Plus récents

🇨🇭 Le bataillon cyber 42 actif depuis le 1er janvier 2022 ne convainc pas tout le monde. L'armée « crée des attentes surfaites », selon un expert.

tdg.ch/le-cyberbataillon-ne-co

🇫🇷 Une partie des SI du Centre Hospitalier de Castelluccio (ch-castelluccio.fr) impactée par une attaque informatique perpétrée dans la journée du lundi 28 mars 2022.

librexpression.fr/lhopital-de-

CVE-2022-27666, a vulnerability in esp6 module that achieves local privilege escalation.

github.com/plummm/CVE-2022-276

In order to breach into its victims' networks, this intrusion set employs not only advanced social engineering techniques that encompass SIM swap attacks against the telecommunication sector and spearphishing, but also the acquisition of active passwords & session tokens on specialized dark web markets and forums.

In this context, the City of London Police announced the 24 th of March 2022 that seven teenagers between the ages of 16 and 21 were arrested. We don't know if the supposedly « mastermind » of the LAPSUS$ intrusion set is amongst the seven.

intrinsec.com/wp-content/uploa

🇺🇸 Arizona's Secretary of State : the agency is experiencing a system-wide outage. Updates will be provided as more information becomes available.

twitter.com/SecretaryHobbs/sta

CVE-2018-25032 could potentially allow a Denial-of-Service () attack. This bug was reported by Danilo Ramos of Eideticom, Inc. It has lain in wait 13 years before being found! The « bug » was introduced in zlib 1.2.2.2, with the addition of the Z_FIXED option.

github.com/madler/zlib/commit/

The Mars Stealer pilfers user credentials stored in various browsers, as well as many different wallets. This is being distributed via social engineering techniques, malspam campaigns, malicious software cracks, and keygens.

blog.morphisec.com/threat-rese

🔥 There is a terrifying and highly effective « method » that criminal hackers are now using to harvest sensitive customer data from Internet service providers, phone companies and firms. It involves compromising email accounts and websites tied to police departments and government agencies, and then sending unauthorized demands for subscriber data while claiming the information being requested can't wait for a court order because it relates to an urgent matter of life and death.

krebsonsecurity.com/2022/03/ha

🇩🇿 Lors de la première conférence sur les enjeux de la cybersécurité organisée, avant-hier, à l'hôtel El-Aurassi, par la société Intelligent Network (Inet), les professionnels en cybersécurité ont recommandés à l'Algérie de créer une agence de sécurité des systèmes d'information. Selon les données de l'ITU de 2020, l'Algérie se positionne à la 104e place sur 182 pays sur la cybersécurité.

liberte-algerie.com/economie/l

🔌 GitHub Actions is now experiencing degraded performance. We are investigating reports of degraded availability.

githubstatus.com/incidents/3nr

CVE-2022-22274 - Vulnerability in the SonicWALL SonicOS via HTTP request allows a remote unauthenticated attacker to cause DoS or potentially results in RCE.

psirt.global.sonicwall.com/vul

CVE-2022-1040 - Sophos Firewall users are therefore advised to make sure their products are updated. Vulnerability allows a remote attacker who can access the Firewall's User Portal or Webadmin interface to bypass authentication and execute arbitrary code.

sophos.com/en-us/security-advi

A vulnerability in 그누보드 (gnuboard5) allows a malicious actor to de-obfuscate all addresses of users.

0g.vc/posts/insecure-cipher-gn

A lot of people still think that the security that OTPs offer is based on their randomness but in fact it's based on their unpredictability.

siginthistorian.blogspot.ca/20

Plus anciens