Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

January 15, 2024

Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows

Critical security flaw found in Opera Browsers. MyFlow sync feature lets attackers take over your Windows and macOS systems.

Chrome Users Now Worth 30% Less Money Thanks to Google's Cookie Killing, Ad Firm Says

A week into phase one of Google’s cookie killing project in Chrome, early tests show how it could hit the web’s bottom line.

Framework Data Breach - General Topics - Framework Community

Copypasta’d from an email from FW:

Hello,
Keating Consulting, Framework’s primary external accounting partner, brought to our attention at 8:13am PST on January 11th, 2024, that one of their accountants fell victim to…

Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days

SecurityScorecard has discovered the threat actor group Volt Typhoon has compromised 30% of Cisco RV320/325 Devices in 37 Days. Learn more.

Welcome To 2024, The SSLVPN Chaos Continues - Ivanti CVE-2023-46805 & CVE-2024-21887

Did you have a good break? Have you had a chance to breathe? Wake up.

It’s 2024, and the chaos continues - thanks to Volexity (Volexity’s writeup), the industry has been alerted to in-the-wild exploitation of 2 incredibly serious 0days (CVE-2023-46805 and CVE-2024-21887 - two bugs, Command Injection

Further analysis of Denmark attacks leads to warning about unpatched network gear

What happened in Denmark can also happen to you, cybersecurity researchers are warning in a new report that examines attacks against the country’s energy sector last year.

Waves of incidents in May that seemed like a highly-targeted effort by a nation-state actor — perhaps Russia’s Sandworm hacking group — might have been less connected than originally thought, according to a new report by Forescout.

The researchers say their analysis found two distinct waves against Danish energy providers, and evidence suggests they were unrelated.

QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products

QNAP has released patches for a dozen vulnerabilities in its products, including several high-severity flaws.

Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer

Beware of YouTube videos offering cracked software! They might be a gateway to the Lumma malware, stealing your sensitive information

Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the Globe

Turkish hackers targeting poorly secured MS SQL servers across the U.S., European Union, and Latin America.

ShinyHunters member gets 3 years in prison for breaching 60 firms

The U.S. District Court in Seattle sentenced ShinyHunters member Sebastien Raoult to three years in prison and ordered a restitution of $5,000,000.
#Broker #Computer #Customer #Data #Hackers #InfoSec #Legal #Prison #Security #ShinyHunters #Theft

Turkish hackers targeting database servers with Mimic ransomware

The “RE#TURGENCE” campaign is targeting victims in the E.U., U.S. and Latin America by going after Microsoft SQL, researchers with Securonix found.

Anthropic researchers find that AI models can be trained to deceive

A study co-authored by researchers at Anthropic finds that AI models can be trained to deceive -- and that this deceptive behavior is difficult to combat.