Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 85 / 214
4263 résultats taggé EN  ✕
Formula 1 governing body discloses data breach after email hacks https://www.bleepingcomputer.com/news/security/formula-1-governing-body-discloses-data-breach-after-email-hacks/
07/07/2024 21:58:24
QRCode
archive.org
thumbnail

FIA (Fédération Internationale de l'Automobile), the auto racing governing body since the 1950s, says attackers gained access to personal data after compromising several FIA email accounts in a phishing attack.

bleepingcomputer EN 2024 Data-Breach FIA Formula-1 Phishing
How scam networks use fake celebrity ads to lure online investors https://www.swissinfo.ch/eng/life-aging/how-scam-networks-use-fake-celebrity-ads-to-lure-investors/82568794
05/07/2024 14:50:46
QRCode
archive.org
thumbnail

Investor beware: online promises of quick profits are not always as legitimate as they look. Swiss public broadcaster, SRF, looked into a Cyprus-based network of scam websites.

swissinfo EN 2024 Cyprus-based scam websites celebrity ads
The Rise of Packet Rate Attacks: When Core Routers Turn Evil https://blog.ovhcloud.com/the-rise-of-packet-rate-attacks-when-core-routers-turn-evil/
05/07/2024 10:44:27
QRCode
archive.org
thumbnail

A sharp increase of DDoS attacks have been observed since the beginning of 2023. A new trend is to send high packet rate attacks though. This article introduces the findings of our teams in order to bring new insights regarding this threat.

ovhcloud EN 2024 Mikrotik MikroTik-RouterOS DDoS attacks
RoguePuppet – A Critical Puppet Forge Supply Chain Vulnerability https://adnanthekhan.com/2024/07/02/roguepuppet-a-critical-puppet-forge-supply-chain-vulnerability/
05/07/2024 10:16:03
QRCode
archive.org
thumbnail

What if there was a supply chain attack that could provide an attacker with direct access to core infrastructure within thousands of companies worldwide. What if that attack required no social engi…

adnanthekhan EN 2024 Critical Puppet Forge Vulnerability Supply-Chain-Attack
Europol coordinates global action against criminal abuse of Cobalt Strike https://www.europol.europa.eu/media-press/newsroom/news/europol-coordinates-global-action-against-criminal-abuse-of-cobalt-strike?ref=news.risky.biz
05/07/2024 09:50:04
QRCode
archive.org
thumbnail

Abuse by cybercriminals Cobalt Strike is a popular commercial tool provided by the cybersecurity software company Fortra. It is designed to help legitimate IT security experts perform attack simulations that identify weaknesses in security operations and incident responses. In the wrong hands, however, unlicensed copies of Cobalt Strike can provide a malicious actor with a wide range of attack capabilities.Fortra...

europol EN 2024 crackdown CobaltStrike cybercriminals
blog.ethereum.org mailing list incident https://blog.ethereum.org/2024/07/02/blog-incident
05/07/2024 09:46:14
QRCode
archive.org
thumbnail

On 2024-06-23, 00:19 AM UTC, a phishing email was sent out to 35,794 email addresses by updates@blog.ethereum.org with the following content

blog.ethereum.org EN incident spam mailing
A Hacker Stole OpenAI Secrets, Raising Fears That China Could, Too https://www.nytimes.com/2024/07/04/technology/openai-hack.html?unlocked_article_code=1.400.uQ1I.v-uMLR6dv6TK&smid=url-share
05/07/2024 08:49:17
QRCode
archive.org

Early last year, a hacker gained access to the internal messaging systems of OpenAI, the maker of ChatGPT, and stole details about the design of the company’s A.I. technologies.

The hacker lifted details from discussions in an online forum where employees talked about OpenAI’s latest technologies, according to two people familiar with the incident, but did not get into the systems where the company houses and builds its artificial intelligence.

nytimes EN OpenAI data-leak hacked internal-messaging-systems
Sonar https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1/
04/07/2024 13:18:05
QRCode
archive.org
thumbnail

We discovered 4 critical code vulnerabilities in Gogs, a source code hosting solution, which are still unpatched. Read about the details and how to protect yourself.

sonarsource EN 2024 Gogs vulnerabilities developers Supply-Chain
Caught in the Net: Using Infostealer Logs to Unmask CSAM Consumers https://www.recordedfuture.com/caught-in-the-net-using-infostealer-logs-to-unmask-csam-consumers
04/07/2024 07:24:58
QRCode
archive.org

Discover how Recorded Future uses infostealer logs to identify CSAM consumers and trends. Learn key findings and mitigation strategies.

recordedfuture EN 2024 Unmask CSAM Infostealer Logs
OpenAI’s ChatGPT Mac app was storing conversations in plain text https://www.theverge.com/2024/7/3/24191636/openai-chatgpt-mac-app-conversations-plain-text
04/07/2024 07:20:32
QRCode
archive.org
thumbnail

OpenAI updated its ChatGPT macOS app on Friday after users discovered it stored conversations insecurely in plain text.

theverge EN 2024 OpenAI chatgpt macOS app plain-text
Twilio says hackers identified cell phone numbers of two-factor app Authy users https://techcrunch.com/2024/07/03/twilio-says-hackers-identified-cell-phone-numbers-of-two-factor-app-authy-users/
04/07/2024 07:19:36
QRCode
archive.org
thumbnail

Twilio says "threat actors were able to identify" phone numbers of people who use the two-factor app Authy.

techcrunch EN 2024 Twilio phone numbers Authy data-leak
Europol coordinates global action against criminal abuse of Cobalt Strike | Europol https://www.europol.europa.eu/media-press/newsroom/news/europol-coordinates-global-action-against-criminal-abuse-of-cobalt-strike?mtm_campaign=newsletter
03/07/2024 22:04:56
QRCode
archive.org
thumbnail

Abuse by cybercriminals Cobalt Strike is a popular commercial tool provided by the cybersecurity software company Fortra. It is designed to help legitimate IT security experts perform attack simulations that identify weaknesses in security operations and incident responses. In the wrong hands, however, unlicensed copies of Cobalt Strike can provide a malicious actor with a wide range of attack capabilities.Fortra...

europol EN 2024 CobaltStrike action
CVE-2024-29510 - Exploiting Ghostscript using format strings https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/
03/07/2024 08:32:34
QRCode
archive.org
thumbnail

A format string vulnerability in Ghostscript ≤ 10.03.0 which enables attackers to gain Remote Code Execution (#RCE) while also bypassing sandbox protections. CVE-2024-29510 has significant impact on web-applications and other services offering document conversion and preview functionalities as these often use Ghostscript under the hood. We recommend verifying whether your solution (indirectly) makes use of Ghostscript and if so, update it to the latest version!

codeanlabs EN 2024 CVE-2024-29510 Ghostscript RCE
3 million iOS and macOS apps were exposed to potent supply-chain attacks https://arstechnica.com/security/2024/07/3-million-ios-and-macos-apps-were-exposed-to-potent-supply-chain-attacks/
03/07/2024 08:26:52
QRCode
archive.org
thumbnail

Apps that used code libraries hosted on CocoaPods were vulnerable for about 10 years.

arstechnica EN macOS iOS CVE-2024-38367 CocoaPods
Figma Disables AI App Design Tool After It Copied Apple’s Weather App https://www.404media.co/figma-disables-ai-app-design-tool-after-it-copied-apples-weather-app/
03/07/2024 08:26:10
QRCode
archive.org
thumbnail

“Ultimately it is my fault for not insisting on a better QA process for this work and pushing our team hard to hit a deadline,” Figma’s CEO said.

404media EN Figma disabled AI copyright legal issue design
Poland to probe Russia-linked cyberattack on state news agency https://therecord.media/poland-cyberattack-investigation-state-agency?_hsenc=p2ANqtz--F2mEpRDK35UivTHXp9aafGCFXmjkKa_bKb09DoYw0u5WeqRR5aSNmbFLJHaOMcu61vlCJrQElrGYZP9b-23BRFMNTBQ&_hsmi=314157258
03/07/2024 08:20:57
QRCode
archive.org
thumbnail

In May, hackers published fake news on the website of the Polish Press Agency claiming the country’s authorities had announced a partial mobilization of 200,000 men to be sent to fight in a war in Ukraine.

therecordmedia EN 2024 Poland Russia cyberattack Polish-Press-Agency Russia-Ukraine-war
Cisco NX-OS Command Injection Vulnerability CVE-2024-20399: Insights and Defense Strategies https://www.sygnia.co/threat-reports-and-advisories/china-nexus-threat-group-velvet-ant-exploits-cisco-0-day/
02/07/2024 18:59:25
QRCode
archive.org
thumbnail

Discover key insights into the recently disclosed Cisco NX-OS software CLI vulnerability (CVE-2024-20399) affecting numerous Cisco Nexus devices.

sygnia EN 2024 CVE-2024-20399 Cisco NX-OS Command Injection Cisco Nexus
Vulnerabilities in CocoaPods Open the Door to Supply Chain Attacks Against Thousands of iOS and MacOS Applications https://www.evasec.io/blog/eva-discovered-supply-chain-vulnerabities-in-cocoapods
02/07/2024 18:58:38
QRCode
archive.org
thumbnail
  • E.V.A Information Security researchers uncovered several vulnerabilities in the CocoaPods dependency manager that allows any malicious actor to claim ownership over thousands of unclaimed pods and insert malicious code into many of the most popular iOS and MacOS applications. These vulnerabilities have since been patched.
  • Such an attack on the mobile app ecosystem could infect almost every Apple device, leaving thousands of organizations vulnerable to catastrophic financial and reputational damage. One of the vulnerabilities could also enable zero day attacks against the most advanced and secure organizations’ infrastructure.
  • Developers and DevOps teams that have used CocoaPods in recent years should verify the integrity of open source dependencies used in their application code.
  • Dependency managers are an often-overlooked aspect of software supply chain security. Security leaders should explore ways to increase governance and oversight over the use these tools.
evasec EN 2024 CocoaPods Supply Chain Attacks macOS iOS CVE-2024-38368
TeamViewer: Hackers copied employee directory data and encrypted passwords https://therecord.media/teamviewer-cyberattack-employee-directory-encrypted-passwords
02/07/2024 16:44:27
QRCode
archive.org
thumbnail

TeamViewer says that a recently discovered breach appears to be limited to its internal corporate IT network. The software company has attributed it to a hacking operation associated with Russian intelligence.

therecord.media EN 2024 TeamViewer encrypted passwords incident APT29
Analysis of the Phishing Campaign: Behind the Incident https://any.run/cybersecurity-blog/analysis-of-the-phishing-campaign/
02/07/2024 10:56:19
QRCode
archive.org
thumbnail

See the results of our investigation into the phishing campaign encountered by our company and get information to defend against it. 

Here are some key findings:

  • We found around 72 phishing domains pretending to be real or fake companies. These domains created believable websites that tricked people into sharing their login details.
  • The attack was sophisticated, using advanced techniques like direct human interaction to deceive targets.
  • We analyzed several fake websites and reverse-engineered their web-facing application.
  • At the end of the post, you will find a list of IOCs that can be used for improving your organization’s security.
any.run EN 2024 incident phishing spear-phishing IoCs
page 85 / 214
4872 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn