Plus récents

🚨 CVE-2021-1675 - Microsoft Windows Print Spooler Elevation of Privilege Vulnerability

🔥 Des codes d'exploitation sont publiquement disponibles (ITW), ce qui signifie que l'exploitation de cette vulnérabilité est imminente ou déjà en cours.

🖨 Ces codes exploitent la possibilité offerte par le service spouleur d'impression de téléverser un pilote, dans le cadre de l'ajout d'une nouvelle imprimante, pour installer un code malveillant. Or, par défaut, le service spouleur d'impression (print spooler) est activé sur les contrôles de domaine Active Directory.

Un attaquant, ayant préalablement compromis un poste utilisateur, pourra in fine obtenir les droits et les privilèges de l'administrateur de domaine Active Directory.

cert.ssi.gouv.fr/alerte/CERTFR

Les opérateurs de Vice Society revendiquent des attaques contre :

  • 🇨🇦 Filgo (filgo.ca)

  • 🇺🇸 Whitehouse Independent School District (whitehouseisd.org)

  • 🇺🇸 Alliance COAL, LLC (arlp.com)

  • 🇨🇭 Rolle (rolle.ch)

  • 🇳🇿 Waikato District Health Board (waikatodhb.health.nz)

  • 🇺🇸 Priority Building Services, LLC (priorityservices.net)

  • 🇸🇦 Communications Solutions Company (csc-sa.com)

  • 🇪🇸 JEALSA (jealsa.com)

  • 🇺🇸 McNamara & Thiel Insurance Agency (mtins.net)

  • 🇺🇸 FREDERICK Public Schools (frederickbombers.net)

Pas de place aux négociations pour ce groupe.

So this is the part of trash talks of customer. We delayed auction for 1.5 weeks, gave them chance. But... nothing happens. We continue upload data to leaks server. All registered users will receive messages about company, data and time when auction begin.

Afficher le fil de discussion

Les opérateurs de Lorenz revendiquent une attaque contre :

  • 🇺🇸 Refuah Health (refuahhealth.org)

Our team of doctors, specialists, and dentists work together to provide high-quality, comprehensive care. Our seamless coordinated care is fast and efficient, allowing our Members to focus less on their healthcare and more on their lives. Our mission is to provide high-quality, comprehensive medical, dental and supportive services to all patients, regardless of their ability to pay.

  • Analyse des propriétés de sécurité dans les implémentations du Bluetooth Low Energy
  • InjectaBLE : injection de trafic malveillant dans une connexion Bluetooth Low Energy
  • Hyntrospect : a fuzzer for Hyper-V devices
  • Vous avez obtenu un trophée : PS4 jailbreaké
  • HPE iLO 5 security : Go home cryptoprocessor, you're drunk!
  • From CVEs to proof : Make your USB device stack great again
  • Ne sortez pas sans vos masques ! Description d'une contre-mesure contre les attaques par canaux auxilliaires
  • Defeating a Secure Element with Multiple Laser Fault Injections
  • EEPROM : It Will All End in Tears
  • Runtime Security Monitoring with eBPF
  • Protecting SSH authentication with TPM 2.0
  • U2F2 : Prévenir la menace fantôme sur FIDO/U2F
  • The security of SD-WAN : the Cisco case
  • Taking Advantage of PE Metadata, or How To Complete your Favorite Threat Actor's Sample Collection
  • Exploitation du graphe de dépendance d'AOSP à des fins de sécurité
  • Return of ECC dummy point additions : Simple Power Analysis on efficient P-256 implementation
  • Monitoring and protecting SSH sessions with eBPF
  • Analyzing ARCompact Firmware with Ghidra

📎 (PDF) actes.sstic.org/SSTIC21/sstic-

Les opérateurs RagnarLocker revendiquent une attaque contre :

  • 🇹🇼 [1500GiB] ADATA Technology Co., Ltd (adata.com)

Fondée en 2001, A-Data est une importante société taiwanaise produisant des composants informatiques basés sur la mémoire. Taiwanese memory and storage manufacturer, founded in May 2001. Its main product line consists of DRAM modules, USB Flash drives, hard disk drives, solid state drives, memory cards, memory readers, USB chargers, power banks, wireless, mobile accessories. ADATA is also expanding into new areas, including robotics and electric powertrain systems. In 2017, ADATA was the second-largest DRAM module manufacturer in the world. Since, ADATA have extended its business to Europe and the Americas, while competing strongly with Samsung in Asia. Xtreme Performance Gear (XPG) (xpg.com) was established by ADATA with the aim of providing high-performance products to gamers, e-sports pros, and tech enthusiasts.

Les opérateurs de RansomExx diffusent des données relatives à :

Born 40 years ago, our company has been providing comprehensive assistance services to travelers ever since. Our global operations serve customers across five continents through our 24/365 multilingual call centers located across the world. Universal Assistance is part of Zurich Insurance Group, one of the world's leading providers of travel assistance and travel insurance. Zurich Insurance Group (Zurich) is a leading multi-line insurer that serves its customers in global and local markets.

Les opérateurs Grief revendiquent une attaque contre :

  • 🇺🇸 Warren Vicksburg School District (vwsd.org)

Warren Vicksburg School District is located in Vicksburg, MS, United States and is part of the Public Schools K-12 Industry. Warren Vicksburg School District has 965 total employees across all of its locations and generates $85.17 million in sales (USD). There are 24 companies in the Warren Vicksburg School District corporate family.

Les opérateurs LV revendiquent une attaque contre :

  • SMPDYNAMICS

Soit c'est une erreur de typographie soit cette société est discrète puisque nous n'avons pas été en mesure de l'identifier formellement.

Sur une capture d'écran figure l'interface d'un Payroll Software & Time Management dont le bandeau courant est positionné sur la série TV « The Gilded Age ».

Parmi les données d'autres échantillons figurent des informations (nom, prénom, adresse, numéro de sécurité sociale,..) d'actrices (Meghan Fitton, Tsikhanava Anastasiya, Juri Love,..) demeurant aux États-Unis (Massachusetts, New Hampshire, Rhode Island,..)

A suivre...

🇫🇷 - Les systèmes informatiques et téléphoniques du CASAS, la Communauté d'Agglomération Saint-Avold Synergie (agglo-saint-avold.fr), impactés par une attaque informatique par perpétrée dans la nuit du mercredi 2 juin 2021. Les données de sauvegardes ont également été chiffrées.

Les opérateurs de Avaddon revendiquent des attaques contre :

  • 🇮🇹 Estendo S.p.A (estendo.it)

Provides property and casualty insurance services. The company offers insurance policies for household electronic appliances.

  • 🇺🇸 Cormetech, Inc (cormetech.com)

A world leader in manufacturing of high-quality environmental catalysts, providing SCR catalyst regeneration and engineering services for the power, marine, industrial-process, refinery, and petrochemical markets.

  • 🇧🇪 Tetra Law (tetralaw.com)

Fondée en 2012, Tetra Law a connu un développement rapide et important basé sur les fondamentaux suivants :

  • 🇪🇸 Crystal Travel Retail S.L. (crystaltr.com)

Crystal Travel Retail fue fundada en el año 1995 por profesionales procedentes del sector “Duty Free” para cubrir las demandas de tiendas de electrónica en los aeropuertos. Desde entonces hemos abierto tiendas especializadas en electrónica en los Aeropuertos más importantes de España, habiendo iniciado recientemente nuestra expansión Internacional en Bélgica. Actualmente estamos ampliando nuestra diversificación tanto en otros aeropuertos internacionales como en otros sectores como la moda, regalo o complementos.

Les opérateurs de Avaddon revendiquent des attaques contre :

  • 🇲🇽 **Talma Servicios Aeroportuarios (talma.com.mx)

Pioneers in bonded warehouse services with more than 25 years of experience, Talma Peru and Talma México. In 2015 we have attended more than 1,750 flights and we have moved more than 34 metric tons of domestic and international air cargo. We are a company with more than 260 colleague experts trained under high international standards and operating in 3 stations: Mexico City, Toluca and Guadalajara. We have three business units: bonded warehouses, maneuvers and bonded trucking Service.

  • 🇺🇸 Sandlin Homes (sandlinhomes.com)

Founded in 1957, Sandlin Homes has been building superior quality, family homes in Texas for 60 years.

  • 🇺🇸 Timpanogos Harley-Davidson (timpharley.com)

One of the largest dealerships in the United States, our dealership harvested more than 75 percent of the materials from Geneva Steel to construct our 58,000 square-foot building.

A leading Kuwaiti Sharia'a compliant investment group established in 2005 and was listed on Bourse Kuwait in 2011.

Les opérateurs de Revil revendiquent une attaque contre :

Law Firm's Services. Based in Altamonte Springs, Fla., with additional offices in Tampa, Melbourne and Orlando, the Law Offices of Michael B. Brehne, P.A. provide personalized and dedicated legal representation to individuals throughout the Orlando area, as well as the greater Central Florida region.

👁 socat a partagé

Les systèmes informatiques de PRB (prb.fr) impactés par une attaque informatique perpétrée dans la nuit de vendredi 4 juin 2021.

Implantée aux Achards, près des Sables d'Olonne, PRB est spécialisée dans la production de revêtements de façade pour le bâtiment.

Connue pour être un des sponsors historiques de bateaux du Vendée Globe.

Production, livraisons et bureaux sont totalement à l'arrêt. Sur place les informaticiens de l'entreprise épaulés par un prestataire extérieur évaluent et réparent les dégâts provoqués par le .

Les 650 salariés sont invités à rentrer chez eux.

francebleu.fr/infos/faits-dive

En avril 2021, le Department of Justice (DOJ) créer la Ransomware Task Force (RTF), pilotée par l'Institute for Security and Technology (IST).

Christopher Wray, directeur du FBI, avait déclaré voir un parallèle entre les attaques ransomware et les attaques du 11 septembre 2001.

Aujourd'hui, le DOJ annonce qu'à l'avenir il traitera les cas d'attaques par ransomware comme des attaques terroristes.

(reuters.com/article/cyber-usa-)

Ci-dessous, les déclarations de l'un des opérateurs REvil.

Crédits: Gabriel Thierry

Les opérateurs de Xing 星Team revendiquent une attaque contre :

Blue Yonder (formerly JDA Software Group) is an American software and consultancy company, providing supply chain management, manufacturing planning, retail planning, store operations and category management offerings headquartered in Scottsdale, Arizona. The company has more than 5,500 employees and 3,000 corporate customers in the manufacturing, distribution, transportation, retail and services industries. Blue Yonder is the world's leading, end-to-end, digital supply chain platform provider, enabling companies to better predict and pivot to quickly fulfill customer demand. Blue Yonder’s intelligent platform empowers companies to make smarter, faster business and commerce decisions to deliver more growth, less waste and amazing customer experiences.

Les opérateurs de REvil revendiquent de multiples attaques contre :

Aspire Systems is a global technology services provider for our customers that span 150+ VC funded start-ups to Fortune 500 companies. We have technology expertise around Software Engineering, Digital Services,..

  • 🇺🇸 Sol Oriens, LLC (soloriensllc.com)

Veteran-owned consulting firm focused on managing advanced technologies and concepts with strong potential for military and space applications.

Wilson Sons is the largest integrated port and maritime logistics operator in Brazil. With over 180 years of history, we have complete solutions for various industries, such as oil and gas and foreign trade.

  • 🇺🇸 St. John Knits International, Inc (wilsonsons.com.br)

St. John Knits International Inc. is a luxury American fashion brand that specializes in women's knitwear founded in 1962 by Robert and Marie Gray.

  • 🇫🇷🇳🇱 Tendriade (tendriade.fr)

Société spécialisée dans l'abattage et la transformation des veaux. Tendriade a intégré le groupe néerlandais VanDrie Group Veal (vandriegroup.com) en fin d'année 2013. Tendriade has two locations for the slaughter and processing of meat, making it possible to guarantee delivery of really fresh products throughout France. Tendriade has a turnover of 200 million euro, slaughters 200,000 calves and produces approximately 30,000 tonnes of veal annually.

#

Les opérateurs de Xing 星Team diffusent des données relatives à :

  • 🇺🇸 Greenwood Fabricating & Plating (gfpi.com)

Founded in 1986 to service electrical equipment manufacturers. Since then, we have grown into a full service fabrication, machining, and electroplating job shop, providing finished components to a wide classification of manufacturers.
Incorporating the latest technology in design and manufacturing, we are capable of fabricating your most intricate parts and assemblies. And because of our ability to produce your parts from start to finish, we offer all the advantages of reduced inventories, shorter cycle times, one-point invoicing, and reduced scrap.

As the lead federal investigative agency fighting cyber threats, combating cybercrime is one of the FBI’s highest priorities. We have attributed the JBS attack to REvil and Sodinokibi and are working diligently to bring the threat actors to justice. We continue to focus our efforts on imposing risk and consequences and holding the responsible cyber actors accountable. Our private sector partnerships are essential to responding quickly when a cyber intrusion occurs and providing support to victims affected by our cyber adversaries. A cyberattack on one is an attack on us all. We encourage any entity that is the victim of a cyberattack to immediately notify the FBI through one of our 56 field offices.

fbi.gov/news/pressrel/press-re

Plus anciens

👁 socat recommande :

nanao

Comme le soleil, les machines ne se couchent jamais.