Quotidien Hebdomadaire Mensuel

Hebdomadaire Shaarli

Tous les liens d'un semaine sur une page.

Semaine 20 (May 15, 2023)

Apple Restricts Employee Use of ChatGPT, Joining Other Companies Wary of Leaks

The iPhone maker is concerned workers could release confidential data as it develops its own similar technology.

Popular Android TV boxes sold on Amazon are laced with malware

The malware-infected AllWinner and RockChip-powered Android TV models are still available to purchase on Amazon.

MalasLocker ransomware targets Zimbra servers, demands charity donation

A new ransomware operation is hacking Zimbra servers to steal emails and encrypt files. However, instead of demanding a ransom payment, the threat actors claim to require a donation to charity to provide an encryptor and prevent data leaking.

Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices

An overview of the Lemon Group’s use of preinfected mobile devices, and how this scheme is potentially being developed and expanded to other internet of things (IoT) devices. This research was presented in full at the Black Hat Asia 2023 Conference in Singapore in May 2023.

Visualizing QakBot Infrastructure

This blog post seeks to draw out some high-level trends and anomalies based on our ongoing tracking of QakBot command and control (C2) infrastructure. By looking at the data with a broader scope, we hope to supplement other research into this particular threat family, which in general focuses on specific infrastructure elements; e.g., daily alerting on active C2 servers.

“FleeceGPT” mobile apps target AI-curious to rake in cash

Interest in OpenAI’s latest version of its interactive language model has spurred a new wave of scam apps looking to cash in on the hype

KeePass flaw allows retrieval of master password, PoC is public (CVE-2023-32784)

A vulnerability (CVE-2023-32784) in KeePass can be exploited to retrieve the master password from the software's memory.

GitHub - vdohney/keepass-password-dumper

The vulnerability was assigned CVE-2023-32784. It should be fixed in KeePass 2.54, which should come out in ~July 2023. Thanks again to Dominik Reichl for his fast response and creative fix!

Discord discloses data breach after support agent got hacked

Discord is notifying users of a data breach that occurred after the account of a third-party support agent was compromised.

SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack

Attacker activity in Microsoft Azure that we attribute to a financially motivated threat actor.

Piratage et médias suisses, la justice entre en action

Comme d’autres médias, «Le Temps» a été sommé par CH Media et la NZZ, via leurs avocats, de ne publier aucune information confidentielle liée à la cyberattaque subie. En Suisse alémanique, deux médias ont dû modifier des articles en ligne

Malicious VSCode extensions with more than 45K downloads steal PII and enable backdoors - Check Point Blog

Highlights: CloudGuard Spectrals detected malicious extensions on the VSCode marketplace Users installing these extensions were enabling attackers to

Review and analysis of fake Trezor cryptowallet

Fake hardware cryptowallet, and how bitcoins were stolen from it.

FBI confirms access to Breached cybercrime forum database

Today, the FBI confirmed they have access to the database of the notorious BreachForums (aka Breached) hacking forum after the U.S. Justice Department also officially announced the arrest of its…

Securonix Threat Labs Security Advisory: Latest Update: Ongoing MEME#4CHAN Attack/Phishing Campaign uses Meme-Filled Code to Drop XWorm Payloads

An unusual attack/phishing campaign delivering malware while using meme-filled code and complex obfuscation methods continues dropping Xworm payloads for the last few months and is still ongoing today.

WordPress Plugin Vulnerability Exposed Ferrari Website to Hackers

A vulnerability in a WordPress plugin exposed the official website of sports car maker Ferrari to hacker attacks.

Hackers offer personal information of 500,000 Israeli students for sale

Weeks after breach of college chain Atid servers, hacker group Sharp Boys puts stolen information up for sale and releases additional data of students; Atid: ‘These are Iranian hackers, and most of the materials are outdated’