Plus récents

💥 Spring4Shell - Another critical deserialization RCE flaw this time in Java Spring Core that has the potential to be weaponized rather easily.

threatpost.com/critical-rce-bu

🇫🇷 Les opérateurs RansomEXX diffusent 423Mo de données relatives au groupe Stago (stago.com), société de l'industrie du Diagnostic In-Vitro depuis plus de 60 ans, Stago est spécialisé dans le domaine de l'hémostase et de la thrombose. Cet acteur disposait d'accès à distance dans de nombreux hopitaux...

🇨🇭 Le canton de Neuchâtel accélére sa mise en place de nouvelles mesures de sécurité et tente d'améliorer sa capacité à résister à des attaques au niveau des systèmes centraux.

journaldujura.ch/nouvelles-en-

The largest fraud in 🇺🇸 U.S. history : « Nothing like this has ever happened before. It is the biggest fraud in a generation. » ( Matthew Schneider ). Even if the highest estimates are inflated, the total fraud in all Covid relief funds amounts to a mind-boggling sum of taxpayer money that could rival the $579 billion in federal funds. People went on state websites and took the names of existing businesses or registered new, fake ones.

nbcnews.com/politics/justice-d

A new campaign from the hacking group tracked as APT36 has been discovered using new custom malware. The most interesting aspect is the use of laced Kavach Authentication, is an OTP application, targeting military personnel or employees of the 🇮🇳 Indian government. APT36 is considered to be a 🇵🇰 Pakistan-aligned and state-sponsored threat actor.

blog.talosintelligence.com/202

🇫🇷 92% des français souhaitent que le prochain président de la République renforce les moyens de protection contre les cyberattaques envers les organismes publics et collectivités. Sondage IFOP commandé par la société commerciale française spécialisée dans l'exploitation de données médicales Galeon (galeon.care) sur un échantillon de 1 005 personnes âgées de 18 ans et plus.

ifop.com/wp-content/uploads/20

🇷🇺 Russian hackers have been scanning the systems of energy companies and other critical infrastructure in the 🇺🇸 United States, and state-sponsored hacking by Russia presents a « current » threat to American national security, a top FBI official told lawmakers on Tuesday.

reuters.com/world/fbi-says-rus

CISA call with critical infrastructure partners on potential russian cyberattacks against the 🇺🇸 U.S

youtube.com/watch?v=q-vnMmQHAS

Unidentified hackers tried to breach the email accounts of election officials in nine states. The malicious email campaign last October included fake invoices and were designed to steal the email passwords of election officials. The phishing effort didn't appear to have a big impact.

wcvb.com/article/hackers-tried

Les opérateurs Conti revendiquent une attaque contre « BANQUE CENTRALE DE TUNISIE »

A wave of attacks against vulnerable VMware Horizon servers starting January 19, 2022. Many of the attacks have involved attempts to deploy cryptocurrency miners such as JavaX miner, Jin, z0Miner, XMRig variants.

news.sophos.com/en-us/2022/03/

🇺🇸 America experienced an unprecedented increase in cyber attacks and malicious cyber activity in 2021. IC3 continued to receive a record number of complaints.

ic3.gov/Media/PDF/AnnualReport

Plus anciens