[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Yanluowang Ransomware's Russian Links Laid Bare
Another dump of chat records provides insight into threat group
> UK Privacy Tsar Defends Controversial Enforcement Strategy
Information commissioner wants to avoid "money-go-round" of government fines
> Illustration des problématiques liées à l'intégration de logiciels non maitrisés (23 novembre 2022)
English version : 🇬🇧 De nombreux cadres réglementaires étrangers imposent l’utilisation de logiciels spécifiques aux entreprises présentes sur leur territoire. Si leur intégration ne pose généralement pas de problèmes techniques particuliers, ces logiciels peuvent être utilisés par des attaquants...
> Dozens of Russian Groups Steal 50 Million User Passwords
Info-stealing malware infected nearly one million devices in 2022
> CTS (Conveyancing Transaction Services)
Un 'incident cybernétique' a touché environ 80 entreprises au Royaume-Uni, perturbant les transactions immobilières et empêchant l'accès aux systèmes. Le prestataire de services d'infrastructure spécialisé dans le secteur juridique, CTS, travaille avec des experts en cyberforensique pour résoudre le...
> Ducktail Hacker Group Evolves, Targets Facebook Business Accounts
Activity observed since early September featured new avenues to spear-phish targets
> US Takes Down Domains Used in 'Pig Butchering' Cryptocurrency Scheme
The US Attorney's Office for the Eastern District of Virginia made the announcement on Monday
> Northeast Orthopedics and Sports Medicine
Le fournisseur de soins de santé New-Yorkais Northeast Orthopedics and Sports Medicine a été victime d'une cyberattaque qui a compromis les données personnelles de plus de 177 000 personnes, dont des patients, révélant des informations sensibles telles que les numéros de sécurité sociale, les inform...
> Firms Spend $1197 Per Employee Yearly to Address Cyber-Attacks
The data excludes compliance fines, ransomware costs and losses from non-operational processes
> Estonian Duo Arrested for Masterminding $575m Ponzi Scheme
US authorities unseal 18-count indictment
> Device Code Phishing Attacks
As more organizations move to hardware tokens and password-less auth (e.g. Yubi-keys, Windows Hello for Business,…) attackers will look for other ways to to trick users to gain access to their data. One novel phishing technique is by using the OAuth2 Device Authorization Grant. This post describes h...
> Experts Warn Threat Actors May Abuse Red Team Tool Nighthawk
C2 framework could be the next Cobalt Strike, says Proofpoint
> Credential Stuffers Steal $300K from DraftKings Customers
Complaints about poor customer service flood Twitter
> Ropci deep-dive for Azure hackers
Misconfigurations with MFA setups are not uncommon when using AAD, especially when federated setups or Pass Through Authentication is configured I have seen MFA bypass opportunities in multiple production tenants. A common misconfiguration is that MFA is enforced at the federated identity provider,...
> Google Wins Legal Battle Against Glupteba Botnet
The tech giant said the court's ruling against the botnet operators set a crucial legal precedent
> Thousands of Algolia API Keys Could Expose Users' Data
The majority were from shopping, education, lifestyle, business and medical firms
> Knowledge Base Digest - October 2022
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in October. Articles Full Disk Access Error in Endpoint Protection Service After Upgrade to macOS 13 Ventura Generate a .HAR file from your web browser macOS Ventura 13.x...
> Luna Moth Phishing Extortion Campaign Targets Businesses in Multiple Sectors
It leverages extortion without encryption and has cost victims hundreds of thousands of dollars
> Private Equity Exposed by Cyber-Hygiene Shortcomings
Fifth of portfolio companies feature "zero tolerance findings"
> ABI compatibility in Python: How hard could it be?
TL;DR: Trail of Bits has developed abi3audit, a new Python tool for checking Python packages for CPython application binary interface (ABI) violations. We’ve used it to discover hundreds of inconsistently and incorrectly tagged package distributions, each of which is a potential source of crashes an...