[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> Richland Community College
Richland Community College a été victime d'une cyberattaque le 17 février, entraînant des perturbations importantes de ses systèmes, notamment la mise hors service des serveurs réseau, des téléphones et de certains e-mails départementaux. Bien que les cours en personne se poursuivent et que l'accès...
> Cazaubon
Le département du Gers en France a connu une augmentation des cyberattaques, comme en témoigne l'infection par un virus du serveur informatique de la mairie de Cazaubon. Le vice-amiral d’escadre Arnaud Coustillière souligne la structuration quasi industrielle des cyberattaquants et l'importance de l...
> BEC Groups Target Firms With Multilingual Impersonation Attacks
Combined, the two groups have launched BEC campaigns in at least 13 different languages
> Minneapolis Public Schools
Le district scolaire de Minneapolis a été victime d'une cyberattaque en février 2023, lors de laquelle des hackers ont volé des informations sensibles sur les élèves et les enseignants. Les responsables du district ont caché l'ampleur de la violation de données aux familles et aux élèves, en dépit d...
> City of Oakland Declares State of Emergency After Ransomware Attack
Core functions are intact, but the city has taken certain non-emergency systems offline
> Hackers Leverage PayPal to Send Malicious Invoices
The phishing email warned users that there had been fraud on the account
> Readline crime: exploiting a SUID logic bug
I discovered a logic bug in the readline dependency that partially reveals file information when parsing the file specified in the INPUTRC environment variable. This could allow attackers to move laterally on a box where sshd is running, a given user is able to login, and the user’s private key […]
> Quarter of Crypto Tokens Linked to Pump-and-Dump
Scammers made an estimated $30m in profits in 2022
> Experts Warn of Surge in Multipurpose Malware
The average malware variant now utilizes 11 TTPs
> [BugTales] REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB
Last year we published UnZiploc, our research into Huawei’s OTA update implementation. Back then, we have successfully identified logic vulnerabilities in the implementation of the Huawei recovery image that allowed root privilege code execution to be achieved by remote or local attackers. After Hua...
> UK Policing Riddled with Chinese CCTV Cameras
Security and ethical concerns raised by surveillance commissioner
> CVE-2022-44563: Huawei Recovery Update Zip ToC-ToU Vulnerability
We have identified a new Toc-ToU race condition vulnerability in Huawei’s recovery image implementation of SD-card based firmware updates. The vulnerability can be exploited to achieve arbitrary code execution in recovery mode, enabling unauthentic firmware updates, firmware downgrades to a known vu...
> Prefeitura de Marechal Floriano
La municipalité de Marechal Floriano a été victime d'une cyberattaque qui a crypté les données de la préfecture, rendant les services publics et le site officiel inaccessibles. Un rapport a été déposé auprès de la police civile et les techniciens ont isolé la menace, mais une grande partie des donné...
> Google Launches Privacy Sandbox Beta on Android 13 Devices
It is an initiative designed to limit user data sharing in digital advertising
> LockBit and Royal Mail Ransomware Negotiation Leaked
It shows the threat actor trying to convince Royal Mail to pay the ransom using various techniques
> cURL audit: How a joke led to significant findings
In fall 2022, Trail of Bits audited cURL, a widely-used command-line utility that transfers data between a server and supports various protocols. The project coincided with a Trail of Bits maker week, which meant that we had more manpower than we usually do, allowing us to take a nonstandard approac...
> Crypto-Stealing Campaign Deploys MortalKombat Ransomware
The attacks mainly targeted victims in the US but also in the UK, Turkey, and the Philippines
> Threat Analysis: VMware ESXi Attacks Soared in 2022
Recorded Future analyzed how threat actors have been exploiting VMware ESXi vulnerabilities over the past three years
> Sweetwater Union High School District
Le district scolaire Sweetwater Union a confirmé qu'une cyberattaque avait causé une panne de système de plusieurs jours en février. Les données personnelles des employés, des étudiants et des familles ont été compromises. L'attaque a été découverte en mai et le district a mis en place des mesures d...
> Microsoft Patches Three Zero-Day Bugs This Month
February Patch Tuesday contains updates for over 70 CVEs