ITS (iThemes Security) < 7.9.1 souffre d'un bug de lecture de GET/POST/REQUEST pouvant mener à la page wp-login de WordPress. Le but de ce module est donc cassé.
Quand vous connaissez le nom de la nouvelle page de connexion, vous êtes redirigé vers la page de connexion avec le nouveau paramètre agissant tel un jeton secret, il s'agit de itsec-hb-token. Puisque ce paramètre est en GET, Google (ou d'autres moteurs) peut l'indexer, voilà pourquoi vous pouvez sans difficulté trouver ces jetons sur les moteurs de recherche.
https://secupress.me/fr/blog/ithemes-security-7-9-1-hide-backend-bypass/
Le service informatique du centre de lutte contre le cancer François-Baclesse, à Caen, a détecté et bloqué un virus informatique de type « ver » le 21 avril 2021 à 21 h. Aucune donnée perdue, volée ou cryptée.
Les systèmes informatiques de certains établissements des Instituts Médicos-Sociaux de Ciney (imsciney.be
) paralysés suite à une attaque informatique. Les deux structures concernées sont La Séniorerie d’Omalius (seniorieweb.be
) qui accueille des personnes âgées et les Chemins d’Arianne (les-chemins-dariane.be
), une résidence pour personnes handicapées.
The Donot Team APT organization (APT-C-35) is an Advanced Persistent Threat (APT) group that targets organizations having a government background. The threat group is known to carry out APT attacks against Pakistan, China, and countries in South Asia. In addition to spreading malware via spear phishing emails with attachments containing either a vulnerability or a malicious macro, this group is particularly good at leveraging malicious Android APKs in their target attacks.
https://cybleinc.com/2021/04/21/donot-team-apt-group-is-back-to-using-old-malicious-patterns/
Relative Path Traversal Attack on note creation - An attacker can read arbitrary .md files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path traversal
https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-p528-555r-pf87
Les systèmes informatiques et téléphoniques de la commune de Bourg Saint Maurice en grande difficulté depuis dimanche 25 avril 2021 suite à une attaque informatique impliquant un #ransomware.
MISP Galaxy v2.4.142 have been released
A software bug let #malware bypass macOS security defenses
With knowledge of how the bug works, Wardle asked Mac security company Jamf to see if there was any evidence that the bug had been exploited prior to Owens' discovery. Jamf detections lead Jaron Bradley confirmed that a sample of the Shlayer malware family exploiting the #bug was captured in early January, several months prior to Owens' discovery.
Shlayer is an adware that intercepts encrypted web traffic - including HTTPS-enabled sites - and injects its own ads, making fraudulent ad money for the operators.
All the user would need to do is double click - and no #macOS prompts or warnings are generated
https://techcrunch.com/2021/04/26/shlayer-mac-malware-macos-security/
Linux kernel 5.12 has been released
Average internet speed across #Europe
https://datavis.europeandatajournalism.eu/obct/connectivity/
Babuk #Ransomware Gang Targets Washington DC Police - The RaaS developers thumbed their noses at police, saying « We find 0 day before you :þ »
https://threatpost.com/babuk-ransomware-washington-dc-police/165616/
Emotet démantelé : le cas juridique des #botnets
https://www.silicon.fr/emotet-demantele-juridique-botnets-406132.html
Ransomware pode ter derrubado sistema de reservas de 20 linhas aéreas
https://www.cisoadvisor.com.br/ransomware-derrubou-sistema-de-reservas-de-20-linhas-aereas/
10,000+ of ABUS Secvest smart alarm systems are currently unpatched and vulnerable to a bug that would allow miscreants to remotely disable alarm systems and expose homes and corporate headquarters.
https://therecord.media/10000-unpatched-home-alarm-systems-can-be-deactivated-remotely/
Experian's Credit Freeze Security is Still a Joke
https://krebsonsecurity.com/2021/04/experians-credit-freeze-security-is-still-a-joke/
Supply chain attack on the password manager Clickstudios - PASSWORDSTATE
https://www.csis.dk/newsroom-blog-overview/2021/moserpass-supply-chain/
Live Swapping NAND Flash
Data From The Emotet Malware is Now Searchable in Have I Been Pwned
Samedi dernier, Laurent Perrier a annoncé avoir détecté une intrusion sur son réseau informatique.
sc(r)apy | full metal packets
> We Are the Borg
> You Will be Assimilated
> Resistance is Futile