Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 98 / 205
4100 résultats taggé EN  ✕
New ZenHammer memory attack impacts AMD Zen CPUs https://www.bleepingcomputer.com/news/security/new-zenhammer-memory-attack-impacts-amd-zen-cpus/
26/03/2024 10:03:09
QRCode
archive.org
thumbnail

Academic researchers developed ZenHammer, the first variant of the Rowhammer DRAM attack that works on CPUs based on recent AMD Zen microarchitecture that map physical addresses on DDR4 and DDR5 memory chips.

bleepingcomputer EN 2024 AMD CPU Hardware Memory RAM Rowhammer ZenHammer
Why X86 Needs To Die https://hackaday.com/2024/03/21/why-x86-needs-to-die/
26/03/2024 09:59:32
QRCode
archive.org
thumbnail

As I'm sure many of you know, x86 architecture has been around for quite some time. It has its roots in Intel's early 8086 processor, the first in the family. Indeed, even the original 8086 inherits a...

hackaday EN 2024 X86
ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms https://comsec.ethz.ch/research/dram/zenhammer/
26/03/2024 09:57:53
QRCode
archive.org

Our work shows that it is possible to trigger Rowhammer bit flips on DDR4 devices on AMD Zen 2 and Zen 3 systems despite deployed TRR mitigations. This result proves that AMD systems are equally vulnerable to Rowhammer as Intel systems, which greatly increases the attack surface, considering today’s AMD market share of around 36%… Read

ETHZ EN 2024 ZenHammer Rowhammer DDR4 AMD Zen2 Zen3 attack study
Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/
26/03/2024 09:09:23
QRCode
archive.org
thumbnail

Tycoon 2FA has become one of the most widespread adversary-in-The-Middle (AiTM) phishing kits over the last few months.

sekoia EN 2024 Tycoon2FA phishing PhaaS AiTM phishing-kit analysis
Deactivating Cortex XDR via repair function https://badoption.eu/blog/2024/03/23/cortex.html
26/03/2024 08:37:51
QRCode
archive.org

It is trivially possible to disable the Cortex EDR as a non-admin user by triggering a repair function. This is only working, if the Tamper Protection is not enforced! TL;DR; Trigger the repair via GUID Disrupt it when EDR is deactivated Done

badoption EN 2024 Cortex EDR non-admin installer repair Paloalto
Release: VM Escape Exploit for Parallels Desktop Hypervisor (Pwn2Own 2021) https://zerodayengineering.com/research/pwn2own-2021-vm-escape.html
25/03/2024 19:11:13
QRCode
archive.org

In April 2021 I participated in Pwn2Own Vancouvver competition as a single player, and successfully demonstrated a 0-day virtual machine escape exploit with code execution on Parallels hypervisor. Today I am finally releasing the exploit source code together with a technical walkthrough video talk that I gave on Zero Day Engineering livestream in November 2021.

zerodayengineering EN 2024 exploit 2021 0-day Parallels Pwn2Own VM escape
Over 170K users hit by poisoned Python package ruse https://www.theregister.com/2024/03/25/python_package_malware/
25/03/2024 19:08:21
QRCode
archive.org
thumbnail

Supply chain attack targeted GitHub community of Top.gg Discord server

theregister EN 2024 Top.gg GitHub Supply-chain-attack Python
New Go loader pushes Rhadamanthys stealer https://www.malwarebytes.com/blog/threat-intelligence/2024/03/new-go-loader-pushes-rhadamanthys
25/03/2024 18:53:17
QRCode
archive.org
thumbnail

A malicious ad for the popular admin tool PuTTY leads victims to a fake site that downloads malware.

malwarebytes EN 2024 PuTTY malicious fake Go Rhadamanthys
APT29 Uses WINELOADER to Target German Political Parties | Mandiant https://www.mandiant.com/resources/blog/apt29-wineloader-german-political-parties
25/03/2024 09:14:30
QRCode
archive.org
thumbnail

APT29 used a new backdoor variant publicly tracked as WINELOADER to target German political parties.

mandiant EN 2024 report APT29 backdoor WINELOADER German Political Parties Germany
China blocks use of Intel and AMD chips in government computers, FT reports https://www.reuters.com/world/china/china-blocks-use-intel-amd-chips-government-computers-ft-reports-2024-03-24/
25/03/2024 09:08:53
QRCode
archive.org

China has introduced guidelines to phase out U.S. microprocessors from Intel (INTC.O), opens new tab and AMD (AMD.O), opens new tab from government personal computers and servers, the Financial Times reported on Sunday.
The procurement guidance also seeks to sideline Microsoft's (MSFT.O), opens new tab Windows operating system and foreign-made database software in favour of domestic options, the report said.

reuters EN 2024 AMD Intel China government block guidance
Air Europa says customer data may have been compromised in October breach https://www.reuters.com/technology/cybersecurity/iag-flags-air-europas-customers-personal-data-leak-wsj-reports-2024-03-21/
25/03/2024 06:50:59
QRCode
archive.org

Spanish airline Air Europa (ICAG.L), opens new tab said on Friday personal data of its customers may have been compromised in a security incident that was detected in October last year.
The company's investigation showed that name, ID card or passport details, date of birth, telephone number, email address and nationality details could have been leaked, Air Europa told its customers in an email that was seen by Reuters.

reuters EN 2024 Air-Europa PI customer data-breach leak
IMF Investigates Cyber-Security Incident https://www.imf.org/en/News/Articles/2024/03/15/pr2488-imf-investigates-cyber-security-incident
23/03/2024 21:25:52
QRCode
archive.org
thumbnail

The International Monetary Fund (IMF) recently experienced a cyber incident, which was detected on February 16, 2024.

imf.org EN 2024 IMF cyber incident statement breach emails
Change Healthcare ransomware attack disrupting industry nationwide https://www.scmagazine.com/news/change-healthcare-ransomware-attack-disrupting-industry-nationwide?is=09685296f9ea1fb2ee0963f2febaeb3a55d8fb1eddbb11ed4bd2da49d711f2c7
23/03/2024 10:25:18
QRCode
archive.org
thumbnail

The reports keep coming in from across the country on how the Change Healthcare ransomware attack that first came to light on Feb. 21 has been impacting the healthcare sector.

The case has been called the most severe cyberattack on the healthcare sector in history and has had a great impact since Change Healthcare, owned by UnitedHealth Group, processes 15 billion healthcare transactions annually, affecting 1 in 3 patient records.

scmagazine EN 2024 ransomware healthcare Change-Healthcare US
Darknet marketplace Nemesis Market seized by German police https://www.bleepingcomputer.com/news/security/darknet-marketplace-nemesis-market-seized-by-german-police/
22/03/2024 17:21:23
QRCode
archive.org
thumbnail

The German police have seized infrastructure for the darknet Nemesis Market cybercrime marketplace in Germany and Lithuania, disrupting the site's operation.

bleepingcomputer EN 2024 Nemesis Germany Seizure Darknet Takedown BKA Market
Large-Scale StrelaStealer Campaign in Early 2024 https://unit42.paloaltonetworks.com/strelastealer-campaign/
22/03/2024 12:15:51
QRCode
archive.org
thumbnail

We unravel the details of two large-scale StrelaStealer campaigns from 2023 and 2024. This email credential stealer has a new variant delivered through zipped JScript.
#2024 #Campaign #EN #JScript #StrelaStealer #analysis #paloaltonetworks

analysis EN 2024 JScript paloaltonetworks StrelaStealer Campaign
Google Online Security Blog: Vulnerability Reward Program: 2023 Year in Review https://security.googleblog.com/2024/03/vulnerability-reward-program-2023-year.html
22/03/2024 12:13:50
QRCode
archive.org
thumbnail

Last year, we again witnessed the power of community-driven security efforts as researchers from around the world contributed to help us identify and address thousands of vulnerabilities in our products and services. Working with our dedicated bug hunter community, we awarded $10 million to our 600+ researchers based in 68 countries.

security.googleblog EN 2024 reward bug-bounty Google 2023 year
The iSOON Disclosure: Exploring the Integrated Operations Platform https://bishopfox.com/blog/the-isoon-disclosure-exploring-the-integrated-operations-platform
22/03/2024 09:14:22
QRCode
archive.org
thumbnail

Bishop Fox examines the iSoon data disclosure from an offensive security perspective and an analysis of the platform's capabilities, design, features.

Bishop-Fox bishopfox EN 2024 iSOON Integrated Operations Platform China analysis
Ransomware Recruitment Efforts Following Law Enforcement Disruption https://www.guidepointsecurity.com/blog/t-o-x-i-n-b-i-o-ransomware-recruitment-efforts-following-law-enforcement-disruption/
22/03/2024 09:06:54
QRCode
archive.org
thumbnail

In late 2023 and early 2024, the ransomware ecosystem experienced repeated disruption of its most prolific Ransomware-as-a-Service (RaaS) groups at the hands of international Law Enforcement (LE). Alphv’s dark web data leak site was seized, then unseized, then re-seized in a December 2023 law enforcement operation that seemingly failed to deter the group – until AlphV ultimately claimed to disband via an apparent exit scam, immediately following a high-profile attack against Change Healthcare in March 2024. LockBit experienced a far more dramatic and well-marketed disruption, “Operation Cronos,” in February 2024, leading to the compromise of its infrastructure, internal operational details, and data. While LockBit has ostensibly continued operations, its highly publicized disruption raises the question of whether the group will be able to continue operating and attracting affiliates at the level they once enjoyed.

guidepointsecurity EN 2024 Ransomware Recruitment Disruption Operation-Cronos
Trezor X Account Hacked, Shills Fake Crypto https://www.ccn.com/news/trezor-account-hacked-shills-fake-crypto/
22/03/2024 08:56:29
QRCode
archive.org
  • Trezor’s official X account was compromised, likely due to a SIM swap attack, and used to promote a fake token presale.
  • ZachXBT and crypto security firm Scam Sniffer identified the fraudulent activity, preventing wider user losses.
  • Despite compromising Trezor’s account, the hacker only managed to steal a paltry $8,100.
ccn EN 2024 twitter X Trezor SIM-swapping Crypto Account
Apple Sued for Prioritizing Market Dominance Over Security https://www.databreachtoday.eu/apple-sued-for-prioritizing-market-dominance-over-security-a-24687
22/03/2024 08:29:41
QRCode
archive.org
thumbnail

The U.S. Department of Justice in a lawsuit filed Thursday is accusing Apple of discarding user security and privacy protections as part of a broader effort to

databreachtoday EN 2024 Apple Apple-lawsuit DOJ security privacy dominance
page 98 / 205
4677 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio