Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 141 / 215
4300 résultats taggé E*N  ✕
Critical WebP bug: many apps, not just browsers, under threat https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/
14/09/2023 06:48:15
QRCode
archive.org
thumbnail

The heap buffer overflow (CVE-2023-4863) vulnerability in the WebP Codec is being actively exploited in the wild.

stackdiary.com EN 2023 CVE-2023-4863 WebP Codec
With 0-days hitting Chrome, iOS, and dozens more this month, is no software safe? | Ars Technica https://arstechnica.com/security/2023/09/with-0-days-hitting-chrome-ios-and-dozens-more-this-month-is-no-software-safe/
14/09/2023 00:26:45
QRCode
archive.org
thumbnail

With 70 zero-days uncovered so far this year, 2023 is on track to set a new record.

arstechnica EN 2023 0-days record
PSA: Ongoing Webex malvertising campaign drops BatLoader https://www.malwarebytes.com/blog/threat-intelligence/2023/09/ongoing-webex-malvertising-drops-batloader
13/09/2023 22:03:09
QRCode
archive.org
thumbnail

A new malvertising campaign is targeting corporate users who are downloading the popular web conferencing software Webex. Threat actors have bought an advert that impersonates Cisco's brand and is displayed first when performing a Google search.

malwarebytes EN 2023 Webex malvertising campaign BatLoader
Attacker combines phone, email lures into believable, complex attack chain https://news.sophos.com/en-us/2023/08/10/image-spam-attack/
13/09/2023 21:44:02
QRCode
archive.org
thumbnail

A social engineering phone call lends authenticity to the attacker’s malicious email

sophos EN 2023 switzerland phone email lures phishing
Ransomware crew hits Save The Children, steals 7TB of data https://www.theregister.com/2023/09/11/bianlian_save_the_children/
13/09/2023 14:14:35
QRCode
archive.org
thumbnail

Cybercrime crew BianLian says it has broken into the IT systems of a top nonprofit and stolen a ton of files, including what the miscreants claim is financial, health, and medical data.

As highlighted by VX-Underground and Emsisoft threat analyst Brett Callow earlier today, BianLian bragged on its website it had hit an organization that, based on the gang's description of its unnamed victim, looks to be Save The Children International. The NGO, which employs about 25,000 people, says it has helped more than a billion kids since it was founded in 1919.

theregister EN 2023 BianLian exfiltration ONG SavetheChildren databreach
Microsoft to defend customers on AI copyright challenges https://www.reuters.com/technology/microsoft-defend-customers-ai-copyright-challenges-2023-09-07/
12/09/2023 22:01:35
QRCode
archive.org
thumbnail

Microsoft will pay legal damages on behalf of customers using its artificial intelligence (AI) products if they are sued for copyright infringement for the output generated by such systems, the company said on Thursday.

reuters EN 2023 Microsoft pay AI copyright legal damages
ChatGPT fails in languages like Tamil and Bengali https://restofworld.org/2023/chatgpt-problems-global-language-testing/
12/09/2023 22:00:34
QRCode
archive.org
thumbnail

Outside of English, ChatGPT makes up words, fails logic tests, and can't do basic information retrieval.

restofworld EN 2023 ChatGPT fails Tamil Bengali
KNVB paid ransom to prevent cyber criminals from publishing footballers' passports https://nltimes.nl/2023/09/12/knvb-paid-ransom-prevent-cyber-criminals-publishing-footballers-passports
12/09/2023 21:57:50
QRCode
archive.org
thumbnail

The Dutch football association KNVB paid the ransom demanded by cyber criminals in a ransomware attack in April. The hackers stole Dutch and other football players’ passports, ID cards, home addresses, and salary slips and threatened to publish the data if the football association didn’t pay the ransom, the KNVB said on Tuesday.

nltimes EN 2023 Dutch football association KNVB paid ransomware LockBit
Cybersecurity issue prompts computer shutdowns at MGM Resorts properties across US https://apnews.com/article/mgm-resorts-casino-vegas-cybersecurity-outage-06de044bdf1880af2a8bce1a38c986ee
12/09/2023 21:52:55
QRCode
archive.org
thumbnail

Casino and hotel giant MGM Resorts International says a cybersecurity issue led to the shutdown of computer systems at its properties across the U.S.

apnews EN 2023 Casino MGM Resorts US Cybersecurity
“MrTonyScam” — Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts https://labs.guard.io/mrtonyscam-botnet-of-facebook-users-launch-high-intent-messenger-phishing-attack-on-business-3182cfb12f4d
12/09/2023 07:25:33
QRCode
archive.org

Facebook’s Messenger platform has been heavily abused in the past month to spread endless messages with malicious attachments from a swarm of fake and hijacked personal accounts. These threat actors are targeting millions of business accounts on Facebook’s platform — from highly-rated marketplace sellers to large corporations, with fake business inquiries, achieving a staggering “success rate” with approximately 1 out of 70 infected!

labs.guard.io EN 2023 Messenger Facebook Phishing Attack Botnet
Active North Korean campaign targeting security researchers https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/
11/09/2023 23:04:57
QRCode
archive.org
thumbnail

Threat Analysis Group shares findings on a new campaign by North Korean actors targeting security researchers.

Google EN 2023 threat-analysis-group North-Korea security researchers Symbols
North Korea-backed hackers target security researchers with 0-day https://arstechnica.com/security/2023/09/north-korea-backed-hackers-target-security-researchers-with-0-day/
11/09/2023 23:03:12
QRCode
archive.org
thumbnail

Google researchers say currently unfixed vulnerability affects a popular software package.

arstechnica EN 2023 North-Korea security researchers 0-day popular software
Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/
10/09/2023 19:00:22
QRCode
archive.org

In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. Since then, a steady trickle of six-figure cryptocurrency heists targeting security-conscious…

krebsonsecurity EN 2023 LastPass Cracking Keys Stolen
The International Criminal Court Will Now Prosecute Cyberwar Crimes https://www.wired.com/story/icc-cyberwar-crimes/
10/09/2023 16:03:33
QRCode
archive.org
thumbnail

FOR YEARS, SOME cybersecurity defenders and advocates have called for a kind of Geneva Convention for cyberwar, new international laws that would create clear consequences for anyone hacking civilian critical infrastructure, like power grids, banks, and hospitals. Now the lead prosecutor of the International Criminal Court at the Hague has made it clear that he intends to enforce those consequences—no new Geneva Convention required. Instead, he has explicitly stated for the first time that the Hague will investigate and prosecute any hacking crimes that violate existing international law, just as it does for war crimes committed in the physical world.

wired EN 2023 International Criminal Court ICC Prosecute Cyberwar Crimes legal
Last Week on My Mac: How quickly can Apple release a security update? https://eclecticlight.co/2023/09/10/last-week-on-my-mac-how-quickly-can-apple-release-a-security-update/#like-74253
10/09/2023 11:18:45
QRCode
archive.org
thumbnail

We seldom get much insight into how long Apple takes to release an urgent update to macOS, but last week must have seen one of the quickest in recent times. By my reckoning, Apple’s engineers accomplished that in 6-10 days, across four of its operating systems, and with two distinct vulnerabilities.

eclecticlight EN 2023 Apple security update macos release
China’s iPhone ban expected to expand to more government agencies soon https://9to5mac.com/2023/09/07/china-iphone-ban-to-expand/
09/09/2023 12:18:12
QRCode
archive.org
thumbnail

A report yesterday revealed that China has banned government officials from using iPhones and other foreign technology within government agencies. Now, a report from Bloomberg says that this is only the start of China’s crackdown on iPhone, with a much broader set of restrictions also in the works.

9to5mac China ban iPhone EN 2023 government
Microsoft pledges legal protection for AI-generated copyright breaches https://www.ft.com/content/cd7f5391-bba5-4af1-8309-346eb2eafa02
08/09/2023 09:56:37
QRCode
archive.org

US tech giant will assume customers’ liability for material created by AI assistants in Word and coding tools

ft EN 2023 Microsoft AI legal AI-generated copyright breaches
Code Vulnerabilities Put Proton Mails at Risk https://www.sonarsource.com/blog/code-vulnerabilities-leak-emails-in-proton-mail/
07/09/2023 23:42:58
QRCode
archive.org
thumbnail

The Sonar Research team discovered critical code vulnerabilities in Proton Mail, Skiff and Tutanota. This post covers the technical details of the XSS vulnerability in Proton Mail.

sonarsource EN 2023 Code Vulnerabilities ProtonMail XSS Tutanota
MAR-10430311-1.v1 Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 https://www.cisa.gov/news-events/analysis-reports/ar23-250a
07/09/2023 23:30:37
QRCode
archive.org

CISA received 4 files for analysis from an incident response engagement conducted at an Aeronautical Sector organization.

2 files (bitmap.exe, wkHPd.exe) are identified as variants of Metasploit (Meterpreter) and designed to connect and receive unencrypted payloads from their respective command and control (C2) servers. Note: Metasploit is an open source penetration testing software; Meterpreter is a Metasploit attack payload that runs an interactive shell. These executables are used as attack payloads to run interactive shells, allowing a malicious actor the ability to control and execute code on a system.

2 files (resource.aspx, ConfigLogin.aspx) are Active Server Pages (ASPX) web shells designed to execute remote JavaScript code on the victim server.

cisa EN 2023 Multiple Nation-State Threat Actors Exploit CVE-2022-47966 CVE-2022-42475
Mac users targeted in new malvertising campaign delivering Atomic Stealer https://www.malwarebytes.com/blog/threat-intelligence/2023/09/atomic-macos-stealer-delivered-via-malvertising
07/09/2023 21:36:22
QRCode
archive.org
thumbnail
  • Malicious ads for Google searches are targeting Mac users
  • Phishing sites trick victims into downloading what they believe is the app they want
  • The malware is bundled in an ad-hoc signed app so it cannot be revoked by Apple
  • The payload is a new version of the recent Atomic Stealer for OSX
malwarebytes EN 2023 macos AtomicStealer stealer tradingview
page 141 / 215
4888 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn