The Untold Story of the RSA Breach - In March, 2011, RSA was facing a terrible dilemma. An attacker siphoned data relating to SecureID, the company's flagship product used by thousands of high-profile clients around the world - but it was unknown whether the attacker also stole the cryptographic key needed to decipher that data.
The Untold Story of the RSA Breach - No longer bound by NDA, former RSA execs tell how the infamous breach unfolded and share the untold story behind one of the most impactful cyber attacks of all time.
https://www.cybereason.com/blog/the-untold-story-of-the-rsa-breach-part-1
🇪🇺 #Europe - Today's agreement provides for a derogation to articles 5(1) and 6(1) of the ePrivacy directive, to allow providers to continue to detect, remove and report Child Sexual Abuse Material and apply anti-grooming #technologies. In December 2020, the comprehensive European Electronic Communications Code (EECC) entered into application, bringing with it a new definition of electronic communications services. This definition encompasses «number-independent interpersonal communications services » (NI-ICS), which includes messaging services. This temporary measure allow providers of electronic communications services such as web-based #email and #messaging services to continue to detect, remove and report child sexual abuse online.
🇪🇺 #Europe - Le certificat de vaccination numérique - Lifting restrictions on vaccinated passengers is a step forward. We urge EU States to implement the « recommendation » ( #digital identity management, #biometric recognition,.. ) A digital European COVID-19 vaccination certificate will be adopted soon. This certificate is expected to be ready by July 1, 2021. Through an app, passengers can share their status and the digital test certificates with authorities, airports, and airlines. Unilabs will be able to securely and efficiently manage test results. IATA is the global trade association of airlines. Their members comprise 82% of total air traffic in the world.
🇪🇺 #Europe - Session I - Enabling #contactless travel: e-Visa #Schengen, #digital identity and travel credentials
Session II - Enabling contactless travel : #Biometric #technologies
Les généalogistes aux racines angevines devront se passer des archives en ligne pendant ce long week-end de Pentecôte. Le site Internet des Archives départementales du Maine-et-Loire est annoncé indisponible du 21 au 24 mai inclus. Cette fermeture est rendue nécessaire par le transfert d'une partie des serveurs informatiques du Département vers le nouveau Datacenter de l’Université d’Angers sur le campus de Belle-Beille.
Les chercheurs ne pourront malheureusement pas se rabattre sur le site des archives patrimoniales de la ville d'Angers, vidé de son contenu depuis l'attaque informatique ( ransomware ) dont ont été victimes les services informatiques de la mairie d'Angers et d'Angers Loire métropole, mi-janvier 2021. Un retour à la normale est envisagé « au mieux en septembre 2021, sous réserves des bonnes avancées techniques »
https://www.rfgenealogie.com/infos/maine-et-loire-archives-en-rade-pendant-la-pentecote
A large library in Montreal will be closed until Tuesday morning in the wake of a hacking attack on Quebec's public daycare registration website. The Bibliothèque et Archives nationales du Québec (BAnQ) says it has temporarily shut down some of its computer systems. The personal data of 5,000 parents and children was compromised. The Treasury Board says the hack took place due to unspecified vulnerabilities in the software. The website was developed by Montreal-based InMedia Technologies, according to a client list posted on its website.
The continually increasing frequency and severity of cyberattacks, especially ransomware attacks, have led insurers to reduce cyber coverage limits for certain riskier industry sectors [...] and for public entities and to add specific limits on #ransomware coverage
The findings come amid a period of unprecedented scrutiny for the #cyber #insurance #industry, as multimillion-dollar ransoms come to light and cybercriminals appear to target insurers for a list of their clients to extort.
CNA Financial, a major U.S. insurer, paid its digital extortionists $40 million in what some analysts described as a record ransom. Meanwhile, Colonial Pipeline, the main artery for delivering fuel to the East Coast, paid hackers $4.4 million for decryption keys.
https://www.cyberscoop.com/cyber-insurance-ransom-hack-payments-gao/
Ransomware Gang Shutters Operations after Making $365,000 in One Month
« All of our data is potentially compromised » The HSE has secured injunctions from the High Court restraining any sharing, processing, selling or publishing of data stolen from its computer systems in cyberattack.
« Cybergang » provides decryption tool to unlock HSE systems
Un échantillon de données de santé concernant des patients irlandais diffusés suite à la compromission du système informatique de santé publique irlandais (HSE).
Cisco Talos recently discovered an exploitable integer overflow vulnerability in Apple macOS' SMB server that could lead to information disclosure.
https://blog.talosintelligence.com/2021/05/vuln-spotlight-smb-information-disclosure.html
In the first three months of 2021 alone, researchers found 7 million malicious emails sent from Microsoft 365 and a staggering 45 million sent from Google's infrastructure, Proofpoint reported, adding that cybercriminals have used Office 365, Azure, OneDrive, SharePoint, G-Suite and Firebase storage to send phishing and host attacks.
The Islamic Revolutionary Guards Corps and the Iranian regime's Ministry of Intelligence and Security have a sophisticated cyber setup whose toxic output affects every continent.
https://www.upi.com/Top_News/Voices/2021/05/17/iran-Iran-cyberattacks-West/1521621252268/
Une partie des systèmes informatiques et téléphoniques du groupe français Berger-Levrault (berger-levrault.com
) partiellement paralysée suite à une attaque informatique avec utilisation de #ransomware. De grands comptes du secteur industriel, immobilier, transports, santé,.. utilisent quotidiennement les solutions logicielles développées par CARL Software qui, depuis 2018, est devenu CARL Berger-Levrault (carl-software.com
), actuel leader européen et n°1 en #France en GMAO & EAM.
sc(r)apy | full metal packets
> We Are the Borg
> You Will be Assimilated
> Resistance is Futile