Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 151 / 222
4427 résultats taggé EN  ✕
WinRAR 0-day that uses poisoned JPG and TXT files under exploit since April | Ars Technica https://arstechnica.com/security/2023/08/winrar-0-day-that-uses-poisoned-jpg-and-txt-files-under-exploit-since-april/
24/08/2023 08:39:23
QRCode
archive.org
thumbnail

Vulnerability allows hackers to execute malicious code when targets open malicious ZIP files.

arstechnica EN WinRAR 0-day CVE-2023-38831
#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation https://www.deepinstinct.com/blog/nofilter-abusing-windows-filtering-platform-for-privilege-escalation
24/08/2023 08:34:53
QRCode
archive.org
thumbnail

This blog is based on a session we presented at DEF CON 2023 on Sunday, August 13, 2023, in Las Vegas. Privilege escalation is a common attack vector in the Windows OS. There are multiple offensive tools in the wild that can execute code as “NT AUTHORITY\SYSTEM” (Meterpreter, CobaltStrike, Potato tools), and they all usually do so by duplicating tokens and manipulating services. This allows them to perform attacks like LSASS Shtinkering.

deepinstinct EN 2023 #NoFilter DEFCON2023 Privilege escalation
British court convicts two teen Lapsus$ members of hacking tech firms https://therecord.media/lapsus$-hackers-convinctions-teens-uk-court
23/08/2023 15:35:38
QRCode
archive.org
thumbnail

Two teenagers, ages 18 and 17, were found guilty of hacking into major corporations. The cases involved Uber, Nvidia and more.

therecord EN 2023 Lapsus$ teenagers busted
macOS 0day: App Management https://lapcatsoftware.com/articles/2023/8/2.html
22/08/2023 21:26:42
QRCode
archive.org

App Management is a new macOS security feature in Ventura introduced at WWDC last year:

If an app is modified by something that isn't signed by the same development team and isn't allowed by an NSUpdateSecurityPolicy, macOS will block the modification and notify the user that an app wants to manage other apps. Clicking on the notification sends people to System Settings, where they can allow an app to update and modify other apps.

lapcatsoftware EN 2023 macOS 0-day AppManagement
XLoader's Latest Trick | New macOS Variant Disguised as Signed OfficeNote App https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/
22/08/2023 09:55:02
QRCode
archive.org
thumbnail

Notorious botnet and infostealer XLoader makes a return to macOS with a new dropper and malware payload.

sentinelone EN 2023 XLoader macOS dropper payload
Ecuador’s national election agency says cyberattacks caused absentee voting issues https://therecord.media/ecuador-election-cyberattacks-absentee-voting
22/08/2023 08:50:49
QRCode
archive.org
thumbnail

Absentee voters flooded social media to express their frustration at not being able to cast votes through an online system created by the government.

therecord EN 2023 Ecuador voting election cyberattacks
CVE-2023-34127 https://attackerkb.com/topics/Vof5fWs4rx/cve-2023-34127
21/08/2023 21:47:28
QRCode
archive.org
thumbnail

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authe…

attackerkb EN 2023 rapid7 SonicWall CVE-2023-34127 vulnerability PoC
Sneaky Amazon Google ad leads to Microsoft support scam https://www.bleepingcomputer.com/news/security/sneaky-amazon-google-ad-leads-to-microsoft-support-scam/
21/08/2023 20:19:41
QRCode
archive.org
thumbnail

A legitimate-looking ad for Amazon in Google search results redirects visitors to a Microsoft Defender tech support scam that locks up their browser.

bleepingcomputer EN 2023 GoogleAds technical-support scam
Brazilian hacker claims Bolsonaro asked him to hack into the voting system ahead of 2022 vote | AP News https://apnews.com/article/brazil-bolsonaro-hacking-inquiry-cc8f890588a5115ff77370d236b3e149
21/08/2023 07:16:26
QRCode
archive.org
thumbnail

A Brazilian hacker claimed at a congressional hearing Thursday that then-President Jair Bolsonaro wanted him to hack into the country’s electronic voting system to expose its alleged weaknesses ahead of the 2022 presidential election.

apnews EN 2023 Brazil Bolsanero hacker voting system
2023-08 Out-of-Cycle Security Bulletin: Junos OS: SRX Series and EX Series: Multiple vulnerabilities in J-Web can be combined to allow a preAuth Remote Code Execution https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US
20/08/2023 18:21:02
QRCode
archive.org
juniper EN 2023 bulletin vulnerability Out-of-Cycle CVE-2023-36844 CVE-2023-36845 CVE-2023-36846 CVE-2023-36847
Data Theft Via MOVEit: 4.5 Million More Individuals Affected https://www.databreachtoday.com/data-theft-via-moveit-45-million-more-individuals-affected-a-22810
20/08/2023 18:17:34
QRCode
archive.org
thumbnail

The fallout from the Clop cybercrime group's mass theft of data from MOVEit servers continues to increase. Colorado's state healthcare agency alone is now notifying

databreachtoday EN 2023 MOVEit Clop Colorado US healthcare
Chinese Microsoft hackers also hit GOP Rep. Don Bacon of Nebraska https://www.washingtonpost.com/technology/2023/08/14/microsoft-china-hack-congress/
20/08/2023 18:17:05
QRCode
archive.org
thumbnail

Rep. Don Bacon tweeted Monday that he had been notified by the FBI that his emails had been hacked.

washingtonpost EN 2023 US Microsoft cloud DonBacon FBI emails hacked outlook China
Threat actors use beta apps to bypass mobile app store security https://www.bleepingcomputer.com/news/security/threat-actors-use-beta-apps-to-bypass-mobile-app-store-security/
19/08/2023 17:23:08
QRCode
archive.org
thumbnail

The FBI is warning of a new tactic used by cybercriminals where they promote malicious "beta" versions of cryptocurrency investment apps on popular mobile app stores that are then used to steal crypto.

bleepingcomputer EN 2023 FBI beta mobile apps cryptocurrency
New Apple iOS 16 Exploit Enables Stealthy Cellular Access Under Fake Airplane Mode https://thehackernews.com/2023/08/new-apple-ios-16-exploit-enables.html
19/08/2023 17:22:46
QRCode
archive.org
thumbnail

Cybersecurity researchers have documented a novel post-exploit persistence technique on iOS 16 that could be abused to fly under the radar and maintain access to an Apple device even when the victim believes it is offline.

The method "tricks the victim into thinking their device's Airplane Mode works when in reality the attacker (following successful device exploit) has planted an artificial Airplane Mode which edits the UI to display Airplane Mode icon and cuts internet connection to all apps except the attacker application," Jamf Threat Labs researchers Hu Ke and Nir Avraham said in a report shared with The Hacker News.

thehackernews EN 2023 iOS apple airplanemode exploit
Approximately 2000 Citrix NetScalers backdoored in mass-exploitation campaign https://blog.fox-it.com/2023/08/15/approximately-2000-citrix-netscalers-backdoored-in-mass-exploitation-campaign/
19/08/2023 17:20:54
QRCode
archive.org
thumbnail

Fox-IT (part of NCC Group) has uncovered a large-scale exploitation campaign of Citrix NetScalers in a joint effort with the Dutch Institute of Vulnerability Disclosure (DIVD). An adversary appears to have exploited CVE-2023-3519 in an automated fashion, placing webshells on vulnerable NetScalers to gain persistent access. The adversary can execute arbitrary commands with this webshell, even when a NetScaler is patched and/or rebooted. At the time of writing, more than 1900 NetScalers remain backdoored. Using the data supplied by Fox-IT, the Dutch Institute of Vulnerability Disclosure has notified victims.

fox-it EN 2023 CVE-2023-3519 citrix NetScalers backdoored
Discord.io confirms breach after hacker steals data of 760K users https://www.bleepingcomputer.com/news/security/discordio-confirms-breach-after-hacker-steals-data-of-760k-users/
19/08/2023 17:20:03
QRCode
archive.org
thumbnail

The Discord.io custom invite service has temporarily shut down after suffering a data breach exposing the information of 760,000 members.

bleepingcomputer EN 2023 discord databreach
The New Frontline of Geopolitics | Understanding the Rise of State-Sponsored Cyber Attacks https://www.sentinelone.com/blog/the-new-frontline-of-geopolitics-understanding-the-rise-of-state-sponsored-cyber-attacks/
18/08/2023 14:35:53
QRCode
archive.org
thumbnail

Understanding the complex threat landscape facing businesses today from state-sponsored cyber attacks is crucial to effective cyber defense.

sentinelone EN 2023 APT research state-sponsored cyberdefense
Phishing pages placed on hacked websites https://securelist.com/phishing-with-hacked-sites/110334/
18/08/2023 14:23:35
QRCode
archive.org
thumbnail

Scammers are hacking websites powered by WordPress and placing phishing pages inside hidden directories. We share some statistics and tips on recognizing a hacked site.

securelist EN 2023 Data-theft Phishing websites Website-Hacks Wordpress
Users of cybercrime forums often fall victim to info-stealers, researchers find https://therecord.media/cybercrime-forum-users-infected-with-info-stealing-malware
18/08/2023 10:10:54
QRCode
archive.org
thumbnail

After analyzing millions of computers infected with info-stealing malware, researchers at Hudson Rock said they identified 120,000 that contained credentials used for logging into cybercrime forums.

therecord EN 2023 cybercrime InfoStealer credentials
Prominent Threat Actor Accidentally Infects Own Computer with Info-Stealer https://www.hudsonrock.com/blog/prominent-threat-actor-accidentally-infects-own-computer-with-info-stealer
18/08/2023 10:10:07
QRCode
archive.org
thumbnail

Threat actor “La_Citrix” is known for hacking companies — he accidentally infected his own computer and likely ended up selling it without noticing.

hudsonrock EN 2023 La_Citrix pwoned InfoStealer Accidentally
page 151 / 222
5047 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn