Plus récents

IRIS is a web collaborative platform for incident response analysts allowing to share investigations at a technical level. This project is in its early stage. It can already be used in production, but please set backups of the database and DO NOT expose the interface on the Internet.

dfir-iris.github.io/

📈 40% d'attaques en + sont menées par semaine en 2021, par rapport à 2020. Le monde de la cybercriminalité ne cesse de prendre de l'ampleur et le paysage des cybermenaces évolue rapidement. A quoi faut-il faire attention ?

globalsecuritymag.fr/Eviter-le

A group linked to Chinese intelligence was found distributing Flagpro in two stages via phishing emails. Flagpro is in the wild from October 2020 and was found targeting companies operating in , and sectors.

insight-jp.nttsecurity.com/pos

How Log4j vulnerabilities affect a lot of devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.

trendmicro.com/en_us/research/

🇫🇷 French regulators have hit Google and Facebook with 210 million euros ($237 million) in fines over their use of « cookies », the data used to track users online. The fines were based on an earlier EU law, the General Data Protection Regulation

rfi.fr/en/france-hits-google-f

Scammers are really doing is setting up a Google Voice account in your name using your real phone number as verification. Once set up, they can use that Google Voice account to conduct any number of scams against other victims that won't come back directly to crooks. They can also use that code to gain access to, and take over, your Google Gmail account.

fbi.gov/contact-us/field-offic

L'armée suisse proscrit (enfin) les messageries Facebook Whatsapp, Signal, Telegram,.. lors des opérations de service, lui préférant la messagerie suisse Threema. threats

la-croix.com/L-armee-suisse-ba

L'agence fédérale américaine du commerce (FTC) gonfle ses muscles afin de créer un rapport de force en menaçant d'utiliser toute son autorité légale pour poursuivre en justice les entreprises qui ne protégent pas les données des consommateurs contre l'exposition à des vulnérabilités connues

lemondeinformatique.fr/actuali

CVE-2021-20047 - SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in RCE in the target system.

cyberis.co.uk/blog/CVE-2021-20

Passer par les sous-traitants attaquer des grands groupes est une technique établie. Terminé les escarmouches, ce sont de vraies batailles que se livrent états, services secrets, entreprises et électrons libres du dark web. Avec, comme dans le champ du terrorisme, une frontière parfois très poreuse entre cyberguerre et cybercriminalité.

le-tout-lyon.fr/a-lyon-les-age

New Zloader campaign exploits Microsoft's Signature Verification putting users at risk. 🔥 This banking malware designed to steal user credentials and private information is back with a simple yet sophisticated infection chain.

research.checkpoint.com/2022/c

Increasing incidence of cyberattacks will be a key driver fueling the mobile security software market. Mobile market size is estimated to grow by USD 2.75 billion from 2021 to 2025 at a CAGR of 10% with the enterprises segment having largest market share.

technavio.com/report/mobile-se

Plus anciens