Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 95 / 214
4264 résultats taggé EN  ✕
How Apple Wi-Fi Positioning System can be abused to track people around the globe https://www.theregister.com/AMP/2024/05/23/apple_wifi_positioning_system/
24/05/2024 06:50:26
QRCode
archive.org
thumbnail

Academics have suggested that Apple's Wi-Fi Positioning System (WPS) can be abused to create a global privacy nightmare.

In a paper titled, "Surveilling the Masses with Wi-Fi-Based Positioning Systems," Erik Rye, a PhD student at the University of Maryland (UMD) in the US, and Dave Levin, associate professor at UMD, describe how the design of Apple's WPS facilitates mass surveillance, even of those not using Apple devices.

theregister EN 2024 Apple Wi-Fi Positioning WPS privacy abused
A root-server at the Internet’s core lost touch with its peers. We still don’t know why. https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/
23/05/2024 21:10:50
QRCode
archive.org
thumbnail

For 4 days, the c-root server maintained by Cogent lost touch with its 12 peers.

arstechnica EN 2024 DNS c-root Cogent delay
CVE-2024-4978: Backdoored Justice AV Solutions Viewer Software Used in Apparent Supply Chain Attack | Rapid7 Blog https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/
23/05/2024 16:57:07
QRCode
archive.org
thumbnail

Justice AV Solutions (JAVS) is a U.S.-based company specializing in digital audio-visual recording solutions for courtroom environments. According to the vendor’s website, JAVS technologies are used in courtrooms, chambers and jury rooms, jail and prison facilities, and council, hearing, and lecture rooms. Their company website cites over 10,000 installations of their technologies worldwide.

rapid7 EN 2024 Backdoored JusticeAV US CVE-2024-4978
When privacy expires: how I got access to tons of sensitive citizen data after buying cheap domains https://inti.io/p/when-privacy-expires-how-i-got-access
22/05/2024 19:41:24
QRCode
archive.org

Cybersecurity has always been transient: what is deemed to be secure today, may be considered easily hackable tomorrow. Domain names in web and e-mail addresses, such as info@inti.io, are leased in time. This means that if nobody thinks of renewing them after they expire, they will be put up for sale. It made me wonder what would happen to the graveyard of cloud accounts attached to the e-mail addresses that once belonged to these expired domains.

inti.io EN 2024 privacy expired domains research
Criminal record database of millions of Americans dumped online https://www.malwarebytes.com/blog/news/2024/05/criminal-record-database-of-millions-of-americans-dumped-online
22/05/2024 13:20:08
QRCode
archive.org
thumbnail

A notorious cybercriminal involved in breaches has released a database containing 70 million US criminal records.

malwarebytes EN 2024 US Criminal record database leak dumped
CVE-2023-34992: Fortinet FortiSIEM Command Injection Deep-Dive https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/
20/05/2024 14:35:51
QRCode
archive.org
thumbnail

CVE-2023-34992 Fortinet FortiSIEM Command Injection Deep-Dive and Indicators of Compromise. This blog details a command injection vulnerability which allows an unauthenticated attacker to access the FortiSIEM server as root to execute arbitrary commands.

horizon3 EN 2024 cve-2023-34992 research PoC FortiSIEM IoCs
Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code https://thehackernews.com/2024/05/critical-flaws-in-cacti-framework-could.html
20/05/2024 11:41:33
QRCode
archive.org

The maintainers of the Cacti open-source network monitoring and fault management framework have addressed a dozen security flaws, including two critical issues that could lead to the execution of arbitrary code.

thehackernews EN cacti vulnerability CVE-2024-25641 CVE-2024-29895
'Got that boomer!': How cybercriminals steal one-time passcodes for SIM swap attacks and raiding bank accounts | TechCrunch https://techcrunch.com/2024/05/13/cyber-criminals-stealing-one-time-passcodes-sim-swap-raiding-bank-accounts/
20/05/2024 10:16:50
QRCode
archive.org
thumbnail

The incoming phone call flashes on a victim’s phone. It may only last a few seconds, but can end with the victim handing over codes that give cybercriminals the ability to hijack their online accounts or drain their crypto and digital wallets.

“This is the PayPal security team here. We’ve detected some unusual activity on your account and are calling you as a precautionary measure,” the caller’s robotic voice says. “Please enter the six-digit security code that we’ve sent to your mobile device.”

techcrunch EN 2024 scam passcode PayPal SIM swap attacks SIM-swapping
QNAPping At The Wheel (CVE-2024-27130 and friends) https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/
20/05/2024 10:09:52
QRCode
archive.org
thumbnail

Infosec is, at it’s heart, all about that data. Obtaining access to it (or disrupting access to it) is in every ransomware gang and APT group’s top-10 to-do-list items, and so it makes sense that our research voyage would, at some point, cross paths with products intended to manage - and safeguard - this precious resource.

watchtowr EN 2024 CVE-2024-27130 QNAPping QNAP NAS IoT vulnerability
Andrew Tate’s The Real World exposes 22M user messages https://cybernews.com/security/tates-real-world-exposes-user-messages/?ref=news.risky.biz
20/05/2024 10:06:10
QRCode
archive.org

The Real World, a learning platform from the controversial social media personality Andrew Tate, has leaked nearly a million users and over 22 million messages.

Hundreds of thousands of exposed users, millions of messages, and session tokens – that’s the reality that The Real World finds itself in.

The Cybernews research team has uncovered an exposed MongoDB instance with 88GB from one of The Real World’s servers.

cybernews EN 2024 The-Real-World Andrew-Tate dataleak messages MongoDB
Exclusive: Flutterwave loses ₦11 billion in security breach https://techcabal.com/2024/05/16/exclusive-flutterwave-loses-%E2%82%A611-billion-in-security-breach/?ref=news.risky.biz
20/05/2024 10:05:26
QRCode
archive.org
thumbnail

One month after obtaining a court order to recover $24 million lost to unauthorised POS transactions, Flutterwave suffered another security breach that allowed unknown persons to divert billions of naira to several bank accounts.

The perpetrators illegally transferred ₦11 billion ($7 million) to several accounts in April 2024, one financial services insider with direct knowledge of the incident said. A second insider claimed the amount involved was at least ₦20 billion ($13.5 million).

techcabal EN 2024 Flutterwave POS transactions breach
Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee | CNN Business https://edition.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk/index.html?ref=news.risky.biz
20/05/2024 10:04:17
QRCode
archive.org
thumbnail

A British multinational design and engineering company behind world-famous buildings such as the Sydney Opera House has confirmed that it was the target of a deepfake scam that led to one of its Hong Kong employees paying out $25 million to fraudsters.

A spokesperson for London-based Arup told CNN on Friday that it notified Hong Kong police in January about the fraud incident, and confirmed that fake voices and images were used.

“Unfortunately, we can’t go into details at this stage as the incident is still the subject of an ongoing investigation. However, we can confirm that fake voices and images were used,” the spokesperson said in an emailed statement.

cnn EN 2024 deepfake Arup CEO-fraud Hong-Kong
Microsoft will require MFA for all Azure users https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/microsoft-will-require-mfa-for-all-azure-users/ba-p/4140391?ref=news.risky.biz
18/05/2024 22:55:24
QRCode
archive.org
thumbnail

Multi-factor authentication makes you, your company and your cloud investments safer

microsoft EN 2024 announce announcement MFA Azure Multi-factor authentication
Cybercriminals Exploit Docusign With Customizable Phishing Templates https://abnormalsecurity.com/blog/cybercriminals-exploit-docusign
17/05/2024 09:27:38
QRCode
archive.org
thumbnail

Cybercriminals are abusing Docusign by selling customizable phishing templates on cybercrime forums, allowing attackers to steal credentials for phishing…

abnormalsecurity EN 2024 phishing customizable templates credentials business docusign selling cybercrime forums Docusign
Russian hackers use new Lunar malware to breach a European govt's agencies https://www.bleepingcomputer.com/news/security/russian-hackers-use-new-lunar-malware-to-breach-a-european-govts-agencies/#google_vignette
17/05/2024 09:25:27
QRCode
archive.org
thumbnail

Security researchers discovered two previously unseen backdoors dubbed LunarWeb and LunarMail that were used to compromise a European government's diplomatic institutions abroad.

bleepingcomputer EN 2024 APT Lunar LunarMail LunarWeb Malware Turla
To the Moon and back(doors): Lunar landing in diplomatic missions https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/
17/05/2024 09:22:41
QRCode
archive.org
thumbnail

ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs

welivesecurity EN 2024 Lunar toolset Turla APT EU European ministry analysis
Log4j Exploited by XMRig Cryptominer Malware: Analysis & Mitigation https://www.uptycs.com/blog/log4j-campaign-xmrig-malware
16/05/2024 16:56:08
QRCode
archive.org
thumbnail

Learn how the Log4j vulnerability (CVE-2021-44228) is exploited by XMRig cryptominer malware. Discover attack methods, indicators, and effective mitigation strategies.

uptycs EN 2024 Log4j XMRig Cryptominer Malware CVE-2021-44228
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/
16/05/2024 16:15:33
QRCode
archive.org
thumbnail

Microsoft Threat Intelligence has observed Storm-1811 misusing the client management tool Quick Assist to target users in social engineering attacks that lead to malware like Qakbot followed by Black Basta ransomware deployment.

microsoft EN 2024 QuickAssist Ransomware Qakbot BlackBasta
Employee Personal GitHub Repos Expose Internal Azure and Red Hat Secrets https://www.aquasec.com/blog/github-repos-expose-azure-and-red-hat-secrets/
16/05/2024 16:00:38
QRCode
archive.org
thumbnail

Our research reveals that personal repositories often expose sensitive corporate data, leading to severe security breaches

aquasec EN 2024 GitHub Repos Exposed Redhat Microsoft tokens
Cyber Official Speaks Out, Reveals Mobile Network Attacks in U.S. https://www.404media.co/email/79f7367c-bd3c-4bff-ac9f-85c738d08bec/?ref=daily-stories-newsletter
16/05/2024 15:21:49
QRCode
archive.org
thumbnail

A CISA official breaks with the government narrative and tells the FCC that SS7 and similar networks and protocols have been used to track people in the U.S. in recent years.

404media EN 2024 SS7 spy tracking position people US
page 95 / 214
4873 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn