Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 76 / 215
4285 résultats taggé E*N  ✕
The Hidden Treasures of Crash Reports https://objective-see.org/blog/blog_0x7B.html?mc_cid=cc6f2fb89f&mc_eid=0d9a12074d
15/08/2024 07:06:53
QRCode
archive.org
thumbnail

Sadly, nobody really loves crash reports, but I’m here to change that!

This research, a crash course on crash reports, will highlight how these often overlooked files are an invaluable source of information, capable of revealing malware infections, exploitation attempts, or even buggy (exploitable?) system code. Such insights are critical for defense and offense, empowering us to either protect or exploit macOS systems.

objective-see EN 2024 crash-report course Hidden analysis macos
Troy Hunt: Inside the "3 Billion People" National Public Data Breach https://www.troyhunt.com/inside-the-3-billion-people-national-public-data-breach/
15/08/2024 06:24:37
QRCode
archive.org
thumbnail

I decided to write this post because there's no concise way to explain the nuances of what's being described as one of the largest data breaches ever. Usually, it's easy to articulate a data breach; a service people provide their information to had someone snag it through an act of unauthorised access and publish a discrete corpus of information that can be attributed back to that source. But in the case of National Public Data, we're talking about a data aggregator most people had never heard of where a "threat actor" has published various partial sets of data with no clear way to attribute it back to the source. And they're already the subject of a class action, to add yet another variable into the mix. I've been collating information related to this incident over the last couple of months, so let me talk about what's known about the incident, what data is circulating and what remains a bit of a mystery.

troyhunt EN 2024 3billion National Public Data Breach data-breach USDoD
Want to Win a Bike Race? Hack Your Rival’s Wireless Shifters | WIRED https://www.wired.com/story/shimano-wireless-bicycle-shifter-jamming-replay-attacks/
14/08/2024 19:55:52
QRCode
archive.org
thumbnail

Please don’t, actually. But do update your Shimano Di2 shifters’ software to prevent a new radio-based form of cycling sabotage.
#bicycles #cyberattacks #cybersecurity #cycling #fitness #hacks #security

wired EN 2024 fitness hacks Shimano cycling
Inside the FBI's Dashboard for Wiretapping the World https://www.404media.co/inside-the-fbis-dashboard-for-wiretapping-the-world/?ref=daily-stories-newsletter
14/08/2024 18:15:09
QRCode
archive.org
thumbnail

Never-before-published screenshots of an internal FBI tool show how the agency monitored millions of messages from the secretly backdoored messaging app Anom.

404media EN 2024 Anom images dahsboard FBI
Extension Trojan Malware Campaign https://reasonlabs.com/research/new-widespread-extension-trojan-malware-campaign
14/08/2024 17:49:30
QRCode
archive.org
thumbnail

Malwares make no distinction between corporate and personal devices. Therefore, past perceptions of different levels of antivirus for businesses and households must be challenged. ReasonLabs is the first endpoint protection based on a multilayered machine-learning engine, that provides enterprise-grade security for all your personal devices.

reasonlabs EN 2024 Extension Trojan Malware Campaign
Russia-linked phishing campaigns ensnare civil society and NGOs https://www.accessnow.org/russian-phishing-campaigns/
14/08/2024 14:21:00
QRCode
archive.org
thumbnail

Russia-linked phishing campaigns are targeting civil society and NGOs operating in the region and abroad, according to a new investigation by Access Now and the Citizen Lab.

accessnow EN 2024 Russia Russia-linked phishing campaigns NGO civil-society
Critical SAP flaw allows remote attackers to bypass authentication https://www.bleepingcomputer.com/news/security/critical-sap-flaw-allows-remote-attackers-to-bypass-authentication/
14/08/2024 00:14:10
QRCode
archive.org
thumbnail

SAP has released its security patch package for August 2024, addressing 17 vulnerabilities, including a critical authentication bypass that could allow remote attackers to fully compromise the system.

bleepingcomputer EN 2024 Authentication-Bypass SAP SSRF Vulnerability CVE-2024-41730
CVE-2024-39825 and CVE-2024-39818: High-Risk Zoom Flaws Require Urgent Updates https://securityonline.info/cve-2024-39825-and-cve-2024-39818-high-risk-zoom-flaws-require-urgent-updates/
13/08/2024 21:53:19
QRCode
archive.org
thumbnail

Among the most critical are CVE-2024-39825 and CVE-2024-39818, both with a CVSS score of 8.5, indicating a high level of severity

securityonline EN 2024 CVE-2024-39825 CVE-2024-39818 High-Risk Zoom
CVE-2024-23897 Enabled Ransomware Attack on Indian Banks https://blogs.juniper.net/en-us/threat-research/cve-2024-23897-enabled-ransomware-attack-on-indian-banks
13/08/2024 20:41:37
QRCode
archive.org
thumbnail

CVE-2024-23897 is an unauthenticated arbitary file read vulnerability in Jenkins CLI used by RansomEXX to target small Indian banks.

juniper EN 2024 CVE-2024-23897 Ransomware Jenkins RansomEXX ransom-note
Exploitable PoC Released for CVE-2024-38077: 0-Click RCE Threatens All Windows Servers https://securityonline.info/exploitable-poc-released-for-cve-2024-38077-0-click-rce-threatens-all-windows-servers/
13/08/2024 17:43:45
QRCode
archive.org
thumbnail

Security researchers have detailed and published a PoC exploit code for a critical vulnerability, designated as CVE-2024-38077 (CVSS 9.8)

securityonline EN 2024 CVE-2024-38077 RCE PoC exploit code
Suspected head of prolific cybercrime groups arrested and extradited - National Crime Agency https://www.nationalcrimeagency.gov.uk/news/suspected-head-of-prolific-cybercrime-groups-arrested-and-extradited
13/08/2024 15:45:35
QRCode
archive.org
thumbnail

The National Crime Agency leads the UK's fight to cut serious and organised crime.

nationalcrimeagency.gov.uk EN 2024 organised-crime J.P.Morgan Reveton Angler
Compromising Microsoft's AI Healthcare Chatbot Service https://www.tenable.com/blog/compromising-microsofts-ai-healthcare-chatbot-service
13/08/2024 15:33:44
QRCode
archive.org
thumbnail

Tenable finds privilege-escalation issues in Azure Health Bot via an SSRF, which allowed access to cross-tenant resources.

tenable en 2024 azure azure-health-bot tenable-research ssrf vulnerability cross-tenant-access artificial-intelligence ai-security
Don’t get Mad, get wise https://news.sophos.com/en-us/2024/08/13/dont-get-mad-get-wise/
13/08/2024 15:30:10
QRCode
archive.org
thumbnail

The “Mad Liberator” ransomware group leverages social-engineering moves to watch out for

sophos EN 2024 MadLiberator ransomware group social-engineering
Exploiting pfsense Remote Code Execution – CVE-2022-31814 https://laburity.com/exploiting-pfsense-remote-code-execution-cve-2022-31814/
13/08/2024 13:50:49
QRCode
archive.org
thumbnail

Greetings everyone, In this write-up, we will be exploring the interesting exploitation that has been done against the pfsense CVE-2022-31814. What is pfsense? pfSense software is a FreeBSD-based operating system designed to install and configure a firewall that can be easily configured via the web interface and installed on any PC. With all of the

laburity.com en 2024 pfsense Remote Code Execution CVE-2022-31814
NIST's Post-Quantum Cryptography Standards Are Here - IEEE Spectrum https://spectrum.ieee.org/post-quantum-cryptography-2668949802
13/08/2024 13:33:52
QRCode
archive.org
thumbnail

Today, the National Institute of Standards and Technology (NIST) announced the first standardization of three cryptography schemes that are immune against the threat of quantum computers, known as post-quantum cryptography (PQC) schemes. With these standards in hand, NIST is encouraging computer system administrators to begin transitioning as soon as possible.

ieee.org en 2024 quantum-computing nist standards security cryptography
60 Hurts per Second – How We Got Access to Enough Solar Power to Run the United States https://www.bitdefender.com/blog/labs/60-hurts-per-second-how-we-got-access-to-enough-solar-power-to-run-the-united-states/
13/08/2024 11:45:28
QRCode
archive.org
thumbnail
  • Bitdefender researchers have identified a series of vulnerabilities in PV plant management platforms operated by Solarman and Deye.
  • This platform is responsible for coordinating production operations of millions of solar installations worldwide generating a whopping output of approximately 195 GW of solar power (20% of the global solar production)
  • If exploited, these vulnerabilities could allow an attacker to control inverter settings that could take parts of the grid down, potentially causing blackouts.
  • These vulnerabilities have been communicated to the affected vendors and fixed.
bitdefender EN 2024 Solar Power plant management IoT Solarman Deye
Technical Exploits of HID's iClass SE Discovered, To Be Revealed at DEF CON 32 https://ipvm.com/reports/iclass-se-exploit
13/08/2024 10:16:07
QRCode
archive.org
thumbnail

Researchers have "reverse-engineered" HID's iCLASS SE platform and will be "revealing some cryptographic keys to the kingdom."

ipvm.com EN 2024 defcon2024 iclass-se HID exploit
Feds seize Radar/Dispossessor ransomware gang servers in US and Europe https://therecord.media/fbi-seizes-ransomware-servers-radar
13/08/2024 09:04:59
QRCode
archive.org
thumbnail

The agency said at least 43 companies have been attacked by the group in the U.S., South America, India, Europe, the United Arab Emirates, and elsewhere.

therecord.media EN 2024 Radar Dispossessor lockbit seized FBI
CrowdStrike Exec Shows Up to Accept 'Most Epic Fail' Award in Person https://uk.pcmag.com/security/153845/crowdstrike-exec-shows-up-to-accept-most-epic-fail-award-in-person
13/08/2024 08:12:53
QRCode
archive.org
thumbnail

CrowdStrike President Michael Sentonas appears at DEF CON's annual Pwnie Awards to accept the 'award' because 'we got this horribly wrong [and] it's super important to own it.'

pcmag crowdstrike EN 2024 defcon2024 CrowdStrike PwnieAwards
Improving Apache httpd Protections Proactively with Orange Tsai of DEVCORE https://www.akamai.com/blog/security-research/2024/aug/2024-august-apache-waf-proactive-collaboration-orange-tsai-devcore?ref=news.risky.biz
12/08/2024 19:58:53
QRCode
archive.org
  • In collaboration with renowned security researcher Orange Tsai and DEVCORE, Akamai researchers have issued early-release remediations to Apache CVEs for our Akamai App & API Protector customers.

  • Tsai presented his research at Black Hat USA 2024 and outlined the details for many Apache HTTP Server (httpd) vulnerabilities that were recently patched.

  • Before his Black Hat presentation, the Akamai Security Intelligence Group (SIG) proactively contacted Tsai to facilitate the sharing of technique details for proactive defense for our customers.

  • App & API Protector customers who are in automatic mode have existing and updated protections.

akamai OrangeTsai EN 2024 DEVCORE vulnerabilities Apache httpd CVE-2024-38475 CVE-2024-38472 CVE-2024-39573 CVE-2024-38477
page 76 / 215
4872 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn