Plus récents

Oracle - 390 new security fixes as part of the April 2021 Critical Patch Update (CPU), including patches for more than 200 bugs that could be exploited remotely without authentication. These patches address vulnerabilities in Oracle code and in third-party components included in Oracle products.

oracle.com/security-alerts/cpu

L'ancienne Commissaire des enfants en Angleterre, Anne Longfield, a lancé mardi une action en justice contre la plateforme de vidéos TikTok l'accusant d'avoir illégalement collecté des données personnelles de millions d'enfants au Royaume-Uni et en Europe.

7sur7.be/tech/tiktok-accuse-de

Une alerte du département de la sécurité intérieure américain a signalé que des pirates informatiques chinois ont exploité des faiblesses informatiques pour épier durant des mois des douzaines de cibles américaines et européennes de haute valeur dans les secteurs du gouvernement, de l’industrie de la défense, des finances.

lapresse.ca/international/etat

1.500 cartes Delhaize Plus vidées par un (ou des) pirate informatique. Les clients lésés ont été remboursés. Delhaize a déposé une plainte.

dhnet.be/actu/faits/1-500-cart

BazarLoader Malware Abuses Slack, BaseCamp Clouds : Two cyberattack campaigns are making the rounds using unique social-engineering techniques.

southwalesargus.co.uk/news/192

Max Justicz have found a remote code execution bug in the central CocoaPods server holding keys for the Specs repo (trunk.cocoapods.org/). CocoaPods is a popular package manager used by lots of iOS apps. This bug would have allowed an attacker to poison any package download. Keep calm, it's fixed now.

justi.cz/security/2021/04/20/c

BazarLoader Malware Abuses Slack, BaseCamp Clouds : Two cyberattack campaigns are making the rounds using unique social-engineering techniques.

threatpost.com/bazarloader-mal

Auto insurance giant Geico has admitted a data breach. Fraudsters exploited a bug in the company's website to steal customer driver's license numbers. This is the second time (recently) fraudsters have exploited a bug in an auto insurance company's website to steal driver's license numbers - often used to fraudulently obtain unemployment benefits.

techcrunch.com/2021/04/19/geic

Three zero-days in SonicWall products reported by Mandiant's Josh Fleischer and Chris DiGiamo (CVE-2021-20021) (CVE-2021-20022) (CVE-2021-20023)

sonicwall.com/support/product-

1-click code execution vulnerabilities in popular software : Telegram, Nextcloud, VLC, Libre-/OpenOffice, Bitcoin/Dogecoin Wallets, Wireshark, Mumble,..

positive.security/blog/url-ope

Discord ends sale talks with Microsoft. Microsoft has been on an acquisition spree following its failed bid for TikTok last summer.

reuters.com/business/discord-t

Remote Code Execution vulnerabilities in Cosori Smart Air Fryer, a WiFi-enabled kitchen appliance that cooks food with a variety of methods and settings.

blog.talosintelligence.com/202

Plus anciens