Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 204 / 215
4283 résultats taggé EN  ✕
Analyzing a Pirrit adware installer https://forensicitguy.github.io/analyzing-pirrit-adware-installer/
14/05/2022 09:33:03
QRCode
archive.org

While Windows holds the largest market share on malware, macOS has its fair share of threats that mostly exist in an adware/grayware area. In this post I want to walk through how a Pirrit PKG file installer works. There are lots of more complex threats, but this is a good place to start if you’re just jumping into analysis. If you want to follow along at home, I’m working with this file in MalwareBazaar: https://bazaar.abuse.ch/sample/d39426dbceb54bba51587242f8101184df43cc23af7dc7b364ca2327e28e7825/.

forensicitguy EN Analysis pirrit macOS malware walkthough PKG adware
Known macOS Vulnerabilities Led Researcher to Root Out New Flaws https://www.darkreading.com/endpoint/known-macos-vulnerabilities-led-researcher-to-root-out-new-flaws
12/05/2022 23:27:36
QRCode
archive.org
thumbnail

Researcher shares how he unearthed newer bugs in Apple's operating system by closer scrutiny of previous research, including vulnerabilities that came out of the Pwn2Own competition.

darkreading macOS EN 2022 bugs Apple vulnerabilities Fitzl XCSSET
Russia hacked an American satellite company one hour before the Ukraine invasion https://www.technologyreview.com/2022/05/10/1051973/russia-hack-viasat-satellite-ukraine-invasion
11/05/2022 14:08:50
QRCode
archive.org
thumbnail

The attack on Viasat showcases cyber’s emerging role in modern warfare.

technologyreview EN 2022 cyberwar russia-ukraine-war Viasat satellite warfare
npm Supply Chain Attack Targeting Germany-Based Companies https://jfrog.com/blog/npm-supply-chain-attack-targets-german-based-companies/
11/05/2022 11:32:33
QRCode
archive.org
thumbnail

The JFrog Security Research team identified and quickly disclosed new npm malicious packages aimed at compromising leading industrial organizations

jfrog 2022 EN Supply Chain supplychain industrial npm attack research
Ransomware-as-a-service: Understanding the cybercrime gig economy and how to protect yourself https://www.microsoft.com/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/
11/05/2022 11:25:36
QRCode
archive.org
thumbnail

Microsoft coined the term “human-operated ransomware” to clearly define a class of attack driven by expert humane intelligence at every step of the attack chain and culminate in intentional business disruption and extortion. In this blog, we explain the ransomware-as-a-service affiliate model and disambiguate between the attacker tools and the various threat actors at play during a security incident.

microsoft ransomware Ransomware-as-a-service EN 2022 affiliate
Costa Rica declares national emergency after Conti ransomware attacks https://www.bleepingcomputer.com/news/security/costa-rica-declares-national-emergency-after-conti-ransomware-attacks/
10/05/2022 19:48:37
QRCode
archive.org
thumbnail

The Costa Rican President Rodrigo Chaves has declared a national emergency following cyber attacks from Conti ransomware group on multiple government bodies.

BleepingComputer also observed Conti published most of the 672 GB dump that appears to contain data belonging to the Costa Rican government agencies.

The declaration was signed into law by Chaves on Sunday, May 8th, same day as the economist and former Minister of Finance effectively became the country's 49th and current president.

bleepingcomputer EN 2022 Conti ransomware leak Costarica emergency
Dissecting Saintstealer https://blog.cyble.com/2022/04/27/dissecting-saintstealer/
10/05/2022 15:09:32
QRCode
archive.org
thumbnail

Cyble Analyzes Saintstealer, an infostealer using a C&C server with known links to other popular infostealers.

Cyble 2022 EN Saintstealer infostealer
Russian TVs, search engines hacked on Victory Day with antiwar message https://www.washingtonpost.com/world/2022/05/09/russia-tv-hack-victory-day-ukraine-war/
10/05/2022 13:27:46
QRCode
archive.org
thumbnail

Russians using smart TVs reported seeing something atypical: A message appeared instead of the usual listing of channels. “The blood of thousands of Ukrainians and hundreds of murdered children is on your hands,” read the message that took over their screens. “TV and the authorities are lying. No to war.”

washingtonpost 2022 EN russian TV hacked smart
Apple, Google, and Microsoft commit to expanded support for FIDO standard https://www.apple.com/newsroom/2022/05/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard/
10/05/2022 09:56:44
QRCode
archive.org
thumbnail

Faster, easier, and more secure sign-ins will be available to consumers across leading devices and platforms.

Apple newsroom EN 2022 FIDO standard
Vulnerability Analysis - CVE-2022-1388 https://www.randori.com/blog/vulnerability-analysis-cve-2022-1388/
09/05/2022 19:01:08
QRCode
archive.org
thumbnail

CVE-2022-1388 is a critical vulnerability (CVSS 9.8) in the management interface of F5 Networks’ BIG-IP solution that enables an unauthenticated attacker to gain remote code execution on the system through bypassing F5’s iControl REST authentication. The vulnerability was first discovered by F5’s internal product security team and disclosed publicly on May 4, 2022.

CVE-2022-1388 randori EN 2022 critical vulnerability F5 BIG-IP RCE
From the Front Lines | Unsigned macOS oRAT Malware Gambles For The Win https://www.sentinelone.com/blog/from-the-front-lines-unsigned-macos-orat-malware-gambles-for-the-win/
09/05/2022 18:58:30
QRCode
archive.org
thumbnail

Researchers looking into a new APT group targeting gambling sites with a variety of cross-platform malware recently identified a version of oRAT malware targeting macOS users and written in Go. While neither RATs nor Go malware are uncommon on any platform, including the Mac, the development of such a tool by a previously unknown APT is an interesting turn, signifying the increasing need for threat actors to address the rising occurrence of Macs among their intended targets and victims. In this post, we dig deeper into the technical details of this novel RAT to understand better how it works and how security teams can detect it in their environments.

SentinelOne EN 2022 macos oRat Go APT RAT
Russia to Rent Tech-Savvy Prisoners to Corporate IT? https://krebsonsecurity.com/2022/05/russia-to-rent-tech-savvy-prisoners-to-corporate-it/
08/05/2022 11:59:23
QRCode
archive.org

Faced with a brain drain of smart people fleeing the country following its invasion of Ukraine, the Russian Federation is floating a new strategy to address a worsening shortage of qualified information technology experts: Forcing tech-savvy people within the nation's…

krebsonsecurity EN 2022 Russia russia-ukraine-war prisoners strategy
BPFDoor — an active Chinese global surveillance tool https://doublepulsar.com/bpfdoor-an-active-chinese-global-surveillance-tool-54b078f1a896
07/05/2022 17:54:58
QRCode
archive.org
doublepulsar EN 2022 BPFDoor nix unix surveillance Chinese implant backdoor
Fuzzing ClamAV with real malware samples https://mmmds.pl/clamav/
07/05/2022 11:10:09
QRCode
archive.org
mmmds EN 2022 ClamAV fuzzing CVE-2022-20770 CVE-2022-20771 CVE-2022-20785 CVE-2022-20792
MacOS Two-machine Kernel Debugging https://www.diverto.hr/en/blog/2022-03-06-macos-two-Machine-kernel-debugging/
06/05/2022 18:33:27
QRCode
archive.org
thumbnail

Diverto is an information security company. We provide consulting and managed services.

MacOS diverto 2022 EN howto kernel Debugging
Operation CuckooBees: Cybereason Uncovers Massive Chinese Intellectual Property Theft Operation https://www.cybereason.com/blog/operation-cuckoobees-cybereason-uncovers-massive-chinese-intellectual-property-theft-operation
06/05/2022 16:55:57
QRCode
archive.org
thumbnail

Cybereason recently an attack assessed to be the work of Chinese APT Winnti that operated undetected, siphoning intellectual property and sensitive data - the two companion reports examine the tactics and techniques of the overall campaign as well as more detailed analysis of the malware arsenal and exploits used...

cybereason 2022 EN CuckooBees Winnti APT APT41 intellectual property siphoning Theft
Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard to Accelerate Availability of Passwordless Sign-Ins https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/
06/05/2022 16:19:39
QRCode
archive.org
thumbnail

Faster, easier and more secure sign-ins will be available to consumers across leading devices and platforms  Mountain View, California, MAY 5, 2022  – In a joint effort to make the web […]

FIDO fidoalliance EN 2022 Google Apple Microsoft Passwordless password Standard
How Data Brokers Sell Access to the Backbone of the Internet https://www.vice.com/en/article/jg84yy/data-brokers-netflow-data-team-cymru
06/05/2022 15:12:32
QRCode
archive.org
thumbnail

ISPs are quietly distributing "netflow" data that can, among other things, trace traffic through VPNs.

vice 2021 EN VPN Backbone Privacy netflow Data Brokers
Nozomi Networks Discovers Unpatched DNS Bug in Popular C Standard Library Putting IoT at Risk https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-dns-bug-in-popular-c-standard-library-putting-iot-at-risk/
04/05/2022 10:41:30
QRCode
archive.org
thumbnail

Nozomi Networks Labs has disclosed an unpatched vulnerability affecting the DNS of popular C standard libraries potentially in use by millions of IoT devices: uClibc and uClibc-ng.

Nozomi EN 2022 C uClibc uClibc-ng vulnerability ICS-VU-638779
UNC3524: Eye Spy on Your Email https://www.mandiant.com/resources/unc3524-eye-spy-email
03/05/2022 17:16:56
QRCode
archive.org
thumbnail

We introduce UNC3524, a newly discovered suspected espionage threat actor targeting corporate emails.

Mandiant EN 2022 Email espionage corporate emails QUIETEXIT
page 204 / 215
4893 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn