www.secnews.physaphae.fr This is the RSS 2.0 feed from www.secnews.physaphae.fr. IT's a simple agragated flow of multiple articles soruces. Liste of sources, can be found on www.secnews.physaphae.fr. 2025-05-10T19:29:32+00:00 www.secnews.physaphae.fr The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Au-delà de la gestion de la vulnérabilité - pouvez-vous cve ce que je cve?<br>Beyond Vulnerability Management – Can You CVE What I CVE? The Vulnerability Treadmill The reactive nature of vulnerability management, combined with delays from policy and process, strains security teams. Capacity is limited and patching everything immediately is a struggle. Our Vulnerability Operation Center (VOC) dataset analysis identified 1,337,797 unique findings (security issues) across 68,500 unique customer assets. 32,585 of them were distinct]]> 2025-05-09T15:30:00+00:00 https://thehackernews.com/2025/05/beyond-vulnerability-management-cves.html www.secnews.physaphae.fr/article.php?IdArticle=8673638 False Vulnerability,Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Mirai Botnet ciblant les serveurs Biz vulnérables à la traversée du répertoire<br>Mirai Botnet targeting OFBiz Servers Vulnerable to Directory Traversal Enterprise Resource Planning (ERP) Software is at the heart of many enterprising supporting human resources, accounting, shipping, and manufacturing. These systems can become very complex and difficult to maintain. They are often highly customized, which can make patching difficult. However, critical vulnerabilities keep affecting these systems and put critical business data at risk.  The]]> 2024-08-02T16:22:00+00:00 https://thehackernews.com/2024/08/mirai-botnet-targeting-ofbiz-servers.html www.secnews.physaphae.fr/article.php?IdArticle=8549665 False Vulnerability,Patching None 2.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Les cybercriminels utilisent un Phantomloader pour distribuer des logiciels malveillants SSLoad<br>Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware The nascent malware known as SSLoad is being delivered by means of a previously undocumented loader called PhantomLoader, according to findings from cybersecurity firm Intezer. "The loader is added to a legitimate DLL, usually EDR or AV products, by binary patching the file and employing self-modifying techniques to evade detection," security researchers Nicole Fishbein and Ryan Robinson said in]]> 2024-06-13T15:49:00+00:00 https://thehackernews.com/2024/06/cybercriminals-employ-phantomloader-to.html www.secnews.physaphae.fr/article.php?IdArticle=8517166 False Malware,Patching None 3.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) GitHub lance l'outil AutoFix alimenté par AI pour aider les développeurs à patcher des défauts de sécurité<br>GitHub Launches AI-Powered Autofix Tool to Assist Devs in Patching Security Flaws GitHub on Wednesday announced that it\'s making available a feature called code scanning autofix in public beta for all Advanced Security customers to provide targeted recommendations in an effort to avoid introducing new security issues. "Powered by GitHub Copilot and CodeQL, code scanning autofix covers more than 90% of alert types in JavaScript, Typescript, Java, and]]> 2024-03-21T16:00:00+00:00 https://thehackernews.com/2024/03/github-launches-ai-powered-autofix-tool.html www.secnews.physaphae.fr/article.php?IdArticle=8467865 False Tool,Patching None 2.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Microsoft désactive le protocole d'installation de l'application MSIX largement utilisée dans les attaques de logiciels malveillants<br>Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks Microsoft on Thursday said it\'s once again disabling the ms-appinstaller protocol handler by default following its abuse by multiple threat actors to distribute malware. “The observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware distribution,” the Microsoft Threat Intelligence]]> 2023-12-29T10:46:00+00:00 https://thehackernews.com/2023/12/microsoft-disables-msix-app-installer.html www.secnews.physaphae.fr/article.php?IdArticle=8430625 False Ransomware,Malware,Threat,Patching None 4.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Alerte: \\ 'Effluence \\' Backdoor persiste malgré le patchage des serveurs de confluence atlassienne<br>Alert: \\'Effluence\\' Backdoor Persists Despite Patching Atlassian Confluence Servers Cybersecurity researchers have discovered a stealthy backdoor named Effluence that\'s deployed following the successful exploitation of a recently disclosed security flaw in Atlassian Confluence Data Center and Server. "The malware acts as a persistent backdoor and is not remediated by applying patches to Confluence," Aon\'s Stroz Friedberg Incident Response Services said in an analysis published]]> 2023-11-10T14:28:00+00:00 https://thehackernews.com/2023/11/alert-effluence-backdoor-persists.html www.secnews.physaphae.fr/article.php?IdArticle=8408992 False Malware,Patching None 2.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Microsoft publie des correctifs d'octobre 2023 pour 103 défauts, y compris 2 exploits actifs<br>Microsoft Releases October 2023 Patches for 103 Flaws, Including 2 Active Exploits Microsoft has released its Patch Tuesday updates for October 2023, addressing a total of 103 flaws in its software, two of which have come under active exploitation in the wild. Of the 103 flaws, 13 are rated Critical and 90 are rated Important in severity. This is apart from 18 security vulnerabilities addressed in its Chromium-based Edge browser since the second Tuesday of September. The two]]> 2023-10-11T12:30:00+00:00 https://thehackernews.com/2023/10/microsoft-releases-october-2023-patches.html www.secnews.physaphae.fr/article.php?IdArticle=8394211 False Patching None 3.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Une autre faille SQLI non authentifiée critique découverte dans le logiciel de transfert Moveit<br>Another Critical Unauthenticated SQLi Flaw Discovered in MOVEit Transfer Software Progress Software has announced the discovery and patching of a critical SQL injection vulnerability in MOVEit Transfer, popular software used for secure file transfer. In addition, Progress Software has patched two other high-severity vulnerabilities. The identified SQL injection vulnerability, tagged as CVE-2023-36934, could potentially allow unauthenticated attackers to gain unauthorized]]> 2023-07-07T19:31:00+00:00 https://thehackernews.com/2023/07/another-critical-unauthenticated-sqli.html www.secnews.physaphae.fr/article.php?IdArticle=8353388 False Vulnerability,Patching None 3.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Les pare-feu zyxel sont attaqués!Rattuage urgent requis<br>Zyxel Firewalls Under Attack! Urgent Patching Required The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday placed two recently disclosed flaws in Zyxel firewalls to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities, tracked as CVE-2023-33009 and CVE-2023-33010, are buffer overflow vulnerabilities that could enable an unauthenticated attacker to cause a]]> 2023-06-06T09:46:00+00:00 https://thehackernews.com/2023/06/zyxel-firewalls-under-attack-urgent.html www.secnews.physaphae.fr/article.php?IdArticle=8342380 False Patching None 2.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Patch where it Hurts: Effective Vulnerability Management in 2023 2023-01-12T15:10:00+00:00 https://thehackernews.com/2023/01/patch-where-it-hurts-effective.html www.secnews.physaphae.fr/article.php?IdArticle=8300494 False Vulnerability,Patching None 3.0000000000000000 The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Integrating Live Patching in SecDevOps Workflows 2022-09-06T14:27:00+00:00 https://thehackernews.com/2022/09/integrating-live-patching-in-secdevops.html www.secnews.physaphae.fr/article.php?IdArticle=6749523 False Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Taking the Risk-Based Approach to Vulnerability Patching 2022-07-27T04:00:30+00:00 https://thehackernews.com/2022/07/taking-risk-based-approach-to.html www.secnews.physaphae.fr/article.php?IdArticle=5968026 False Vulnerability,Threat,Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Which Hole to Plug First? Solving Chronic Vulnerability Patching Overload 2022-05-02T07:00:53+00:00 https://thehackernews.com/2022/05/which-hole-to-plug-first-solving.html www.secnews.physaphae.fr/article.php?IdArticle=4532703 False Vulnerability,Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Meeting Patching-Related Compliance Requirements with TuxCare 2022-01-13T00:18:27+00:00 https://thehackernews.com/2022/01/meeting-patching-related-compliance.html www.secnews.physaphae.fr/article.php?IdArticle=3956100 False Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) First Patch Tuesday of 2022 Brings Fix for a Critical \'Wormable\' Windows Vulnerability 2022-01-11T22:42:18+00:00 https://thehackernews.com/2022/01/first-patch-tuesday-of-2022-brings-fix.html www.secnews.physaphae.fr/article.php?IdArticle=3950727 False Vulnerability,Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) How Can You Leave Log4J in 2021? 2022-01-11T12:29:57+00:00 https://thehackernews.com/2022/01/how-can-you-leave-log4j-in-2021.html www.secnews.physaphae.fr/article.php?IdArticle=3948578 False Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Why Database Patching Best Practice Just Doesn\'t Work and How to Fix It ]]> 2021-10-18T09:00:32+00:00 http://feedproxy.google.com/~r/TheHackersNews/~3/hKgN5eUgEqg/why-database-patching-best-practice.html www.secnews.physaphae.fr/article.php?IdArticle=3527206 False Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Why You Should Consider QEMU Live Patching ]]> 2021-09-23T04:16:28+00:00 http://feedproxy.google.com/~r/TheHackersNews/~3/Q0tJHjYUBvY/why-you-should-consider-qemu-live.html www.secnews.physaphae.fr/article.php?IdArticle=3417000 False Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Latest Microsoft Updates Patch 4 Critical Flaws In Windows RDP Client ]]> 2019-09-10T11:36:01+00:00 https://thehackernews.com/2019/09/microsoft-windows-update.html www.secnews.physaphae.fr/article.php?IdArticle=1318040 True Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Firefox 67.0.4 Released - Mozilla Patches Second 0-Day Flaw This Week ]]> 2019-06-21T02:11:04+00:00 https://thehackernews.com/2019/06/firefox-0day-vulnerability.html www.secnews.physaphae.fr/article.php?IdArticle=1166577 False Vulnerability,Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Microsoft Issues Software Updates for 17 Critical Vulnerabilities ]]> 2018-09-11T11:36:02+00:00 https://thehackernews.com/2018/09/microsoft-software-updates.html www.secnews.physaphae.fr/article.php?IdArticle=803562 False Patching None None The Hacker News - The Hacker News est un blog de news de hack (surprenant non?) Microsoft Releases Patches for 60 Flaws-Two Under Active Attack ]]> 2018-08-14T11:36:00+00:00 https://thehackernews.com/2018/08/microsoft-patch-updates.html www.secnews.physaphae.fr/article.php?IdArticle=779652 False Patching None 5.0000000000000000