#Microsoft #Azure Exposed & Not Secured Endpoints Lead To PII leak #cyber #threats #informatique
https://github.com/jonathandata1/microsoft_azure_personally_identifiable_info_leak
Update on Windows 11 minimum system requirements and the PC Health Check app #microsoft #windows
Windows 11 : #Microsoft met à jour la configuration matérielle minimale requise tout en permettant aux autres appareils d'effectuer une installation manuelle #windows
A new ransomware family that emerged last month comes with its own bag of tricks to bypass ransomware protection by leveraging a novel technique called « intermittent encryption ». Called LockFile, the operators of the ransomware has been found exploiting recently disclosed flaws such as ProxyShell and PetitPotam to compromise #Microsoft #Windows servers and deploy file-encrypting #malware that scrambles only every alternate 16 bytes of a file, thereby giving it the ability to evade #ransomware defences.
https://thehackernews.com/2021/08/lockfile-ransomware-bypasses-protection.html
FBI agents appear to have been misusing a #digital evidence vault, causing privacy concerns and drawing attention to a secretive program created by the CIA-funded company Palantir. It's raising questions about FBI's shoddy track record of protecting #Americans' #privacy. #usa #cyber #threats
https://www.thedailybeast.com/fbi-screwup-lets-agents-access-information-they-werent-supposed-to-see
A team of scientists from a Swiss university has discovered a way to bypass PIN codes on contactless cards from Mastercard & Maestro #carding #banking #threats
https://therecord.media/academics-bypass-pins-for-mastercard-and-maestro-contactless-payments/
Z3 is a powerful framework developed by Microsoft Research. Given a list of restrictions and conditions, Z3 finds one solution that satisfies them all, if that solution exists. It can be used for multiple purposes but some known uses in security are exploiting or checking firewall rules. It is also a handy tool for solving many CTF challenges related to encryption and keygen generation.
https://infosecadalid.com/2021/08/27/my-introduction-to-z3-and-solving-satisfiability-problems/
A survey, based on a global sample of 1,430 senior cybersecurity executives, reveals data breach fears as 90% of businesses see rise in cyber attacks. Ireland's IT leaders are worried and it's easy to understand why. « Cyber attacks are becoming more frequent, more damaging, longer-lasting, and harder to anticipate. »
China's Microsoft hack may have had a bigger purpose than just spying - White House & Microsoft have said unequivocally that Chinese government-backed hackers are to blame. « There is a long-term project underway. We don't know what the Chinese are building, but what we do know is that diversity of data, quality of data aggregation, accumulation of data is going to be critical to its success. » ( Kiersten Todt ) #usa #cyber #threats
American policymakers need to recognize that one of the Kremlin's goals include being a #cyber superpower. « In the ongoing revolution in information technologies, information & psychological #warfare will largely lay the groundwork for victory. » #ngw
https://www.defenseone.com/ideas/2021/08/curious-omission-russias-new-security-strategy/184854/
VaxiCode Vérif : Le ministère de la Santé et des Services sociaux indique avoir déposé des « plaintes formelles » à la police pour qu'elle mène enquête concernant le vol et l'usurpation des codes QR de plusieurs élus de l'Assemblée Nationale #canada #santé #covid #passsanitaire #informatique
VaxiCode Vérif : Un individu télécharge illégalement les preuves vaccinales du Premier Ministre François Legault et d'une dixaine de politiciens #canada #santé #covid #passsanitaire #informatique
VaxiCode Vérif : Un individu créer de faux passeports vaccinaux pour des personnes fictives. La communauté du Hackfest a contribué à trouver une dizaine de problèmes avant même que les applications soient disponibles en téléchargement #canada #santé #covid #passsanitaire #informatique
https://ici.radio-canada.ca/nouvelle/1819589/passeport-vaccinal-faille-application-vaxicode
« Worst cloud vulnerability you can imagine » discovered in #Microsoft #Azure. Microsoft only emailed 30% or so of its Cosmos DB customers about the vulnerability #vuln
The operators of the Phorpiex #malware have shut down their #botnet and put its source code for sale on a dark web. This botnet isn't as secure as other malware #botnets and has often been hijacked by third parties
https://therecord.media/phorpiex-botnet-shuts-down-source-code-goes-up-for-sale/
#Microsoft warned thousands of its #cloud computing customers, including some of the world's largest companies, that intruders could have the ability to read, change or even delete their main databases. The vulnerability is in Microsoft Azure's flagship Cosmos DB database. #vuln #windows #informatique
#Python context free payloads in template engine, Mako #informatique
https://podalirius.net/en/articles/python-context-free-payloads-in-mako-templates/
DirtyMoe is a complex malicious #backdoor employing various self-protection and anti-forensics mechanisms. The driver provides key functionalities to hide malicious processes, services, and registry keys. #windows #rootkit #threats
https://decoded.avast.io/martinchlumecky/dirtymoe-rootkit-driver/
sc(r)apy | full metal packets
> We Are the Borg
> You Will be Assimilated
> Resistance is Futile