlvbnMtY2hpbmEtcnVzc2lhLyJ9.lZy8-t9Wf1mDTHueMt7j0kCTV8XAifSEbK8hmsBd3bk
31/05/2024 08:02:03
QRCode
archive.org
thumbnail

Covert propagandists have already begun using generative artificial intelligence to boost their influence operations.

washingtonpost EN 2024 OpenAI chatgpt China Russia propaganda
CVE-2024-34331: Parallels Repack Privilege Escalation https://khronokernel.com/macos/2024/05/30/CVE-2024-34331.html
30/05/2024 19:50:15
QRCode
archive.org

Another day, another accidental exploit 🥳. This time abusing Parallels Desktop’s trust in macOS installers, gaining local privilege escalation!

khronokernel EN 2024 Parallels Repack Privilege Escalation CVE-2024-34331
page 95 / 235
4695 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio