Plus récents

Since the beginning of 2020, Dutch and Belgian residents have been increasingly targeted by financially motivated cybercriminals looking to obtain access to their bank accounts. In many strikingly similar cases, fraudsters reach out to victims via email, SMS, or WhatsApp messages to deliver fake notifications containing malicious links pointing to a phishing site. Our researchers identified a Dutch-speaking criminal syndicate, codenamed Fraud Family by Group-IB, which develops, sells and rents sophisticated phishing frameworks to other criminals targeting users mainly in the Netherlands and Belgium. The phishing frameworks allow attackers with minimal skills to optimize the creation and design of campaigns to carry out massive fraudulent operations all the while bypassing 2FA. This blog post analyzes the methods and techniques used by Fraud Family's shady customers, Fraud Family's technical infrastructure, and their phishing panels.

blog.group-ib.com/fraud_family

Ontwikkelaar phishing software opgepakt - De politie heeft dinsdag een 24-jarige man uit Arnhem De 24-jarige verdachte zou de software hebben ontwikkeld voor zogenoemde phishing panels.

politie.nl/nieuws/2021/juli/22

According to data provided to The Block, analytics firm Chainalysis Inc. (chainalysis.com) has confirmed over $208 million in payouts thus far in 2021. In 2020, the firm confirmed $416,432 in ransomware. 2021 will likely be bigger than 2020.

theblockcrypto.com/post/112243

CVE-2021-33909 - We discovered a size_t-to-int conversion vulnerability in the kernel's filesystem layer: by creating, mounting, and deleting a deep directory structure whose total path length exceeds 1GB, an unprivileged local attacker can write the 10-byte string //deleted to an offset of exactly -2GB-10B below the beginning of a vmalloc()ated kernel buffer. We successfully exploited this uncontrolled out-of-bounds write, and obtained full root privileges on default installations of Ubuntu 20.04, Ubuntu 20.10, Ubuntu 21.04, Debian 11, and Fedora 34 Workstation; other Linux distributions are certainly vulnerable, and probably exploitable. Our exploit requires approximately 5GB of memory and 1M inodes; we will publish it in the near future.

qualys.com/2021/07/20/cve-2021

CVE-2021-3438 - 16 Years In Hiding - Millions of Worldwide Vulnerable. This led to the discovery of a high severity vulnerability in HP, Xerox, and Samsung printer driver that has remained undisclosed for 16 years. Millions of devices and likely millions of users worldwide. This vulnerability affects a very long list of over 380 different and printer models as well as at least a dozen different products.

labs.sentinelone.com/cve-2021-

managed to disconnect itself from the global during tests in June and July 2021. The capability of physically disconnecting the Russian part of the Internet was tested.

reuters.com/technology/russia-

PetitPotam - PoC - Gilles Lionel, a Paris-based French security researcher, has discovered a security flaw in the operating system that can be exploited to force remote Windows machines to authenticate and share their password hashes with an attacker.

github.com/topotam/PetitPotam

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the Windows SAM, Security, and Software in 10 version 1809 or newer

github.com/WiredPulse/Invoke-H

Generic Signature Format for SIEM Systems - Sigma is a generic and open signature format that allows you to describe relevant log events in a straightforward manner. The rule format is very flexible, easy to write and applicable to any type of log file. The main purpose of this project is to provide a structured form in which researchers or analysts can describe their once developed detection methods and make them shareable with others. Sigma is for log files what Snort is for network traffic and YARA is for files.

github.com/SigmaHQ/sigma

La plus grande compagnie pétrolière au monde Saudi Aramco a été victime en juin 2021 d'une importante fuite de données de 1 terabyte de données, qu'ils ont mis à prix 5 millions de dollars : les attaquants sont passés par l'intermédiaire d'un de ses sous-traitants.

lefigaro.fr/secteur/high-tech/

DUBAI, United Arab Emirates (AP) - Saudi Arabia's state oil giant acknowledged Wednesday that leaked data from the company — files now apparently being used in a cyber-extortion attempt involving a $50 million ransom demand - likely came from one of its contractors. The Saudi Arabian Oil Co., better known as Saudi Aramco, told The Associated Press that it « recently became aware of the indirect release of a limited amount of company data which was held by third-party contractors » The firm did not say which contractor found itself affected nor whether that contractor had been hacked or if the information leaked out another way. « We confirm that the release of data was not due to a breach of our systems, has no impact on our operations and the company continues to maintain a robust cybersecurity posture » Aramco said. A page accessed by the AP on the darknet - a part of the internet hosted within an encrypted network and accessible only through specialized anonymity-providing tools - claimed the extortionist held 1,000 gigabytes worth of Aramco data. The global energy has seen a ramp up in attacks with Colonial Pipeline becoming the most visible of late.

apnews.com/article/technology-

Il y a quelques semaines, l'hebdomadaire américain The New Yorker a publié un reportage hallucinant sur les cyberattaques menées par le régime nord-coréen aux quatre coins du monde. On se croirait dans un film de science-fiction.

journaldequebec.com/2021/07/21

L'opérateur Orange est en cause dans l'entretien de ses infrastructures et sa gestion de l'incident qui a sévèrement perturbé les appels aux urgences le 2 juin 2021.

lemonde.fr/economie/article/20

« Haurus », l'ancien agent de la DGSI qui était jugé pour avoir vendu sur le Darknet des informations tirées de fichiers de protégés, a été condamné à 7 ans de prison dont 2 avec sursis par le correctionnel de Nanterre

lemonde.fr/police-justice/arti

Plus anciens