Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
|
2021-03-08 14:00:05 |
Supernova malware clues link Chinese threat group Spiral to SolarWinds server hacks (lien direct) |
SolarWinds servers are being exploited to deploy the malicious .NET web shell. |
Malware
Threat
|
|
|
|
2021-03-08 12:50:00 |
Everything you need to know about Microsoft Exchange Server hack (lien direct) |
Vulnerabilities are being exploited by Hafnium. Other cyberattackers are following suit. |
Hack
|
|
|
|
2021-03-08 08:26:40 |
Flagstar Bank customer data breached through Accellion hack (lien direct) |
Like many other users, Flagstar Bank has now permanently stopped using the platform. |
Hack
|
|
|
|
2021-03-06 15:32:00 |
Check to see if you\'re vulnerable to Microsoft Exchange Server zero-days using this tool (lien direct) |
A CISA alert has been issued to urge admins to check their systems as quickly as possible. |
Tool
|
|
|
|
2021-03-05 12:18:44 |
FTC joins 38 states in takedown of massive charity robocall operation (lien direct) |
Over $110 million was taken from victims who believed they were funding veteran, children, and firefighter charities. |
|
|
|
|
2021-03-05 11:10:13 |
$100 in crypto for a kilo of gold: Scammer pleads guilty to investor fraud (lien direct) |
The case brings a new meaning to a cryptocurrency gold rush. |
|
|
|
|
2021-03-05 10:02:00 |
Microsoft Exchange zero-day vulnerabilities exploited in attacks against US local governments (lien direct) |
Mandiant says attacks are taking place against a wide array of US targets -- local governments included. |
|
|
|
|
2021-03-05 09:04:02 |
Cyberattack shuts down online learning at 15 UK schools (lien direct) |
The cyberattack also took email, phone, and website communication offline. |
|
|
|
|
2021-03-04 12:16:52 |
Accellion zero-day claims a new victim in cybersecurity company Qualys (lien direct) |
A hotfix was applied, but not before some customer files may have been compromised. |
|
|
|
|
2021-03-04 11:27:19 |
CISA issues emergency directive to agencies: deal with Microsoft Exchange zero-days now (lien direct) |
Patch now, or disconnect Microsoft Exchange services from the internet. |
|
|
|
|
2021-03-04 10:36:10 |
Maza Russian cybercriminal forum suffers data breach (lien direct) |
Forums can be areas to swap illicit tools and data, but they can also be the targets of cyberattackers in their turn. |
Data Breach
|
|
|
|
2021-03-03 14:09:07 |
Ursnif Trojan has targeted over 100 Italian banks (lien direct) |
1,700 credentials were stolen from a single payment processor. |
|
|
|
|
2021-03-03 12:09:28 |
Microsoft account hijack vulnerability earns bug bounty hunter $50,000 (lien direct) |
The researcher says he could have abused the bug to hijack Microsoft accounts. |
Vulnerability
|
|
|
|
2021-03-03 10:44:18 |
Google patches actively exploited Chrome browser zero-day vulnerability (lien direct) |
Upgrading your Chrome build as quickly as possible is recommended. |
Vulnerability
|
|
|
|
2021-03-03 09:42:32 |
SEC charges group for alleged pump-and-dump Airborne Wireless stock scam (lien direct) |
SEC claims investors were defrauded out of $45 million. |
|
|
|
|
2021-03-02 13:00:00 |
ObliqueRAT Trojan now lurks in images on compromised websites (lien direct) |
The malware has been upgraded in new campaigns across Asia. |
Malware
|
|
★★★
|
|
2021-03-02 11:18:03 |
Oxfam Australia supporters embroiled in new data breach (lien direct) |
Personal data, including partial payment information, is thought to be included. |
Data Breach
|
|
|
|
2021-03-02 10:30:32 |
Google addresses customer data protection, security in Workspace (lien direct) |
Google has also introduced new Workspace features as we continue to work from home. |
|
|
|
|
2021-03-02 09:08:06 |
Twitter\'s new strike system will target prolific COVID-19 fake information spreaders (lien direct) |
Twitter says repeat offenders will be booted from the platform. |
|
|
|
|
2021-03-01 20:12:58 |
SolarWinds security fiasco may have started with simple password blunders (lien direct) |
Many things came together to crack SolarWinds, but it may all have started with that classic mistake of leaking a lousy password. |
|
|
|
|
2021-03-01 14:00:03 |
Hackers exploit websites to give them excellent SEO before deploying malware (lien direct) |
Climbing up Google's ranks is key to this new technique. |
Malware
|
|
|
|
2021-03-01 13:50:00 |
Tether faces 500 Bitcoin ransom: We are \'not paying\' (lien direct) |
The cryptocurrency firm says “forged” documents attempting to undermine the ecosystem as a whole are also circulating. |
|
|
|
|
2021-03-01 11:06:19 |
Judge approves $650m settlement for Facebook users in privacy, biometrics lawsuit (lien direct) |
Facebook users represented in the lawsuit may soon receive hundreds of dollars each. |
|
|
|
|
2021-03-01 10:04:26 |
Minion privilege escalation exploit patched in SaltStack Salt project (lien direct) |
The bug permitted attackers to perform privilege escalation attacks in the automation software. |
|
|
|
|
2021-03-01 09:09:18 |
Businessman charged with intent to steal General Electric\'s secret silicon technology (lien direct) |
Trade secrets worth millions on the market were the goal of the conspiracy. |
|
|
|
|
2021-02-26 18:36:35 |
Chrome will soon try HTTPS first when you type an incomplete URL (lien direct) |
If users type an URL and they forget to add the HTTP or HTTPS prefix, Chrome will soon use HTTPS by default. |
|
|
|
|
2021-02-26 16:16:00 |
Berlin resident jailed for threatening to bomb NHS hospital unless Bitcoin ransom was paid (lien direct) |
The bomb threats escalated over the course of six weeks to include Black Lives Matter protests and threats on UK politicians. |
|
|
|
|
2021-02-26 13:09:06 |
Go malware is now common, having been adopted by both APTs and e-crime groups (lien direct) |
There's been a 2,000% increase of new malware written in Go over the past few years. |
Malware
|
|
|
|
2021-02-26 12:26:00 |
Oxford University lab with COVID-19 research links targeted by hackers (lien direct) |
Compromised machines included those used in sample analysis. |
|
|
|
|
2021-02-26 08:25:44 |
TikTok agrees to pay $92 million to settle teen privacy class-action lawsuit (lien direct) |
The video platform was accused of collecting biometric data without consent. |
|
|
|
|
2021-02-25 17:47:50 |
Chinese cyberspies targeted Tibetans with a malicious Firefox add-on (lien direct) |
The Chinese hacking group used the malicious add-on to collect Gmail and Firefox data from their victims. |
|
|
|
|
2021-02-25 14:04:47 |
This chart shows the connections between cybercrime groups (lien direct) |
CrowdStrike puts together a list of connections and how cybercrime groups cooperate with each other. |
|
|
|
|
2021-02-24 21:16:14 |
More than 6,700 VMware servers exposed online and vulnerable to major new bug (lien direct) |
Proof-of-concept exploit code has been published online earlier today, and active scans for vulnerable VMware systems have been detected already. |
|
|
|
|
2021-02-24 15:13:18 |
Ukraine reports cyber-attack on government document management system (lien direct) |
Ukrainian officials blame "one of the hacker spy groups from the Russian Federation." |
|
|
|
|
2021-02-24 12:24:00 |
This botnet is abusing Bitcoin blockchains to stay in the shadows (lien direct) |
BTC transactions are being used to obfuscate malicious activity. |
|
|
|
|
2021-02-24 11:02:23 |
Start Options, B2G founder indicted for alleged digital currency, investor fraud (lien direct) |
The individual has been accused of being part of a scheme to defraud "hundreds" of investors. |
|
|
|
|
2021-02-24 05:01:03 |
COVID pandemic causes spike in cyberattacks against hospitals, medical companies (lien direct) |
IBM says attack rates have doubled against medical entities since the pandemic began. |
|
|
|
|
2021-02-23 23:28:16 |
Airplane maker Bombardier data posted on ransomware leak site following FTA hack (lien direct) |
Bombardier is the latest in a long string of hacks caused by companies using old versions of the Accellion FTA file-sharing server. |
Ransomware
Hack
|
|
|
|
2021-02-23 17:26:06 |
Flash version distributed in China after EOL is installing adware (lien direct) |
Security researchers say the Chinese Flash app is behaving lide adware and opening browser windows to show ads. |
|
|
|
|
2021-02-23 17:00:00 |
Google\'s Password Checkup feature coming to Android (lien direct) |
The Password Checkup feature will tell Android users when one of their passwords has been exposed in an online data breach. |
|
|
|
|
2021-02-23 14:00:03 |
Qualcomm, Sophos ink deal to secure 5G Snapdragon PCs (lien direct) |
Sophos will provide endpoint protection for always on, always connected PCs. |
|
|
|
|
2021-02-23 10:29:07 |
IBM issues patches for Java Runtime, Planning Analytics Workspace, Kenexa LMS (lien direct) |
The worst bugs could lead to malicious code execution and application crashes. |
Guideline
|
|
|
|
2021-02-23 09:25:22 |
Keybase patches bug that kept pictures in cleartext storage on Mac, Windows clients (lien direct) |
Keybase failed to wipe clean cached pictures even after deletion. |
|
|
|
|
2021-02-22 21:19:51 |
FireEye links 0-day attacks on FTA servers & extortion campaign to FIN11 group (lien direct) |
FireEye: Hackers breached companies running FTA servers, stole private files, and are now publishing data on the Clop ransomware leak site. |
Ransomware
|
|
|
|
2021-02-22 15:45:22 |
Powerhouse VPN products can be abused for large-scale DDoS attacks (lien direct) |
Around 1,500 Powerhouse VPN servers are exposed online and ready to be abused by DDoS groups. |
|
|
|
|
2021-02-22 12:03:25 |
(Déjà vu) Stored XSS bug in Apple iCloud domain disclosed by bug bounty hunter (lien direct) |
The cross-site scripting bug reportedly earned the researcher a $5000 reward. |
|
|
|
|
2021-02-22 11:01:46 |
Chinese hackers cloned attack tool belonging to NSA\'s Equation Group (lien direct) |
The Jian tool was used to exploit a Windows zero-day vulnerability years before a patch was issued. |
Tool
Vulnerability
|
|
|
|
2021-02-22 07:58:04 |
30,000 Macs infected with new Silver Sparrow malware (lien direct) |
Silver Sparrow can even run on systems with Apple's new M1 chip. |
Malware
|
|
|
|
2021-02-19 16:02:00 |
Brave browser leaks onion addresses in DNS traffic (lien direct) |
DNS leak leaves footprints in DNS server logs for a Brave user's Tor traffic. |
|
|
|
|
2021-02-19 13:31:19 |
Myanmar arrests 11 suspects for hacking government sites during protests (lien direct) |
Hacktivists operated via a Facebook group and called themselves the "Myanmar Hackers." |
|
|
|