Plus récents

CVE-2021-41379 works in every supporting installation. Including Windows 11 & Server 2022 with November 2021 patch.

github.com/klinix5/InstallerFi

The top of the cybercriminal pyramid is represented by the for zero-days. It is an extremely expensive and competitive one, and it's usually been a prerogative of state-sponsored threat groups. However, certain high-profile cybercriminal groups (read: gangs) have amassed incredible fortunes and can now compete with the traditional buyers of exploits. During our investigation for this research piece we've noticed cybercriminals discussing ideas for an Exploit-as-a-Service model that would inevitably lower the barrier for accessing sophisticated .

digitalshadows.com/blog-and-re

Le site de Nature & Découvertes Suisse victime d'une attaque. Les données personnelles de plus de 200 clients ont été exfiltrées. Les personnes concernées ont été informées. L'incident technique a été identifié lors d'un contrôle. « Il y avait une faille de sécurité sur le système de gestion de contenu »

lenouvelliste.ch/articles/suis

A vulnerability at a CDSL subsidiary, CDSL Ventures Limited (CVL), has exposed personal and financial data of over 4 crore Indian investors twice in a period of 10 days

cyberx9.com/cdsl-data-exposed-

CVE-2021-43287 - GoCD instances - exploitability is high due to the fact that this vulnerability can be exploited in a single HTTP request

attackerkb.com/assessments/910

L'héritier du cyberattaquant de Mohamed bin Zayed, DarkMatter, s'allie à la start-up de l'ex-patron du Mossad. Beacon Red, la filiale dédiée à la guerre hybride du groupe de défense émirati EDGE Group, se rapproche de XM Cyber. Cette start-up cyber, fondée par l'ex-chef du Mossad, Tamir Pardo, va l'assister pour traiter des vulnérabilités informatiques [intelligenceonline]

Afficher le fil de discussion

<html><meta http-equiv="refresh" content="0; url=calculator://1234" /><body><h1>hacked</h1></body></html>&#10

A attack on University of Colorado Boulder in September 2021 compromised the personal information of approximately 30,000 current and former students and employees, the campus announced Monday. Attackers exploited a vulnerability in Atlassian software that CU Boulder’s Office of Information Technology

denverpost.com/2021/10/25/cu-b

This vulnerability allows a low-privilege user (such as www-data) to escalate his privileges to root using a bug in PHP-FPM, which has been present for 10 years (the patched release is PHP-8.0.12)

ambionics.io/blog/php-fpm-loca

💥 Nextcloud security vulnerabilities (CVE-2021-39220, CVE-2021-39221, CVE-2021-39222, CVE-2021-39223, CVE-2021-39224)

github.com/nextcloud/security-

CVE-2021-1529 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, LOCAL attacker to execute arbitrary commands with root privileges

tools.cisco.com/security/cente

CVE-2021-42299 Une preuve de faisabilité baptisée « TPM Carte Blanche » permet de faire passer pour sain un appareil qui ne l'est plus en manipulant des données au niveau TPM

github.com/google/security-res

Plus anciens