Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 98 / 213
4253 résultats taggé E*N  ✕
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining - Avast Threat Labs https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/
23/04/2024 13:39:01
QRCode
archive.org
thumbnail

Avast discovered and analyzed GuptiMiner, a malware campaign hijacking an eScan antivirus update mechanism to distribute backdoors and coinminers.

avast EN 2024 GuptiMiner: research Hijacking Antivirus Updates
Siemens Industrial Product Impacted by Exploited Palo Alto Firewall Vulnerability https://www.securityweek.com/siemens-industrial-product-impacted-by-exploited-palo-alto-firewall-vulnerability/
23/04/2024 13:06:28
QRCode
archive.org

The recently disclosed Palo Alto Networks firewall vulnerability tracked as CVE-2024-3400, which has been exploited in attacks for at least one month, has been found to impact one of Siemens’ industrial products.

In an advisory published late last week, Siemens revealed that its Ruggedcom APE1808 devices configured with a Palo Alto Networks virtual next-generation firewall (NGFW) could be affected by CVE-2024-3400.

securityweek EN 2024 CVE-2024-3400 Palo Alto Networks firewall Siemens IoT
How a Massive Hack of Psychotherapy Records Revealed a Nation’s Secrets https://www.bloomberg.com/news/features/2024-04-22/a-massive-therapy-hack-shows-just-how-unsafe-patients-files-can-be?leadSource=uverify%20wall
23/04/2024 11:28:26
QRCode
archive.org
thumbnail

Aleksanteri Kivimäki was a hacker wunderkind with a mean streak. Now he’s on trial for the largest crime in Finland’s history.

bloomberg EN 2024 Criminal Finland Kivimäki
CVE-2024-20356: a Cisco appliance to run DOOM https://labs.nettitude.com/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom/
23/04/2024 11:07:42
QRCode
archive.org
thumbnail

Exploiting remote code execution in Cisco's CIMC management system and jailbreaking the device to run untrusted code

nettitude EN 2024 CVE-2024-20356 DOOM Jailbreaking CIMC analysis
DDoS platform shut down by international law enforcement agencies https://www.heise.de/en/news/DDoS-platform-shut-down-by-international-law-enforcement-agencies-9691209.html
23/04/2024 10:35:42
QRCode
archive.org
thumbnail

International law enforcement authorities have shut down a DDoS-as-a-service platform and seized its domain.

heise EN 2024 Beschlagnahme Cybercrime DDoS DDoS-as-a-service PowerOFF Security stresser.tech
Hackers Broke Into Change Healthcare’s Systems Days Before Cyberattack https://www.wsj.com/articles/change-healthcare-hackers-broke-in-nine-days-before-ransomware-attack-7119fdc6?st=f8jgsar36jvj533
23/04/2024 07:48:39
QRCode
archive.org

UnitedHealth Group paid ransom to hackers, person familiar with the cyber investigation says

wsj EN 2024 change-healthcare UnitedHealth Cyberattack intrusion
Microsoft: APT28 hackers exploit Windows flaw reported by NSA https://www.bleepingcomputer.com/news/security/microsoft-apt28-hackers-exploit-windows-flaw-reported-by-nsa/#google_vignette
22/04/2024 20:08:32
QRCode
archive.org
thumbnail

Microsoft warns that the Russian APT28 threat group exploits a Windows Print Spooler vulnerability to escalate privileges and steal credentials and data using a previously unknown hacking tool called GooseEgg.
#APT28 #Computer #Credential #Escalation #Exploit #GooseEgg #InfoSec #NSA #Print #Privilege #Security #Spooler #Theft #Windows

bleepingcomputer EN 2024 NSA Spooler Print Theft Escalation Credential Windows Privilege GooseEgg Exploit APT28
Unauthenticated function injection vulnerability in WordPress Shortcode Addons plugin (unpatched). – NinTechNet https://blog.nintechnet.com/unauthenticated-function-injection-vulnerability-in-wordpress-shortcode-addons-plugin-unpatched/
22/04/2024 06:54:05
QRCode
archive.org
thumbnail

The WordPress Shortcode Addons plugin version 3.2.5 and below is prone to an unauthenticated function injection vulnerability.

nintechnet EN 2024 WordPress Shortcode Addons plugin vulnerability
‘Large volume’ of data stolen from UN agency after ransomware attack https://cyberscoop.com/undp-data-stolen-ransomware/
21/04/2024 20:53:08
QRCode
archive.org
thumbnail

The attack is just the latest in a string targeting the multilateral body in recent years.

cyberscoop EN 2024 UN agency UNDP Copenhagen
MITRE says state hackers breached its network via Ivanti zero-days https://www.bleepingcomputer.com/news/security/mitre-says-state-hackers-breached-its-network-via-ivanti-zero-days/
21/04/2024 20:51:39
QRCode
archive.org
thumbnail

The MITRE Corporation says a state-backed hacking group breached its systems in January 2024 by chaining two Ivanti VPN zero-days.

bleepingcomputer EN 2024 Breach Ivanti MITRE Zero-Day Security InfoSec Computer-Security
LastPass Users Lose Master Passwords to Ultra-Convincing Scam https://www.darkreading.com/cyberattacks-data-breaches/lastpass-users-lose-master-passwords-ultra-convincing-scam
21/04/2024 20:44:24
QRCode
archive.org
thumbnail

CryptoChameleon attackers trade quantity for quality, dedicating time and resources to trick even the most diligent into handing over their high-value credentials.

darkreading EN 2024 CryptoChameleon LastPass scam
Ransomware payments drop to record low of 28% in Q1 2024 https://www.bleepingcomputer.com/news/security/ransomware-payments-drop-to-record-low-of-28-percent-in-q1-2024/
21/04/2024 20:42:03
QRCode
archive.org
thumbnail

Ransomware actors have had a rough start this year, as stats from cybersecurity firm Coveware show that the trend of victims declining to pay the cybercriminals continues and has now reached a new record low of 28%.

bleepingcomputer EN 2024 Cybercrime Extortion Law-Enforcement Ransom Ransomware stats
‘The machine did it coldly’: Israel used AI to identify 37,000 Hamas targets https://www.theguardian.com/world/2024/apr/03/israel-gaza-ai-database-hamas-airstrikes
21/04/2024 20:31:12
QRCode
archive.org
thumbnail

Israeli intelligence sources reveal use of ‘Lavender’ system in Gaza war and claim permission given to kill civilians in pursuit of low-ranking militants

theguardian EN 2024 Lavender AI war bombing kill
Hackers are threatening to leak World-Check, a huge sanctions and financial crimes watchlist | TechCrunch https://techcrunch.com/2024/04/18/world-check-database-leaked-sanctions-financial-crimes-watchlist/
20/04/2024 09:58:04
QRCode
archive.org
thumbnail

A financially motivated criminal hacking group says it has stolen a confidential database containing millions of records that companies use for screening potential customers for links to sanctions and financial crime.

The hackers, which call themselves GhostR, said they stole 5.3 million records from the World-Check screening database in March and are threatening to publish the data online.

techcrunch EN 2024 GhostR stolen confidential database World-Check financial crime.
China Orders Apple to Remove Popular Messaging Apps https://www.wsj.com/tech/apple-removes-whatsapp-threads-from-china-app-store-on-government-orders-a0c02100?st=mjijkzg2og31ug5&reflink=desktopwebshare_permalink
20/04/2024 09:54:09
QRCode
archive.org

WhatsApp, Signal and Telegram among apps cut from iPhone app store to comply with censorship demand

wsj EN 2024 WhatsApp Signal Telegram apple remove AppStore China censorship
'Crude' ransomware tools proliferating on the dark web for cheap, researchers find https://therecord.media/cheap-ransomware-for-sale-dark-web
20/04/2024 09:38:42
QRCode
archive.org
thumbnail

Cheap ransomware is being sold for one-time use on dark web forums, allowing inexperienced freelancers to get into cybercrime without any interaction with affiliates.

Researchers at the intelligence unit at the cybersecurity firm Sophos found 19 ransomware varieties being offered for sale or advertised as under development on four forums from June 2023 to February 2024.

therecord EN 2024 Crude Sophos ransomware tools DarkWeb
Ransomware attack has cost UnitedHealth $872 million; total expected to surpass $1 billion https://therecord.media/ransomware-unitedhealth-costs-billions-still-climbing?_hsenc=p2ANqtz-_NXHMTMofLbyaVNJ3kRdE2p0pM0usepgEV5vo9-YtsvtStuDxwMKTaOTeKMbd68ggASIMwjDEVxSEsUTcKeFlD-lWmgw&_hsmi=303475837
20/04/2024 09:35:27
QRCode
archive.org
thumbnail

he ransomware attack on a company owned by healthcare giant UnitedHealth Group (UHG) has so far caused $872 million in losses, according to the corporation’s latest earnings report.

UnitedHealth owns Change Healthcare, a key cog in the U.S. healthcare industry that was crippled by a ransomware attack in February. Change Healthcare and UHG subsidiary Optum took hundreds of systems offline as a result of the incident and faced criticism from the White House and Congress over its handling of the ransomware attack.

therecord EN 2024 UnitedHealth cost ransomware change-healthcare
Cisco: Hacker breached multifactor authentication message provider on April 1 https://therecord.media/cisco-duo-data-breach-mfa-telephony-provider?_hsenc=p2ANqtz-9wele4oTF0tDrlbVagSSLRHrkFVta-UiNnzNSZJ5tq6X9qHse_aGaXTU1xX_tC1ttQebQSUZbMCYg3kqq1TxhkgpIrFg&_hsmi=303475837
20/04/2024 09:34:13
QRCode
archive.org
thumbnail

Cisco said one of the providers it uses to send multifactor authentication (MFA) messages was breached by a threat actor on April 1.

In emails to customers, Cisco said the incident specifically affected Duo — a multifactor authentication company it acquired in 2018. The attacker breached the system of a telephony supplier that Duo uses to send MFA messages through texts and phone calls to its customers.

therecord EN 2024 Cisco breached multifactor authentication duo
The Fall of LabHost: Law Enforcement Shuts Down Phishing Service Provider | Trend Micro (US) https://www.trendmicro.com/en_us/research/24/d/labhost-takedown.html?ref=news.risky.biz
19/04/2024 07:10:16
QRCode
archive.org
thumbnail

On Thursday, April 18, 2024, the UK’s Metropolitan Police Service, along with fellow UK and international law enforcement, as well as several trusted private industry partners, conducted an operation that succeeded in taking down the Phishing-as-a-Service (PhaaS) provider LabHost. This move was also timed to coincide with a number of key arrests related to this operation. In this entry, we will briefly explain what LabHost was, how it affected its victims, and the impact of this law enforcement operation — including the assistance provided by Trend Micro.

trendmicro EN 2024 cybercrime report LabHost takedown PhaaS Phishing-as-a-Service
New Backdoor, MadMxShell https://www.zscaler.com/blogs/security-research/malvertising-campaign-targeting-it-teams-madmxshell
18/04/2024 22:06:32
QRCode
archive.org
thumbnail

Beginning in March of 2024, Zscaler ThreatLabz observed a threat actor weaponizing a cluster of domains masquerading as legitimate IP scanner software sites to distribute a previously unseen backdoor. The threat actor registered multiple look-alike domains using a typosquatting technique and leveraged GoogleAds to push these domains to the top of search engine results targeting specific search keywords, thereby luring victims to visit these sites.

The newly discovered backdoor uses several techniques such as multiple stages of DLL sideloading, abusing the DNS protocol for communicating with the command-and-control (C2) server, and evading memory forensics security solutions. We named this backdoor “MadMxShell” for its use of DNS MX queries for C2 communication and its very short interval between C2 requests.

zscaler EN 2024 typosquatting MadMxShell GoogleAds DNS Malvertising Advance-ip-scanner
page 98 / 213
4836 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn