Plus récents

Disables Google's FLoC tracking for your Wordpress by adding a 'Permissions-Policy' HTTP header.

wordpress.org/plugins/disable-

Last summer, 580 cybersecurity researchers spent 13,000 hours trying to break into a new kind of processor called Morpheus. They all failed. University of Michigan's Todd Austin explains how his team's processor defeated every attack in DARPA's hardware hacking challenge.

spectrum.ieee.org/tech-talk/se

pfSense v2.5.1 est une mise à jour qui corrige de nombreux bugs apportés avec pfSense 2.5.0. Autre point, WireGuard est retiré de pfSense.

provya.net/?d=2021/04/15/09/46

This post introduces how one can debug the entire system including system management mode (SMM) code with Windbg and Direct Connect Interface (DCI). As an example use case, we will debug the exploit of the kernel-to-SMM local privilege escalation vulnerability I reported.

standa-note.blogspot.com/2021/

This is a report and an exploit of CVE-2021-26943, the kernel-to-SMM local privilege escalation vulnerability in ASUS UX360CA BIOS version 303 (github.com/tandasat/SmmExploit)

Codecov - On Thursday, April 1, 2021, we learned that someone had gained unauthorized access to our Bash Uploader script and modified it without our permission.

about.codecov.io/security-upda

Biden administration has a plan to harden the security of the US power grid to dramatically improve how power utilities defend themselves against attacks from countries considered to be adversaries in cyberspace - such as Russia, Iran, North Korea, and China.

tripwire.com/state-of-security

Tasmania's lone casino operator confirms it is being held to ransom in a cyber attack that has impacted its pokies machines and hotel bookings system for more than a week.

abc.net.au/news/2021-04-13/ran

Les serveurs informatiques et le système de messagerie de la ville d'Elancourt (elancourt.fr) perturbés par une attaque informatique

facebook.com/VilleElancourt/po

Suite à une infection par ransomware une partie de l'informatique du groupe In Extenso, spécialiste des services aux TPE et PME, est paralysée, jusqu’à la téléphonie de certaines de ses 250 agences en France

lemagit.fr/actualites/25249931

Brazil: Two arrested in global hunt to catch child predators

Extensive research and image analysis led the investigators to a social media profile that matched the victim and allowed them to identify the perpetrators as the victim's parents. The Federal Police acted immediately, arresting both of them the same day. Child sexual abuse material circulates in anonymous and dark corners of the Internet but, as this case shows, its human impact is real and devastating.

interpol.int/News-and-Events/N

An estate agent has been forced to apologise after exposing the seller's personal information in a virtual house tour. Unblurred family photos and financial documents were publicly visible in the 3D tour posted on Rightmove by Devon-based Fowlers. Confidential items such as a shares dividend cheque and an insurance policy paper and the names of beloved pets could be easily read by zooming in. Such viewing methods could be exploited by criminals.

dailymail.co.uk/news/article-9

🚨 A security researcher release PoC exploit for 0-day in Chrome, Edge, Brave, Opera

github.com/r4j0x00/exploits/tr

The vulnerability in Moodle ( an open-source educational platform used by 179,000 sites and has 242 million users ) had existed for 6 years before being discovered : millions of users of popular educational platform exposed..

wizcase.com/blog/moodle-vulner

Indian Supply-chain Giant Bizongo Suffered Devastating Data Breach (643GB - 2,532,610 files exposed)

Bizongo left customer data sitting unsecured on their misconfigured Amazon Web Services (AWS) S3 bucket, a widely-used cloud storage service.

websiteplanet.com/blog/bizongo

Plus anciens