Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

July 20, 2023

Threat Actors Add .zip Domains to Their Phishing Arsenals

In the evolving cybersecurity landscape, understanding the phishing threat has become more critical than ever. Read into a new threat resulting from the addition of a new Top-Level Domain (TLD), '.ZIP'.

JumpCloud says 'nation state' gang hit some customers

JumpCloud says a "sophisticated nation-state" attacker broke into its IT systems and targeted some of its customers.

The identity and access management provider, particularly popular with sysadmins wrangling Macs on corporate networks, said it first discovered signs of an intrusion on June 27. The biz at the time determined persons unknown got "unauthorized access to a specific area of our infrastructure" using a "sophisticated spear-phishing campaign" that began five days prior.

CVE-2023-38408: Remote Code Execution in OpenSSH’s forwarded ssh-agent

The Qualys Threat Research Unit (TRU) has discovered a remote code execution vulnerability in OpenSSH's forwarded ssh-agent. This vulnerability allows a remote…