Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

August 24, 2023

Ransomware infection wipes all CloudNordic servers

IT outfit says it can't — and won't — pay the ransom demand

Fake Roblox packages target npm with Luna Grabber information-stealing malware

ReversingLabs researchers have identified more than a dozen malicious packages targeting Roblox API users on the npm repository. This latest campaign recalls a 2021 attack.

Genève: Un élu a farfouillé sans droit dans les fichiers de la justice

Le conseiller administratif d’une petite commune a été condamné pour violation du secret de fonction. Il avait utilisé son emploi au Pouvoir judiciaire pour se renseigner au sujet d’une plainte pénale.

WinRAR 0-day that uses poisoned JPG and TXT files under exploit since April | Ars Technica

Vulnerability allows hackers to execute malicious code when targets open malicious ZIP files.

Using WinRAR? Be sure to patch against these code execution bugs… – Naked Security

Imagine if you clicked on a harmless-looking image, but an unknown application fired up instead…

#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation

This blog is based on a session we presented at DEF CON 2023 on Sunday, August 13, 2023, in Las Vegas. Privilege escalation is a common attack vector in the Windows OS. There are multiple offensive tools in the wild that can execute code as “NT AUTHORITY\SYSTEM” (Meterpreter, CobaltStrike, Potato tools), and they all usually do so by duplicating tokens and manipulating services. This allows them to perform attacks like LSASS Shtinkering.