Plus récents

This report details a destructive cyberattack that impacted Ukrainian organizations on February 23rd, 2022, and a second attack that affected a different Ukrainian organization from February 24th through 26th, 2022. On February 23rd, 2022, a destructive campaign using HermeticWiper targeted multiple Ukrainian organizations. On February 24th, 2022, a second destructive attack against a Ukrainian governmental network started, using a wiper we have named IsaacWiper.

welivesecurity.com/2022/03/01/

Commercial operator Viasat is investigating a suspected cyberattack that caused a partial outage of its KA-SAT network in . data indicate that the incident began on 24 February ~4 a.m. UTC and is currently ongoing down.

cnbc.com/2022/02/28/ukraine-up

Statistiques:

Dashboard BazarLoader (aka BazarBackdoor) utilisé par les opérateurs Conti.

Afficher le fil de discussion

🇸🇪 Axis Communications (axis.com), a company whose network cameras & physical security are used by & private sector from around the world, was recently hit by a cyberattack that disrupted its operations. Post mortem is now available for the cyber attack that occurred on February 20, 2022.

status.axis.com

🇯🇵 Kojima Industries Corp (kojima-tns.co.jp) appeared to have been the victim of « some kind of cyber attack ». Toyota Motor Corp said it will suspend domestic factory operations on Tuesday, losing around 13,000 cars of output, after a supplier of plastic parts and electronic components was hit by a suspected cyber attack.

reuters.com/business/autos-tra

Le compte Twitter @ContiLeaks a laissé fuiter sur ce qui semble être des données relatives à l'espace de clavardage du . La communauté vx-underground s'est empressée de redistribuer les fichiers. Depuis, elle est confrontée à des salves d'attaques .

25 malicious packages in the npm repository. We were surprised to see an interesting case of authors targeting other malware authors. Hackers are still continuing to abuse npm with the goal of high ROI attacks, since the effort of developing and publishing a malicious package is so low. We estimate this trend will only continue to increase.

jfrog.com/blog/malware-civil-w

An unusual XSS vulnerability in the Horde webmailer. The vulnerability allows an attacker to craft a malicious OpenOffice document that, when previewed as an email attachment, enables an attacker to steal all emails from the victim. Since there is no official patch available yet, we highly recommend to disable the affected feature

blog.sonarsource.com/horde-web

A group, called Anonymous Liberland and the Pwn-Bär Hack Team, claim to have breached Belarusian weapons firm. Tetraedr has operated since 2001 and offers missile and gun systems, air defense and surveillance radar systems.

  • 200 gigabytes of emails and schematics from the Belarusian weapons manufacturer Tetraedr.

ddosecrets.substack.com/p/limi

🇫🇷 La CNIL lance une plateforme afin de suivre et identifier en temps réel les problématiques relatives à la protection des données des électeurs pour l'élection présidentielle 2022.

demarche.services.cnil.fr/sign

Les opérateurs Snatch revendiquent une attaque informatique relative au groupe McDonald's Corporation.

🇨🇦 L'Aluminerie Alouette (alouette.com), à Sept-Îles, la plus grande aluminerie des Amériques, victime d'une panne majeure qui affecte l'ensemble de ses systèmes informatiques.

journaldequebec.com/2022/02/25

🇺🇸 U.S microchip powerhouse Nvidia hit by cyber attack, parts of its business are « completely compromised ». « We are investigating an incident. We don't have any additional information to share at this time. »

telegraph.co.uk/business/2022/

New version of the IcedID GzipLoader component which is distributed since the beginning of February 2022. This version introduces new anti-analysis techniques, whereas it is functionally equivalent to previous versions, except for the removal of the SSL-pinning feature.

threatray.com/blog/a-new-icedi

Plus anciens