Plus récents

A newly-discovered NTLM relay attack makes every Microsoft Windows system vulnerable to an escalation of privileges and there's no patch in sight.

labs.sentinelone.com/relaying-

Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse LSASS dump files and registry hive files to extract credentials and other secrets stored without downloading the file and without uploading any suspicious code to the beacon.

r.sec-consult.com/aggrokatz

New evidence allows us to assess that UNC1151, a suspected state-sponsored espionage actor, conducts at least some components of Ghostwriter influence activity

fireeye.com/blog/threat-resear

Unleashing the Power of Cyber Threat Intelligence with Maltego, STIX & OpenCTI

We are thrilled to announce two significant additions to our Transform Hub: utilities for working with STIX 2.1 and a STIX-powered integration for OpenCTI.

maltego.com/blog/unleashing-th

L'hôpital de Saint-Gaudens panse son système informatique. Bientôt trois semaines que le centre hospitalier Comminges Pyrénées de Saint-Gaudens est amputé de son service informatique à la suite d'une attaque informatique.

ladepeche.fr/2021/04/29/lhopit

The data breach originated from a cloud storage account Paleohacks was using to store the private data and personal details of over 70,000 customers and users. Paleohacks teaches people how to adopt the paleo diet into their lifestyles through various media products, from recipes and meal plans to podcasts and courses.

vpnmentor.com/blog/report-pale

Ransomware gang targets Microsoft SharePoint servers for the first time

Microsoft SharePoint servers have now joined the list of network devices being abused as an entry vector into corporate networks by ransomware gangs. SharePoint now joins a list that also includes Citrix gateways, F5 BIG-IP load balancers, Microsoft Exchange email servers, and Pulse Secure, Fortinet, and Palo Alto Network VPNs. The group behind the attacks targeting SharePoint servers is a new ransomware operation that was first seen at the end of 2020. The group is tracked by security vendors under the codenames of Hello or the WickrMe

therecord.media/ransomware-gan

DoppelPaymer gang leaks files from Illinois AG after ransom negotiations break down

threatpost.com/doppelpaymer-le

Les portails colisprive.fr & colisprive-store.com fortement perturbés suite à une attaque informatique.

Operatorzy ransomware’a Babuk udzielili nam unikalnego wywiadu, bowiem na razie nikomu innemu się to nie udało. Jak to zrobiliśmy? Oficjalnym kanałem. Zadawaliśmy pytania i dostawaliśmy odpowiedzi. Wywiad jest autoryzowany.

sekurak.pl/udalo-nam-sie-zreal

In 2020, cybercriminals succeeded in collecting ransom amounts totalling almost US$ 350 million in cryptocurrency, a +311% increase over 2019.

Plus anciens