Le « pass sanitaire » qui est en train d'être mis en place par le gouvernement français entrera en vigueur le 9 juin 2021, tel qu'il est conçu, met en danger nos vies privées mais aussi nos données médicales. En outre, il accroit significativement le risque de vol d'identité. La confiance ne s'exige pas mais elle s'acquière par la vérité, la transparence, et des actes en accord avec les paroles et les engagements. Sur ce point, le pass sanitaire est un échec. #france #coronavirus #informatique #cyber #covid19
Les systèmes informatiques de PRB (prb.fr
) impactés par une attaque informatique perpétrée dans la nuit de vendredi 4 juin 2021.
Implantée aux Achards, près des Sables d'Olonne, PRB est spécialisée dans la production de revêtements de façade pour le bâtiment.
Connue pour être un des sponsors historiques de bateaux du Vendée Globe.
Production, livraisons et bureaux sont totalement à l'arrêt. Sur place les informaticiens de l'entreprise épaulés par un prestataire extérieur évaluent et réparent les dégâts provoqués par le #ransomware.
Les 650 salariés sont invités à rentrer chez eux.
The organizing committee for the Tokyo Olympics has become the latest to be hit by a data breach through unauthorized access to an information-sharing tool developed by Fujitsu Ltd. Personal information was leaked from a total of about 170 people who are involved in security management and have participated in a drill hosted by #Japan national #cyber security center to brace for potential cyberattacks during the sporting event. The leak was likely due to a #malware infection. Leaked information included names, business titles, affiliations of the participants belonging to about 90 organizations, including the organizing body of the Olympics and Paralympics, ministries, local governments hosting venues such as Tokyo and #Fukushima Prefecture, and sponsors of the games. Government agencies including the foreign and transport ministries have said at least 76,000 email addresses of government officials and external parties, such as members of panels, as well as study materials on creating a digital government, were breached.
https://www.japantimes.co.jp/news/2021/06/04/national/tokyo-olympics-data-breach/
Furniture Village the #UK's largest independent furniture retailer with 54 stores nationwide has been hit by a #cyber attack. At this stage, the true nature of the attack remains unclear, but some industry experts believe the retailer could be the victim of a #ransomware flingers. There has been no formal confirmation as to whether law enforcement agencies have been notified.
https://www.theregister.com/2021/06/04/furniture_village_confirms_cyberattack/
Threat actor took advantage of a WebLogic Remote Code Execution vulnerability (CVE-2020–14882) to gain initial access to the system before installing a coin miner (XMRig).
https://thedfirreport.com/2021/06/03/weblogic-rce-leads-to-xmrig/
Check out how RET2 Systems used 32gb of RAM to exploit a zero-day WebAssembly Vulnerability (CVE-2021-30734) in Apple Safari / JavaScriptCore at #Pwn2Own 2021
Axel Souchet build a PoC for CVE-2021-28476, a guest-to-host « Microsoft Hyper-V Remote Code Execution Vulnerability » in vmswitch.sys (CVE-2021-28476)
About Microsoft Windows Hyper-V vulnerabilities in vmswitch.sys
https://labs.bluefrostsecurity.de/advisories/bfs-sa-2021-001/
CVE-2021-21985 VCenter Pre-Auth RCE (Direct Shell)
The #VMware vSphere Client (HTML5) contains a Remote Code Execution vulnerability with severity rating of 9.8 out of 10 ( CVE-2021-21985 ) [ nmap -p443 --script CVE-2021-21985.nse
]
White House warns U.S companies to step up #cyber security : « We can't do it alone » - threats are serious and they are increasing.
https://www.reuters.com/technology/white-house-warns-companies-step-up-cybersecurity-2021-06-03/
UF Health-The Villages Hospital has been forced to operate by pen and paper thanks to a #ransomware attack which has shut down the computer system.
https://www.villages-news.com/2021/06/02/the-villages-hospital-crippled-by-ransomware-attack/
A dutch pizza #chain, New York Pizza (newyorkpizza.nl
), said they believe a hacker got its hands on the data of approximately 3.9 million users, a number that represents around 22% of the #Netherlands entire population. Stolen data includes pretty personal details, such as real names, delivery addresses, email addresses, telephone numbers, hashed passwords for NYP online accounts, past orders, and in some cases, even dates of birth.
https://therecord.media/dutch-pizza-chain-discloses-breach-after-hacker-tries-to-extort-company/
Mobile County cyberattack shut down systems for 3 days - The county, in a statement released to the media Wednesday, confirmed it discovered a malware affecting « certain systems »
The UL Hospitals Group is warning patients that service disruptions are set to continue into a fourth week as a result of the cyber attack / #ransomware on the HSE.
https://www.clare.fm/news/ul-hospitals-group-warning-patients-service-disruptions-continue/
ExaGrid is not just any old backup storage service company. No, the very first thing you see when you visit its website is a press release extolling the virtues of the « ransomware recovery solution ». According to reports, last month it shelled out $2.6 million worth of ransom in Bitcoin, after having had its systems encrypted and 800GB exfiltrated from its servers. Sounds like just the kind of product that might be handy to have in place before your company gets hit by.. uh-oh.
https://grahamcluley.com/backup-appliance-firm-pays-out-2-6-million-ransom-to-attackers/
Ransomware are the biggest threat to organizations such as police environments and systems and fire departments, municipalities, state agencies and public safety answering points (PSAPs). Cyber criminals are targeting public safety systems, especially inside of land-mobile-radio (LMR), PSAP and IT environments. A prime target is getting into 9-1-1 call handling centers through lateral movement by initially compromising their traditional IT networks or endpoint devices. ( Dr. Pranshu Bajpai, Security Architect )
The Avigilon (avigilon.com
) Cloud Services platform by Motorola Solutions makes it easy to remotely update ACC software and camera firmware across sites and monitor camera. VideoManager v15.0.1 software provides Motorola Solutions' body-worn cameras. Its integration with Avigilon Control Center (ACC) video management software (VMS) displays body-worn camera video feeds for investigations.
https://www.avigilon.com/products/motorola-solutions-integrations/body-worn-cameras/
CHICAGO (U.S) - June 2, 2021 - Malta Police Force has deployed Motorola Solutions VB400 body-worn cameras to all frontline officers across the Republic of Malta - they are widely adopted by frontline emergency teams including the National Police in #France Police, #Belgium Police, #Romania Police, #Romania Border Police, Metro Nashville Police, London Ambulance Services and multiple police forces across the #UK
sc(r)apy | full metal packets
> We Are the Borg
> You Will be Assimilated
> Resistance is Futile