Plus récents

(CVE-2021-34473) Finding exposed OWA servers vulnerable to proxyshell - A new set of critical vulnerabilities popped-up at this year's BlackHat edition regarding Exchange exploitable via Outlook Web Access. This set of vulnerabilities as been dubbed proxyshell

onyphe.io/blog/finding-exposed

's Huawei Technologies Co (huawei.com) stole trade secrets & spied on . 's alleged was located in a database that consolidated sensitive information, including national ID card records, foreigner registrations, tax records and criminal records, for law enforcement, a company (businessefficiencysolutions.com) has said

hindustantimes.com/world-news/

100 million T-Mobile customers records purportedly up for sale. Seller claims to have sucker-punched infrastructure out of . T-Mobile, the mobile communication brand of the German telecommunications company Deutsche Telekom AG, is reportedly investigating.

threatpost.com/t-mobile-invest

Une partie des systèmes informatiques du Groupe Pallas Kliniken AG (pallas-kliniken.ch) impactée par une attaque de type . Spécialisées dans la chirurgie des yeux et esthétique, ces cliniques privées disposent d'une vingtaine d'implantations en et réalisent chaque année plus de 120000 interventions

swissinfo.ch/fre/les-cliniques

PetitPotam code have been updated to use one unpatched Encrypting File System Remote (EFSRPC) functions if needed + added the structs and nearly all RPC calls that can be used to elicit authentication or do other interesting thing

github.com/topotam/PetitPotam

Nota do Ministério da Economia (Brasil) - Foi identificado na noite de sexta-feira (13/8) um ataque de à rede interna da Secretaria do Tesouro Nacional. As medidas de contenção foram imediatamente aplicadas e a Polícia Federal, acionada

gov.br/economia/pt-br/canais_a

Abusing legitimate challenge & response services (such as 's reCAPTCHA) or deploying customized fake CAPTCHA-like validation. Mass phishing and grayware campaigns have become more sophisticated, using evasion techniques to escape detection by automated security crawlers. Fortunately, when malicious actors use infrastructure, services or tools across their ecosystem of malicious websites, we have a chance to leverage these indicators against them.

unit42.paloaltonetworks.com/ca

hAFL1 is able to fuzz Hyper-V's drivers. In this tutorial will focus on fuzzing the Hyper-V virtual switch (vmswitch.sys)

github.com/SB-GC-Labs/hAFL1/

LiveCloudKd v2.0.0.20210814 - Added reading, writing memory options for Hyper-V VMs with running nested guest OS

github.com/gerhart01/LiveCloud

- A cyber attack has affected 's largest run by the Federal Board of Revenue (FBR) and managed to break the virtual environment Hyper-V by , bringing down all the official websites operated by the tax machinery. « It is cyber on our Independence Day ! »

tribune.com.pk/story/2315712/f

A security researcher has figured out a way to dump a user's unencrypted plaintext credentials from Microsoft's new 365 Cloud PC service using Mimikatz

bleepingcomputer.com/news/micr

La nouvelle de la plateforme du SI-DEP concernent aussi les centres de vaccination et les centres de dépistage de (Calvados, ). « On délivre un document non officiel aux vaccinés, certifiant qu'ils ont fait le test. C'est ensuite au bon vouloir des professionnels qui vérifient le passe… »

ouest-france.fr/normandie/caen

agrees to pay $85,000,000 $USD for lying about its « end-to-end encryption » and the transfer of data to and « That's shocking. There is nothing in the privacy policy that addresses that »

vice.com/en/article/k7e599/zoo

Le SI-DEP, régulièrement critiqué par les professionnels de pour ses bugs à répétition, toujours en : une situation inédite par sa durée. Les pharmaciens impactés - 90 % de la profession, selon les syndicats - font, pour le moment, dans le système D et réalisent des attestations papiers, non sécurisées. Ce nouveau « bug » a pour effet (visible) de ne pas pouvoir générer de certificats officiels attestant la négativité ou la positivité des personnes venues se faire dépister

letelegramme.fr/coronavirus/pa

Plus anciens