[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> ConnectWise Fixes XSS Vulnerability that Could Lead to Remote Code Execution
Threat actors could exploit the flaw to take complete control of the ConnectWise platform
> Google Releases Chrome Patch to Fix New Zero-Day Vulnerability
The high-severity vulnerability refers to a heap buffer overflow in the GPU component
> Prophete-Gruppe
La société Prophete, fabricant de vélos, a été victime d'une cyberattaque le 25 novembre 2022, qui a paralysé sa production, sa facturation et ses livraisons pendant environ trois semaines, contribuant ainsi à sa faillite. L'attaque a été immédiatement signalée au Landeskriminalamt (police criminell...
> Remote Code Execution Vulnerability Found in Windows Internet Key Exchange
The discovered vulnerabilities could have been exploited to target almost 1000 systems
> Experts Warn Remote Workers of Black Friday Security Threats
Shared devices can present corporate security risk
> Misconfigured Resource-Based Policies
Common misconfigurations of resource-based policies and how they can be abused.
> Experts Find 1600+ Malicious Docker Hub Images
Shared repository is also a hidden source of malware
> Global Police Celebrate $130m Cyber Busts
Almost 1000 arrested in Haechi III operation
> Abusing Misconfigured ECR Resource Policies
How to take advantage of misconfigured AWS ECR private repositories.
> Bahamut Spyware Group Compromises Android Devices Via Fake VPN Apps
The app used as part of the campaign was a trojanized version of SoftVPN or OpenVPN
> SharkBot Malware Found in Android File Manager Apps With Thousands of Downloads
The apps are no longer available on the Play Store, but can be found in third-party stores
> From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942)
This small series of two blog posts covers an entire vulnerability chain to go from unauthenticated user to full remote code execution against Intel's Data Center Manager (up to version 4.1.1.45749).The chain's first vulnerability bypasses DCM's entire authentication process.
> Sonder confirms data breach, documents and other PII potentially compromised
The company reportedly learned of unauthorized access to one of its systems on November 14
> Cyber Essentials Scheme Set for April 2023 Update
UK best practice security framework to offer new guidance
> Illustration des problématiques liées à l'intégration de logiciels non maitrisés (23 novembre 2022)
English version : 🇬🇧 De nombreux cadres réglementaires étrangers imposent l’utilisation de logiciels spécifiques aux entreprises présentes sur leur territoire. Si leur intégration ne pose généralement pas de problèmes techniques particuliers, ces logiciels peuvent être utilisés par des attaquants...
> UK Cops Lead Action Against Fraud Site that Made £100m+
Over 100 admins and users of iSpoof site arrested
> Russian DDoS Briefly Downs European Parliament Site
Parliament had declared Russia a state-sponsor of terrorism
> CTS (Conveyancing Transaction Services)
Un 'incident cybernétique' a touché environ 80 entreprises au Royaume-Uni, perturbant les transactions immobilières et empêchant l'accès aux systèmes. Le prestataire de services d'infrastructure spécialisé dans le secteur juridique, CTS, travaille avec des experts en cyberforensique pour résoudre le...
> Panaseer Launches Guidance on Security Controls Ahead of EU's New Legislation
The cybersecurity monitoring firm offers 18 recommendations on security controls to help organizations anticipate tougher cybersecurity regulations
> CISA Updates Guidelines to Increase Resilience of Infrastructure Planning
They expand the framework's scope by adding new resources and tools to support SLTT partners