Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

October 14, 2024

Fortinet FortiGate CVE-2024-23113 - A Super Complex Vulnerability In A Super Secure Appliance In 2024

It affected (before patching) all currently-maintained branches, and recently was highlighted by CISA as being exploited-in-the-wild.

This must be the first time real-world attackers have reversed a patch, and reproduced a vulnerability, before some dastardly researchers released a detection artefact generator tool of their own. /s

At watchTowr's core, we're all about identifying and validating ways into organisations - sometimes through vulnerabilities in network border appliances - without requiring such luxuries as credentials or asset lists.

New Google Project Aims to Become Global Clearinghouse for Scam, Fraud Data

Google launches Global Signal Exchange (GSE), an initiative aimed at fostering the sharing of online fraud and scam intelligence.

MITRE Announces AI Incident Sharing Project

MITRE’s AI Incident Sharing initiative helps organizations receive and hand out data on real-world AI incidents.
Non-profit technology and R&D company MITRE has introduced a new mechanism that enables organizations to share intelligence on real-world AI-related incidents.

Shaped in collaboration with over 15 companies, the new AI Incident Sharing initiative aims to increase community knowledge of threats and defenses involving AI-enabled systems.

iPhone Mirroring Exposes Employees' Personal Applications

The iPhone Mirroring feature in macOS Sequoia and iOS 18 may expose employees’ private applications to corporate IT environments.

Gamers Tricked Into Downloading Lua-Based Malware via Fake Cheating Script Engines

Gamers searching for game cheats are falling victim to a global malware campaign delivering RedLine Stealer.

Neo-Nazis head to encrypted SimpleX Chat app, bail on Telegram

App swears there’s no way for law enforcement to track users’ identities.

CTV industry’s unprecedented “surveillance”

48-page report citing Ars Technica urges FTC, FCC investigate connected TV data harvesting. Gen AI, potentially racially discrimniatory practices head concerns.

Ukrainian pleads guilty to operating Raccoon Stealer malware

Ukrainian national Mark Sokolovsky has pleaded guilty to his involvement in the Raccoon Stealer malware-as-a-service (MaaS) cybercrime operation.

Dutch police arrest admin of 'Bohemia/Cannabia' dark web market

An international law enforcement operation led to the arrest of one of the three administrators of the dual dark web market 'Bohemia/Cannabia,' known for hosting ads for drug sales and distributed denial of service (DDoS) attacks.

Personal Information Compromised in Universal Music Data Breach

Universal Music Group is informing hundreds of individuals about a recent data breach impacting personal information.

MoneyGram says hackers stole customers' personal information and transaction data | TechCrunch

The money transfer giant said hackers also stole some customer Social Security numbers during the September cyberattack.

1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies

1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies - zendesk.md

Telekopye transitions to targeting tourists via hotel booking scam

ESET Research shares new findings about Telekopye, a scam toolkit used to defraud people on online marketplaces, and newly on accommodation booking platforms.

Pokemon developer Game Freak hit with hack, internal info leaking

Pokemon developer Game Freak hit with big hack, leaking source code news about MMO-like game Synapse with ILCA, and more.

UK Ambulance Services targeted by Kremlin-protected Russian hackers

A cyber security expert warns the hack, uncovered by i, presents a 'terrible threat to public health safety'

Hackers Advertise Stolen Verizon Push-to-Talk ‘Call Logs’

The breach does not appear to impact the main consumer Verizon network, and instead involves the company’s push to talk (PTT) product, marketed to public sector agencies and enterprises.