Plus récents

CVE-2021-22045 - VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. Someone with access to a VM with CD-ROM device emulation may be able to exploit it in conjunction with other issues to execute code on the hypervisor from a virtual machine.

vmware.com/security/advisories

Purple Fox - The threat actors have noticed that the attacks generally take advantage of legitimate software for implementing malicious payloads. The vulnerability has been named CVE-2021-1732, and this vulnerability generally optimizes rootkit capabilities that are leveraged in their attacks.

blog.minerva-labs.com/maliciou

🇺🇸 IBEX Global Solutions, Inc. (ibex.co) announced that the company's IT systems were the target of a malware attack, resulting in sensitive consumer data of more than 174,000 people being compromised.

jdsupra.com/legalnews/data-bre

Russian businessman Vladislav Klyushin pleaded not guilty to participating in an $82 million insider trading scheme that relied on information stolen through hacking.

reuters.com/world/russian-busi

credential stuffing : more than 1.1 million online accounts compromised in cyberattacks at 17 well-known companies - « Right now, there are more than 15 billion stolen credentials being circulated across the »

ag.ny.gov/press-release/2022/a

🐘 Elephant Beetle, a financially motivated threat group targeting and infiltrating organizations from the finance and commerce sectors in Latin America. The group executes its attacks patiently over long periods of time, blending in with the target’s environment and going completely undetected while it quietly liberates organizations of large amounts of money.

blog.sygnia.co/elephant-beetle

Lnkbomb is used for uploading malicious shortcut files to insecure file shares. Malicious shortcut generator for collecting NTLM hashes

github.com/dievus/lnkbomb

🇨🇦 Weldco-Beales Manufacturing (weldco-beales.com) a canadian manufacturer of blades, buckets and other heavy equipment that is attached to tractors and excavators has acknowledged it suffered a security breach by the Karakurt hacking gang.

itworldcanada.com/article/cana

🇺🇸 McMenamins (mcmenamins.com), a family-owned chain of brewpubs, breweries,.. confirmed internal employee data dating back to January 1, 1998, was compromised in a ransomware attack.

oregonlive.com/silicon-forest/

🇺🇸 A suspected ransomware attack has impacted systems and services with Bernalillo County (bernco.gov). Buildings will be closed Wednesday. The county states that the Metropolitan Detention Center has canceled all visits for Wednesday.

krqe.com/news/politics-governm

🇫🇷 Attaques informatiques : Le manque de préparation des PME et TPE françaises en ce début de 2022 inquiète la Confédération des Petites et Moyennes Entreprises (CPME) qui se montre très préoccupée. Au strict minimum, disposer des sauvegardes de ses données et de ses applications.

larevuedudigital.com/etre-pret

Plus anciens