Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

May 31, 2023

Swiss real estate agency fails to put a password on its systems
  • A misconfiguration of Swiss real estate agency Neho’s systems exposed sensitive credentials to the public.
  • Using leaked data, threat actors could potentially breach the company’s internal systems and hijack official communication channels.
  • Real estate agencies handle sensitive data, including customers' personally identifiable information, bank account details, and other data highly valued by cybercriminals. Ensuring cybersecurity is vital.
  • Cybernews reached out to Neho and the company fixed the issue.
Millions of Gigabyte Motherboards Were Sold With a Firmware Backdoor | WIRED

Hidden code in hundreds of models of Gigabyte motherboards invisibly and insecurely downloads programs—a feature ripe for abuse, researchers say.

2023-05-31 // SITUATIONAL AWARENESS // Spyboy Defense Evasion Tool Advertised Online

On May 21, 2023, an online persona named spyboy began advertising an endpoint defense evasion tool for the Windows operating system via the Russian-language forum Ramp. The author claims that the software — seen in a demonstration video as being titled “Terminator” — can bypass twenty three (23) EDR and AV controls. At time of writing, spyboy is pricing the software from $300 USD (single bypass) to $3,000 USD (all-in-one bypass).

EDR bypassing via memory manipulation techniques | WithSecure™ Labs

Endpoint Detection & Response systems (EDR),
delivered by in-house teams or as part of a managed
service, are a feature of modern intrusion detection
and remediation operations. This success is a problem
for attackers, and malicious actors have worked to
find new ways to evade EDR detection capabilities.

PDF Document

Iranian dissidents take over high-security servers of regime presidency |

A group of Iranian dissidents, self-described as “GhyamSarnegouni” (meaning "Rise to Overthrow" in Farsi), has claimed responsibility for taking control