Plus récents

Une série d'attaques informatiques jugée de « terroriste » par le gouvernement bolivarien du a ciblé la principale banque du pays Banco de Venezuela, S.A. 

reseauinternational.net/venezu

Created in collaboration with a trusted law enforcement partner, this tool helps victims encrypted by to restore their files and recover from attacks made before July 13, 2021.

bitdefender.com/blog/labs/bitd

Three Former U.S. Intelligence Community & Military Personnel Agree to Pay More Than $1.68 Million to Resolve Criminal Charges Arising from Their Provision of Hacking-Related Services to a Foreign Government

justice.gov/opa/pr/three-forme

DOJ: Former NSA Operatives Worked as Cyber-Mercenaries - Members of the U.S. intelligence community and military have reached a deferred prosecution agreement over their role in an overseas cyber-mercenary business

gizmodo.com/doj-former-nsa-ope

U.S. President Joe Biden on Wednesday plans to announce a plan to share advanced technologies in a working group with Britain and Australia

reuters.com/world/us/biden-ann

(CVE-2021-3437) HP OMEN Gaming Hub (omen.com) A driver privilege-escalation « bug » gives attackers kernel-mode access to millions of PCs used for . HP put out a fix on Sept. 14, 2021.

sentinelone.com/labs/cve-2021-

City of Yonkers (yonkersny.gov) has been the victim of a attack and for the period of the past five days, City Hall and its employees have been without their computers

yonkerstimes.com/city-of-yonke

TTEC, [NASDAQ: TTEC], a company used by some of the world's largest brands to help manage customer support and sales online and over the phone, is dealing with disruptions from a network security...

krebsonsecurity.com/2021/09/cu

silently install management agents on VMs, which now have RCE & LPE vulnerabilities ! « OMI is just one example of a secret agent that's pre-installed and silently deployed in cloud environments » ; « Thanks to the combination of a simple conditional statement coding mistake and an uninitialized auth struct, any request without an Authorization header has its privileges default to uid=0, gid=0, which is root »

wiz.io/blog/secret-agent-expos

Les RSSI doivent plus que jamais s'attendre cette année à ce que les rançongiciels ciblent plus agressivement les infrastructures .

silicon.fr/avis-expert/rancong

La Compagnie Générale de Navigation (cgn.ch) sur le lac Léman (CGN) a été victime fin août d'une attaque sur son site internet, ciblant la procédure d'achat des billets. Les intrus ont réussi à voler les coordonnées bancaires de certains clients

lacote.ch/articles/regions/vau

Logs produced by the Audit subsystem and auditd contain information that can be very useful in a SIEM context

github.com/threathunters-io/la

Chimaera campaign - TeamTNT is using new, open source tools to steal usernames and passwords from infected machines. The group is targeting various operating systems including: , different distributions including Alpine (used for containers), , , and .

cybersecurity.att.com/blogs/la

Plus anciens