Plus récents

Plainte contre Google. Celui-ci génère systématiquement et illégalement un code de suivi sur les téléphones Android.

noyb.eu/fr/achetez-un-telephon

We no longer believe the « git.php.net » server has been compromised. However, it is possible that the master.php.net user database leaked

On March 28, unidentified actors used the names of Rasmus Lerdorf and Popov to push malicious commits to the « php-src » repository hosted on the git.php.net server that involved adding a backdoor to the PHP source code in an instance of a software supply chain attack.

news-web.php.net/php.internals

11 million records of French users stolen from marketing platform and put for sale online : A user on a popular hacking forum is selling a database that purportedly contains close to 11 million user records stolen from Apollo, a US-based sales engagement and digital marketing company.

The files contained in the leaked archive include a wide variety of information about the 10,930,000 France-based users whose data has been purportedly stolen, including their full names, phone numbers, location coordinates, workplace information, social media profiles, and more.

cybernews.com/security/11-mill

When it comes to protecting against credentials theft on Windows, enabling LSA Protection (a.k.a. RunAsPPL) on LSASS may be considered as the very first recommendation to implement. But do you really know what a PPL is ?

itm4n.github.io/lsass-runasppl

NOTICE OF DATA BREACH - Mendelson Kornblum Orthopedic and Spine Specialists

mendelsonortho.com/12575-2/

A standalone SIGMA-based detection tool for EVTX.

Zircolite is a standalone tool written in Python 3 allowing to use SIGMA rules on Microsoft Windows EVTX logs. Code is light (less than 500 lines) and simple. For now, evtx_dump is 64 bits only so if you use zircolite.py with evtx files as input you can only execute it on a 64 bits OS.

💾 github.com/wagga40/Zircolite

A recent change to the REvil allows the threat actors to automate file encryption via Safe Mode (-smode) after changing Windows passwords.
REvil also recently warned that they would perform DDoS attacks on victims and email victims' business partners.

bleepingcomputer.com/news/secu

An incident investigation conducted by Kaspersky ICS CERT experts at one of the attacked enterprises revealed that attacks of the Cring exploit a vulnerability in Fortigate VPN servers.

ics-cert.kaspersky.com/media/K

: Did you know that such malicious programs have been around for more than 30 years, and that researchers predicted many features of modern-day attacks back in the mid-1990s ?

kaspersky.com/blog/history-of-

China Creates Its Own Digital Currency, a First for Major Economy

A cyber yuan stands to give Beijing power to track spending in real time, plus money unlinked to the global financial system dominated by the dollar. It also could soften the bite of U.S. sanctions.

wsj.com/articles/china-creates

🇨🇭 Le projet fédéral de commandement Cyber a désormais un chef - Au 1er mai 2021, le divisionnaire Alain Vuitel prendra la tête du commandement de l'armée Suisse

ictjournal.ch/news/2021-04-06/

L'assureur CNA Canada a déconnecté les systèmes de son réseau pour endiguer l'attaque de rançongiciel. Comble de l'ironie, pour absorber les potentielles conséquences financières l'assureur se repose sur une couverture de cyberassurance.

portail-assurance.ca/article/v

Plus anciens