Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
8 résultats taggé Vulnerable  ✕
Apple's Passwords app was vulnerable to phishing attacks for nearly three months after launch https://9to5mac.com/2025/03/18/apples-passwords-app-was-vulnerable-to-phishing-attacks-for-nearly-three-months-after-launch/?ref=metacurity.com
19/03/2025 21:02:20
QRCode
archive.org

In iOS 18, Apple spun off its Keychain password management tool—previously only tucked away in Settings—into a standalone app called...

9to5mac EN 2025 iOS apple passwords http app vulnerable phishing Keychain
“Dirty stream” attack: Discovering and mitigating a common vulnerability pattern in Android apps https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/
03/05/2024 09:16:14
QRCode
archive.org
thumbnail

Microsoft discovered a vulnerability pattern in multiple popular Android applications that could enable a malicious application to overwrite files in the vulnerable application’s internal data storage directory, which could lead to arbitrary code execution and token theft, among other impacts. We have shared our findings with Google’s Android Application Security Research team, as well as the developers of apps found vulnerable to this issue. We anticipate that the vulnerability pattern could be found in other applications. We’re sharing this research more broadly so developers and publishers can check their apps for similar issues, fix as appropriate, and prevent them from being introduced into new apps or releases.

microsoft EN 2024 Android vulnerable application share Dirty-stream
Thousands of Ivanti VPN Appliances Impacted by Recent Vulnerability https://www.securityweek.com/thousands-of-ivanti-vpn-appliances-impacted-by-recent-vulnerability/
14/04/2024 15:35:21
QRCode
archive.org

The Shadowserver Foundation identifies thousands of Ivanti VPN instances likely impacted by a recent remote code execution flaw.

securityweek EN 2024 Shadowserver Ivanti VPN CVE-2024-21894 vulnerable
One in four apps remain exposed to Log4Shell https://www.theregister.com/2023/12/11/log4j_vulnerabilities/
12/12/2023 19:58:36
QRCode
archive.org
thumbnail

Two years after the Log4Shell vulnerability in the open source Java-based Log4j logging utility was disclosed, circa one in four applications are dependent on outdated libraries, leaving them open to exploitation.

Research from security shop Veracode revealed that the vast majority of vulnerable apps may never have updated the Log4j library after it was implemented by developers as 32 percent were running pre-2015 EOL versions.

theregister EN 2023 Log4Shell Log4j Veracode outdated vulnerable
Kazakhstan - the world's last SSLv2 superpower... and a country with potentially vulnerable last-mile internet infrastructure https://isc.sans.edu/diary/29988
28/06/2023 11:46:14
QRCode
archive.org

Kazakhstan - the world's last SSLv2 superpower... and a country with potentially vulnerable last-mile internet infrastructure, Author: Jan Kopriva

sans EN 2023 Kazakhstan SSLv2 vulnerable internet
ALPHV Ransomware Affiliate Targets Vulnerable Backup Installations to Gain Initial Access https://www.mandiant.com/resources/blog/alphv-ransomware-backup
08/04/2023 01:09:27
QRCode
archive.org
thumbnail

A ransomware affiliate is targeting publicly exposed Veritas installations to gain access to organizations.

mandiant EN 2023 ALPHV Ransomware Affiliate Vulnerable Backup Veritas
Pulse Connect Secure: A View from the Internet https://censys.io/pulse-connect-secure-a-view-from-the-internet/
10/12/2022 22:46:22
QRCode
archive.org
thumbnail

Pulse Connect Secure is a low-cost and widely-deployed SSL VPN solution for remote and mobile users. Over the years, researchers have found several significant vulnerabilities in the server software, some even resulting in the active exploitation of critical infrastructure by malicious threat actors. In April of 2021, CISA released a report detailing some of these activities, which included exploiting several unknown (at the time) vulnerabilities and resulted in swift action from Ivanti, the Pulse Connect Secure software developer.

censys EN 2022 PulseConnectSecure VPN vulnerable CVE-2021-22893
Over 18.8 million IPs vulnerable to Middlebox TCP reflection DDoS attacks https://www.shadowserver.org/news/over-18-8-million-ips-vulnerable-to-middlebox-tcp-reflection-ddos-attacks/
02/06/2022 11:08:35
QRCode
archive.org

We recently began scanning for middlebox devices that are vulnerable to Middlebox TCP reflection, which can be abused for DDoS amplification attacks.  Our results are now shared daily, filtered for your network or constituency in the new Vulnerable DDoS Middlebox report. We uncover over 18,800,000 IPv4 addresses responding to our Middlebox probes. In some cases the amplification rates can exceed 10,000!

shadowserver 2022 EN DDoS Vulnerable Middlebox attacks internet monitoring
4259 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio