Plus récents

The company Autodesk confirmed that it was hit by the same as the large-scale scam that attacked SolarWinds servers from Orion Network Management . The company is one of the most renowned in the field of creation and software, including programs such as AutoCAD

somagnews.com/autodesk-was-vic

Indonesian authorities have admitted that the -19 vaccination certificate of the nation's President (Joko Widodo aka Jokowi) has circulated and tried to explain that it's an indication of admirable transparency, rather than lamentable security

theregister.com/2021/09/06/jok

Backdoor Office365 and Microsoft AD by stealing AD FS certificate/key pair. Golden SAML attack will allow an attacker to:

  • Bypass MFA to Azure / Office365
  • Logon as any AD user regardless of password resets
  • Method is usually valid for a year

inversecos.com/2021/09/backdoo

John Donovan, CISO at Malwarebytes (malwarebytes.com) about the impact stress has on information security teams

youtube.com/watch?v=x82U3hMR5h

Investigation into recent attacks by a affiliate reveals that that the attackers initially accessed targeted organizations' networks with ProxyShell, an exploit of vulnerabilities in Exchange that have been the subject of multiple critical updates over the past several months.

news.sophos.com/en-us/2021/09/

This PoC in generates payload when exploited for a 0-day of GhostScript 9.50. This exploit affect to ImageMagick with the default settings from Ubuntu repository #

github.com/duc-nt/RCE-0-day-fo

Les systèmes informatiques de la Société de transport de l'Outaouais (sto.ca) paralysés suite à une attaque

ottawa.ctvnews.ca/sto-targeted

Plus anciens