www.secnews.physaphae.fr This is the RSS 2.0 feed from www.secnews.physaphae.fr. IT's a simple agragated flow of multiple articles soruces. Liste of sources, can be found on www.secnews.physaphae.fr. 2024-05-19T20:49:33+00:00 www.secnews.physaphae.fr Dark Reading - Informationweek Branch \\ 'Commando Cat \\' est la deuxième campagne de l'année ciblant Docker<br>\\'Commando Cat\\' Is Second Campaign of the Year Targeting Docker The threat actor behind the campaign is still unknown, but it shares some similarities with other cyptojacking groups.]]> 2024-02-01T22:20:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/commando-cat-campaign-is-second-this-year-to-target-docker www.secnews.physaphae.fr/article.php?IdArticle=8445746 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch La Chine s'infiltre les infrastructures critiques américaines en accélération au conflit<br>China Infiltrates US Critical Infrastructure in Ramp-up to Conflict Threat actors linked to the People\'s Republic of China, such as Volt Typhoon, continue to "pre-position" themselves in the critical infrastructure of the United States, according to military and law enforcement officials.]]> 2024-02-01T20:30:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/china-infiltrates-us-critical-infrastructure-ramp-up-conflict www.secnews.physaphae.fr/article.php?IdArticle=8445711 False Threat Guam 3.0000000000000000 Dark Reading - Informationweek Branch Le comté de Fulton subit des pannes de courant alors que la cyberattaque se poursuit<br>Fulton County Suffers Power Outages as Cyberattack Continues County services have come to a halt and are not expected to resume until next week; no threat actor has yet been identified.]]> 2024-01-31T22:36:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/fulton-county-suffers-power-outages-cyberattack www.secnews.physaphae.fr/article.php?IdArticle=8445346 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Rapport de menace Microsoft: comment la guerre de la Russie contre l'Ukraine a un impact sur la communauté mondiale de la cybersécurité<br>Microsoft Threat Report: How Russia\\'s War on Ukraine Is Impacting the Global Cybersecurity Community The Russians are engaged in widespread influence operations designed to erode trust, increase polarization, and threaten democratic processes around the globe.]]> 2024-01-31T10:30:00+00:00 https://www.darkreading.com/threat-intelligence/microsoft-threat-report-how-russia-s-war-on-ukraine-is-impacting-the-global-cybersecurity-community www.secnews.physaphae.fr/article.php?IdArticle=8445348 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les correctifs Ivanti Zero-Day sont retardés comme \\ 'Krustyloader \\' Attacks Mount<br>Ivanti Zero-Day Patches Delayed as \\'KrustyLoader\\' Attacks Mount The RCE/auth bypass bugs in Connect Secure VPNs have gone unpatched for 20 days as state-sponsored groups continue to backdoor Ivanti gear.]]> 2024-01-30T23:22:00+00:00 https://www.darkreading.com/endpoint-security/ivanti-zero-day-patches-delayed-krustyloader-attacks-mount www.secnews.physaphae.fr/article.php?IdArticle=8444979 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Feds essaierait de perturber l'infrastructure d'attaque de Typhoon Volt \\ '<br>Feds Reportedly Try to Disrupt \\'Volt Typhoon\\' Attack Infrastructure The China-linked threat actor\'s attacks on US critical infrastructure organizations have alarmed American intelligence officials, Reuters says.]]> 2024-01-30T20:25:00+00:00 https://www.darkreading.com/cybersecurity-operations/us-govt-reportedly-trying-to-disrupt-volt-typhoon-attack-infrastructure www.secnews.physaphae.fr/article.php?IdArticle=8444927 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Nouvellement id \\ 'ed chinois apt cache la porte dérobée dans les mises à jour logicielles<br>Newly ID\\'ed Chinese APT Hides Backdoor in Software Updates The threat actor went more than half a decade before being discovered - thanks to a remarkable backdoor delivered in invisible adversary-in-the-middle attacks.]]> 2024-01-26T21:00:00+00:00 https://www.darkreading.com/application-security/chinese-apt-hides-backdoor-in-software-updates www.secnews.physaphae.fr/article.php?IdArticle=8443534 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Microsoft partage de nouveaux conseils dans le sillage de \\ 'Midnight Blizzard \\' Cyberattack<br>Microsoft Shares New Guidance in Wake of \\'Midnight Blizzard\\' Cyberattack Threat actors created and abused OAuth apps to access Microsoft\'s corporate email environment and remain there for weeks.]]> 2024-01-26T20:37:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/microsoft-shares-new-guidance-in-wake-of-midnight-blizzard-cyberattack www.secnews.physaphae.fr/article.php?IdArticle=8443535 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Fortra révèle le contournement de l'automne critique Vuln à Goanywhere MFT<br>Fortra Discloses Critical Auth Bypass Vuln in GoAnywhere MFT PoC exploit code for flaw is publicly available, heightening breach risks for users of the managed file-transfer technology.]]> 2024-01-24T19:55:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/fortra-discloses-critical-auth-bypass-vuln-in-goanywhere-mft www.secnews.physaphae.fr/article.php?IdArticle=8442665 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les chercheurs mappent le paysage des menaces de l'IA, les risques<br>Researchers Map AI Threat Landscape, Risks With the rush to adopt large language models, companies have not thought through all of the security implications to their businesses. Two groups of researchers tackle the questions.]]> 2024-01-24T14:00:00+00:00 https://www.darkreading.com/cyber-risk/researchers-map-ai-threat-landscape-risks www.secnews.physaphae.fr/article.php?IdArticle=8442552 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Quelques jours après Google, Apple révèle que le moteur du navigateur a exploité le moteur de navigateur<br>Days After Google, Apple Reveals Exploited Zero-Day in Browser Engine The new bug is Apple\'s 12th WebKit zero-day in the last year, highlighting the increasing enterprise exposure to browser-borne threats.]]> 2024-01-23T23:30:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/days-after-google-apple-discloses-actively-exploited-0-day-in-its-browser-engine www.secnews.physaphae.fr/article.php?IdArticle=8442318 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les espions chinois ont exploité le bug de VMware critique pendant près de 2 ans<br>Chinese Spies Exploited Critical VMware Bug for Nearly 2 Years Even the most careful VMware customers may need to go back and double check that they weren\'t compromised by a zero-day exploit for CVE-2023-34048.]]> 2024-01-22T22:08:00+00:00 https://www.darkreading.com/endpoint-security/chinese-spies-exploited-critical-vmware-bug-2-years www.secnews.physaphae.fr/article.php?IdArticle=8441859 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Microsoft est victime de la blizzard \\ 'Midnight Blizzard \\' à minuit \\ '<br>Microsoft Falls Victim to Russia-Backed \\'Midnight Blizzard\\' Cyberattack Russian state-sponsored threat actor Nobelium used a basic password-spray attack to breach Microsoft corporate email accounts, including for execs.]]> 2024-01-22T21:58:00+00:00 https://www.darkreading.com/threat-intelligence/microsoft-falls-victim-russian-midnight-blizzard-cyberattack www.secnews.physaphae.fr/article.php?IdArticle=8441839 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les attaquants de Scarcruft de la Corée du Nord se préparent à cibler les pros de la cybersécurité<br>North Korea\\'s ScarCruft Attackers Gear Up to Target Cybersecurity Pros Based on fresh infection routines the APT is testing, it\'s looking to harvest threat intelligence in order to improve operational security and stealth.]]> 2024-01-22T20:30:00+00:00 https://www.darkreading.com/threat-intelligence/north-koreasc-arcruft-attackers-target-cybersecurity-pros www.secnews.physaphae.fr/article.php?IdArticle=8441819 False Threat APT 37 3.0000000000000000 Dark Reading - Informationweek Branch Israël, République tchèque renforce le cyber-partenariat au milieu de la guerre du Hamas<br>Israel, Czech Republic Reinforce Cyber Partnership Amid Hamas War The agreement to enable future sharing of information and experience is part of a spate of inter-country threat intelligence agreements that Israel is signing, as war-related attacks ramp up.]]> 2024-01-22T17:31:00+00:00 https://www.darkreading.com/cybersecurity-operations/israel-czech-republic-reinforce-cyber-partnership-hamas-war www.secnews.physaphae.fr/article.php?IdArticle=8441756 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Troisième vulnérabilité ivanti exploitée dans la nature, rapporte CISA<br>Third Ivanti Vulnerability Exploited in the Wild, CISA Reports Though reports say this latest Ivanti bug is being exploited, it\'s unclear exactly how threat actors are using it.]]> 2024-01-19T19:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/third-ivanti-vulnerability-exploited-in-the-wild-cisa-reports www.secnews.physaphae.fr/article.php?IdArticle=8440748 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch L'IA donne aux défenseurs l'avantage de la défense des entreprises<br>AI Gives Defenders the Advantage in Enterprise Defense A panel of CISOs acknowledged that artificial intelligence has boosted the capabilities of threat actors, but enterprise defenders are actually benefiting more from the technology.]]> 2024-01-18T23:00:00+00:00 https://www.darkreading.com/cyber-risk/ai-gives-defenders-the-advantage-in-enterprise-defense www.secnews.physaphae.fr/article.php?IdArticle=8440749 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les acteurs de la menace s'associent pour une augmentation des e-mails de phishing après les vacances<br>Threat Actors Team Up for Post-Holiday Phishing Email Surge Just like you and me, cyberattackers returned from winter break and immediately started sending thousands of emails.]]> 2024-01-18T22:46:00+00:00 https://www.darkreading.com/threat-intelligence/threat-actors-post-holiday-phishing-email-surge www.secnews.physaphae.fr/article.php?IdArticle=8440443 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'chaes \\' Le code d'infostealer contient des notes d'amour de chasse à la menace cachée<br>\\'Chaes\\' Infostealer Code Contains Hidden Threat Hunter Love Notes Analysis of the infostealer malware version 4.1 includes hidden ASCII art and a shout-out thanking cybersecurity researchers.]]> 2024-01-18T15:15:00+00:00 https://www.darkreading.com/threat-intelligence/chaes-infostealer-code-threat-hunter-love-notes www.secnews.physaphae.fr/article.php?IdArticle=8440332 False Malware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Google Chrome Zero-Day Bug attaqué, permet l'injection de code<br>Google Chrome Zero-Day Bug Under Attack, Allows Code Injection The first Chrome zero-day bug of 2024 adds to a growing list of actively exploited vulnerabilities found in Chromium and other browser technologies.]]> 2024-01-17T21:15:00+00:00 https://www.darkreading.com/cloud-security/google-chrome-zero-day-bug-attack-code-injection www.secnews.physaphae.fr/article.php?IdArticle=8440044 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Force en nombre: le cas de la cybersécurité de tout l'État<br>Strength in Numbers: The Case for Whole-of-State Cybersecurity WoS cybersecurity creates a united front for governments to defend against threat actors, harden security postures, and protect constituents who depend on services.]]> 2024-01-17T15:00:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/strength-in-numbers-the-case-for-whole-of-state-cybersecurity www.secnews.physaphae.fr/article.php?IdArticle=8439907 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les exploits d'Ivanti Zero-Day montent en flèche dans le monde;Pas encore de correctifs<br>Ivanti Zero-Day Exploits Skyrocket Worldwide; No Patches Yet Anyone who hasn\'t mitigated two zero-day security bugs in Ivanti VPNs may already be compromised by a Chinese nation-state actor.]]> 2024-01-16T21:25:00+00:00 https://www.darkreading.com/cloud-security/ivanti-zero-day-exploits-skyrocket-no-patches www.secnews.physaphae.fr/article.php?IdArticle=8439675 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch 178K + pare-feu Sonicwall vulnérable aux dossiers DOS, RCE<br>178K+ SonicWall Firewalls Vulnerable to DoS, RCE Attacks Two flaws discovered a year apart are ostensibly the same with slightly different exploit paths, exposing corporate networks to risk and potential intrusion.]]> 2024-01-16T16:43:00+00:00 https://www.darkreading.com/vulnerabilities-threats/78k-sonicwall-firewalls-vulnerable-dos-rce-attacks www.secnews.physaphae.fr/article.php?IdArticle=8439604 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Le FBI met en garde plus d'élections & quot; chaos & quot;en 2024<br>FBI Warns More Election "Chaos" in 2024 FBI Director Christopher Wray says to have confidence in the American election system but to expect ongoing information warfare, pointing to China as most formidable threat actor.]]> 2024-01-12T13:00:00+00:00 https://www.darkreading.com/cloud-security/fbi-warns-more-election-chaos-in-2024 www.secnews.physaphae.fr/article.php?IdArticle=8438273 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Volt Typhoon augmente l'activité malveillante contre les infrastructures critiques<br>Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure The Chinese state-sponsored APT has compromised as many as 30% of Cisco legacy routers on a SOHO botnet that multiple threat groups use.]]> 2024-01-11T22:49:00+00:00 https://www.darkreading.com/cyber-risk/volt-typhoon-ramps-up-malicious-activity-critical-infrastructure www.secnews.physaphae.fr/article.php?IdArticle=8438034 False Threat Guam 3.0000000000000000 Dark Reading - Informationweek Branch Les chercheurs de l'Ivanti signalent deux vulnérabilités critiques à jour zéro<br>Ivanti Researchers Report Two Critical Zero-Day Vulnerabilities Patches will be available in late January and February, but until then, customers must take mitigation measures.]]> 2024-01-11T21:43:00+00:00 https://www.darkreading.com/vulnerabilities-threats/ivanti-researchers-report-of-two-critical-zero-day-vulnerabilities www.secnews.physaphae.fr/article.php?IdArticle=8438016 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Pikabot Malware surface en remplacement de Qakbot pour les attaques Black Basta<br>Pikabot Malware Surfaces As Qakbot Replacement for Black Basta Attacks An emerging threat actor, Water Curupira, is wielding a new, sophisticated loader in a series of thread-jacking phishing campaigns that precede ransomware.]]> 2024-01-10T16:29:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/pikabot-malware-qakbot-replacement-black-basta-attacks www.secnews.physaphae.fr/article.php?IdArticle=8437569 False Ransomware,Malware,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Turkish Cyber Threat cible les serveurs MSSQL avec des ransomwares Mimic<br>Turkish Cyber Threat Targets MSSQL Servers With Mimic Ransomware Microsoft\'s database continues to attract cybercriminal attention; the nature of this wave\'s threat group is unknown, with the attacks having been exposed only after a happenstance OpSec lag.]]> 2024-01-09T18:36:00+00:00 https://www.darkreading.com/ics-ot-security/turkish-cyber-threat-targets-mssql-servers-mimic-ransomware www.secnews.physaphae.fr/article.php?IdArticle=8437254 False Ransomware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Outil de surveillance des cactus enrichi par une vulnérabilité critique d'injection SQL<br>Cacti Monitoring Tool Spiked by Critical SQL Injection Vulnerability Attackers can exploit the issue to access all data in Cacti database; and, it enables RCE when chained with a previous vulnerability.]]> 2024-01-08T23:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/cacti-monitoring-tool-critical-sql-injection-vulnerability www.secnews.physaphae.fr/article.php?IdArticle=8436853 False Tool,Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Turkish Apt \\ 'Turtle de la mer \\' refait surface pour espionner l'opposition kurde<br>Turkish APT \\'Sea Turtle\\' Resurfaces to Spy on Kurdish Opposition An old state-aligned threat actor is back on the radar, thanks to recent EMEA espionage campaigns against a minority ethnic group.]]> 2024-01-08T21:49:00+00:00 https://www.darkreading.com/threat-intelligence/turkish-apt-sea-turtle-spy-kurdish-opposition www.secnews.physaphae.fr/article.php?IdArticle=8436829 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'Swatting \\' devient la dernière tactique d'extorsion dans les attaques de ransomwares<br>\\'Swatting\\' Becomes Latest Extortion Tactic in Ransomware Attacks Threat actors leave medical centers with the difficult choice of paying the ransom or witnessing patients suffer the consequences.]]> 2024-01-08T18:22:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/swatting-latest-extortion-tactic-ransomware-attacks www.secnews.physaphae.fr/article.php?IdArticle=8436755 False Ransomware,Threat,Medical None 3.0000000000000000 Dark Reading - Informationweek Branch Le groupe de menaces syriennes colporte un argent destructeur<br>Syrian Threat Group Peddles Destructive SilverRAT The Middle Eastern developers claim to be building a new version of the antivirus-bypassing remote access Trojan (RAT) attack tool.]]> 2024-01-05T19:19:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/syrian-threat-group-peddles-destructive-silverrat www.secnews.physaphae.fr/article.php?IdArticle=8435267 False Tool,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Groupe de menaces utilisant une tactique de transfert de données rares dans une nouvelle campagne de remcosrat<br>Threat Group Using Rare Data Transfer Tactic in New RemcosRAT Campaign UNC-0050 is targeting government agencies in Ukraine in what appears to be a politically motivated intelligence-gathering operation.]]> 2024-01-05T01:27:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/threat-group-using-rare-data-transfer-tactic-in-new-remcosrat-campaign www.secnews.physaphae.fr/article.php?IdArticle=8434800 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch \\ 'Cyber Toufan \\' Hacktivistes a divulgué plus de 100 orgs israéliens en un mois<br>\\'Cyber Toufan\\' Hacktivists Leaked 100-Plus Israeli Orgs in One Month A new threat actor just concluded a month and a half of two major leaks per day. Now comes phase two: follow-on attacks.]]> 2024-01-04T14:32:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/-cyber-toufan-hacktivists-leaked-100-plus-israeli-orgs-in-one-month www.secnews.physaphae.fr/article.php?IdArticle=8434454 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Apache Erp Zero-Day souligne les dangers des correctifs incomplets<br>Apache ERP Zero-Day Underscores Dangers of Incomplete Patches Apache fixed a vulnerability in its OfBiz enterprise resource planning (ERP) framework last month, but attackers and researchers found a way around the patch.]]> 2024-01-03T21:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/apache-erp-0day-underscores-dangers-of-incomplete-patches www.secnews.physaphae.fr/article.php?IdArticle=8434658 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch En cybersécurité et en mode, ce qui est l'ancien est nouveau<br>In Cybersecurity and Fashion, What\\'s Old Is New Again What a recent rise in DDoS attacks portends - and how to prepare for 2024.]]> 2023-12-28T15:00:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/in-cybersecurity-whats-old-is-new-again www.secnews.physaphae.fr/article.php?IdArticle=8430318 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Google libère le huitième patch zéro-jour de 2023 pour Chrome<br>Google Releases Eighth Zero-Day Patch of 2023 for Chrome CVE-2023-7024, exploited in the wild prior to patching, is a Chrome vulnerability that allows remote code execution within the browser\'s WebRTC component.]]> 2023-12-22T18:00:00+00:00 https://www.darkreading.com/cloud-security/google-eighth-zero-day-patch-2023-chrome www.secnews.physaphae.fr/article.php?IdArticle=8427494 False Vulnerability,Threat,Patching None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'Battleroyal \\' Les pirates offrent un rat Darkgate en utilisant chaque astuce<br>\\'BattleRoyal\\' Hackers Deliver DarkGate RAT Using Every Trick The shadowy threat actor uses some nifty tricks to drop popular malware with targets that meet its specifications.]]> 2023-12-21T22:00:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/battleroyal-hackers-deliver-darkgate-rat www.secnews.physaphae.fr/article.php?IdArticle=8427012 False Malware,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les attaquants exploitent le bug Microsoft Office de 6 ans pour répandre les logiciels espions<br>Attackers Exploit 6-Year-Old Microsoft Office Bug to Spread Spyware Malicious attachments that exploit an RCE flaw from 2017 are propagating Agent Tesla via socially engineered emails and an evasive infection method.]]> 2023-12-20T16:00:00+00:00 https://www.darkreading.com/cloud-security/attackers-exploit-microsoft-office-bug-spyware www.secnews.physaphae.fr/article.php?IdArticle=8426182 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch 3 façons d'utiliser des renseignements en temps réel pour vaincre les robots<br>3 Ways to Use Real-Time Intelligence to Defeat Bots Threat intelligence feedback loops are an increasingly vital tool in the escalating battle against bots.]]> 2023-12-20T15:00:00+00:00 https://www.darkreading.com/threat-intelligence/3-ways-real-time-intelligence-defeat-bots www.secnews.physaphae.fr/article.php?IdArticle=8426150 False Tool,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch 5 Informations essentielles du rapport de défense numérique \\ 'Microsoft 2023 \\'<br>5 Essential Insights From the \\'Microsoft Digital Defense Report 2023\\' By reviewing the latest risks, organizations can better protect themselves against a dynamic threat landscape - and deploy technologies and policies that keep them better defended.]]> 2023-12-20T13:55:00+00:00 https://www.darkreading.com/threat-intelligence/5-essential-insights-from-the-microsoft-digital-defense-report-2023 www.secnews.physaphae.fr/article.php?IdArticle=8426116 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: exploiter les supports d'activité pour dangereux Apache Struts 2 Bogue<br>Patch Now: Exploit Activity Mounts for Dangerous Apache Struts 2 Bug CVE-2023-50164 is harder to exploit than the 2017 Struts bug behind the massive breach at Equifax, but don\'t underestimate the potential for attackers to use it in targeted attacks.]]> 2023-12-15T20:55:00+00:00 https://www.darkreading.com/cloud-security/patch-exploit-activity-dangerous-apache-struts-bug www.secnews.physaphae.fr/article.php?IdArticle=8423394 False Threat Equifax 3.0000000000000000 Dark Reading - Informationweek Branch SOHO BOTNET VOLT TYPHOON INFECTE<br>Volt Typhoon-Linked SOHO Botnet Infects Multiple US Gov\\'t Entities Chinese threat actors are taking advantage of the poor state of edge security to breach both small and big fish.]]> 2023-12-14T22:18:00+00:00 https://www.darkreading.com/cloud-security/volt-typhoon-soho-botnet-infects-us-govt-entities www.secnews.physaphae.fr/article.php?IdArticle=8422884 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Nouveau acteur de menace \\ 'gambleforce \\' derrière des attaques d'injection SQL<br>New \\'GambleForce\\' Threat Actor Behind String of SQL Injection Attacks The fresh-faced cybercrime group has been using nothing but publicly available penetration testing tools in its campaign so far.]]> 2023-12-14T22:00:00+00:00 https://www.darkreading.com/cloud-security/gambleforce-threat-actor-sql-injection-attacks www.secnews.physaphae.fr/article.php?IdArticle=8422886 False Tool,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch L'exploitation mondiale de l'équipe ouvre la porte au cauchemar de style solarwinds<br>Global TeamCity Exploitation Opens Door to SolarWinds-Style Nightmare Russia\'s APT29 is going after a critical RCE flaw in the JetBrains TeamCity software developer platform, prompting governments worldwide to issue an urgent warning to patch.]]> 2023-12-13T23:26:00+00:00 https://www.darkreading.com/vulnerabilities-threats/global-teamcity-exploitation-opens-door-to-solarwinds-style-nightmare www.secnews.physaphae.fr/article.php?IdArticle=8422329 False Threat APT 29 3.0000000000000000 Dark Reading - Informationweek Branch Mitre lance la modélisation des menaces ICS pour les systèmes intégrés<br>MITRE Debuts ICS Threat Modeling for Embedded Systems EMB3D, like ATT&CK and CWE, seeks to provide a common understanding of cyber-threats to embedded devices and of the security mechanisms for addressing them.]]> 2023-12-13T20:48:00+00:00 https://www.darkreading.com/ics-ot-security/mitre-debuts-ics-cyber-threat-modeling-embedded-systems www.secnews.physaphae.fr/article.php?IdArticle=8422260 False Threat,Industrial None 4.0000000000000000 Dark Reading - Informationweek Branch Les attaquants ciblent les comptes Microsoft pour armer les applications OAuth<br>Attackers Target Microsoft Accounts to Weaponize OAuth Apps After compromising Azure and Outlook user accounts, threat actors are creating malicious apps with high privileges to conduct cryptomining, phishing, and password spraying.]]> 2023-12-13T18:45:00+00:00 https://www.darkreading.com/cloud-security/attackers-target-microsoft-accounts-weaponize-oauth-apps www.secnews.physaphae.fr/article.php?IdArticle=8422214 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les gangs de ransomware utilisent l'offensive du charme des relations publiques pour faire pression sur les victimes<br>Ransomware Gangs Use PR Charm Offensive to Pressure Victims Threat actors are fully embracing the spin machine: rebranding, speaking with the media, writing detailed FAQs, and more, all in an effort to make headlines.]]> 2023-12-13T11:00:00+00:00 https://www.darkreading.com/threat-intelligence/ransomware-gangs-pr-charm-offensive-pressure-victims www.secnews.physaphae.fr/article.php?IdArticle=8422002 False Ransomware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch ALPHV/BlackCat Takedown Appears to Be Law Enforcement Related Threat intel sources confirm the ransomware group\'s site has been shuttered by law enforcement.]]> 2023-12-09T01:02:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/alphv-blackcat-takedown-appears-to-be-law-enforcement-related www.secnews.physaphae.fr/article.php?IdArticle=8421099 False Ransomware,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch ALPHV / Blackcat Takedown semble être lié aux forces de l'ordre<br>ALPHV/BlackCat Takedown Appears to Be Law Enforcement Related Threat intel sources confirm the ransomware group\'s site has been shuttered by law enforcement.]]> 2023-12-09T01:02:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/alphv-blackcat-takedown-appears-to-be-law-enforcement-related- www.secnews.physaphae.fr/article.php?IdArticle=8420325 False Ransomware,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Russian Espionage Group Hammers zéro cliquez sur Microsoft Outlook Bug<br>Russian Espionage Group Hammers Zero-Click Microsoft Outlook Bug State-sponsored actors continue to exploit CVE-2023-23397, a dangerous no-interaction vulnerability in Microsoft\'s Outlook email client that was patched in March, in a widespread global campaign.]]> 2023-12-08T15:00:00+00:00 https://www.darkreading.com/ics-ot-security/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug www.secnews.physaphae.fr/article.php?IdArticle=8420259 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les 3 cyber-menaces les plus répandues des vacances<br>The 3 Most Prevalent Cyber Threats of the Holidays Chaos and volume of holiday season sales make a perfect storm of threat opportunity. Companies need to prepare - and practice! - action plans, identify key stakeholders, and consider cyber insurance.]]> 2023-12-08T15:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/3-most-prevalent-cyber-threats-holidays www.secnews.physaphae.fr/article.php?IdArticle=8420216 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Cybersixgill annonce un module de renseignement d'identité pour l'analyse des menaces<br>Cybersixgill Announces Identity Intelligence Module for Threat Analysis 2023-12-07T23:18:00+00:00 https://www.darkreading.com/threat-intelligence/cybersixgill-announces-identity-intelligence-module-for-threat-analysis www.secnews.physaphae.fr/article.php?IdArticle=8420041 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Ransomware, les violations de données sont inondées de l'OT et du secteur industriel<br>Ransomware, Data Breaches Inundate OT & Industrial Sector Because of the criticality of remaining operational, industrial companies and utilities are far more likely to pay, attracting even more threat groups and a focus on OT systems.]]> 2023-12-07T19:00:00+00:00 https://www.darkreading.com/ics-ot-security/ransomware-data-breaches-inundate-ot-industrial-sector www.secnews.physaphae.fr/article.php?IdArticle=8419977 False Ransomware,Threat,Industrial None 3.0000000000000000 Dark Reading - Informationweek Branch Dragos étend le programme de défense pour les petits services publics<br>Dragos Expands Defense Program for Small Utilities The Dragos Community Defense Program provides small water, gas, and electric utilities with access to the Dragos Platform, training resources, and threat intelligence.]]> 2023-12-07T15:00:00+00:00 https://www.darkreading.com/ics-ot-security/dragos-expands-defense-program-for-small-utilities www.secnews.physaphae.fr/article.php?IdArticle=8419908 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch CISA: L'acteur de menace a violé les systèmes fédéraux via Adobe Coldfusion Flaw<br>CISA: Threat Actor Breached Federal Systems via Adobe ColdFusion Flaw Adobe patched CVE-2023-26360 in March amid active exploit activity targeting the flaw.]]> 2023-12-06T22:26:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/hreat-actor-breached-federal-agency-systems-via-adobe-coldfusion-flaw-cisa-says www.secnews.physaphae.fr/article.php?IdArticle=8419702 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Paiements Géant Tipalti: pas de violation de ransomware, pas de menace pour Roblox<br>Payments Giant Tipalti: No Ransomware Breach, No Threat to Roblox BlackCat/ALPHV claims it has had access to the payments technology vendor\'s systems since September, and threatens follow-on attacks on its customer Roblox.]]> 2023-12-05T21:19:00+00:00 https://www.darkreading.com/application-security/payments-giant-tipalti-no-ransomware-breach-roblox www.secnews.physaphae.fr/article.php?IdArticle=8419379 False Ransomware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Feds saisit \\ 'Sinbad \\' Mélangeur cryptographique utilisé par la Corée du Nord \\'s Lazarus<br>Feds Seize \\'Sinbad\\' Crypto Mixer Used by North Korea\\'s Lazarus The prolific threat actor has laundered hundreds of millions of dollars in stolen virtual currency through the service.]]> 2023-11-30T17:35:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/feds-seize-sinbad-crypto-mixer-used-by-north-korea-s-lazarus www.secnews.physaphae.fr/article.php?IdArticle=8418122 False Threat APT 38,APT 38 2.0000000000000000 Dark Reading - Informationweek Branch Le partenariat Wiz-Securonix promet une détection de menace unifiée<br>Wiz-Securonix Partnership Promises Unified Threat Detection The collaboration focuses on helping security teams detect and address cloud threats more effectively.]]> 2023-11-30T02:00:00+00:00 https://www.darkreading.com/cloud-security/wiz-securonix-partnership-promises-unified-threat-detection www.secnews.physaphae.fr/article.php?IdArticle=8418084 False Threat,Cloud None 2.0000000000000000 Dark Reading - Informationweek Branch CISA au Congrès: États-Unis menace d'attaques chimiques<br>CISA to Congress: US Under Threat of Chemical Attacks Dropping the ball on chemical security has precipitated "a national security gap too great to ignore," CISA warns.]]> 2023-11-28T22:00:00+00:00 https://www.darkreading.com/cyber-risk/cisa-to-congress-us-under-threat-of-chemical-attacks www.secnews.physaphae.fr/article.php?IdArticle=8417647 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Cyber menaces à faire attention en 2024<br>Cyber Threats to Watch Out for in 2024 As cyber threats evolve in 2024, organizations must prepare for deepfakes, extortion, cloud targeting, supply chain compromises, and zero day exploits. Robust security capabilities, employee training, and incident response plans are key.]]> 2023-11-27T23:16:00+00:00 https://www.darkreading.com/edge/cyber-threats-to-watch-out-for-in-2024 www.secnews.physaphae.fr/article.php?IdArticle=8417351 False Threat,Cloud None 2.0000000000000000 Dark Reading - Informationweek Branch Cyber Threats to Watch Out for in 2024 As cyber threats evolve in 2024, organizations must prepare for deepfakes, extortion, cloud targeting, supply chain compromises, and zero day exploits. Robust security capabilities, employee training, and incident response plans are key.]]> 2023-11-27T23:16:00+00:00 https://www.darkreading.com/cyber-risk/cyber-threats-to-watch-out-for-in-2024 www.secnews.physaphae.fr/article.php?IdArticle=8418317 False Threat,Prediction,Cloud None 3.0000000000000000 Dark Reading - Informationweek Branch Exploit for Critical Windows Defender Bypass Goes Public Threat actors were actively exploiting CVE-2023-36025 in Windows SmartScreen as a zero-day vulnerability before Microsoft patched it in November.]]> 2023-11-21T21:29:00+00:00 https://www.darkreading.com/vulnerabilities-threats/exploit-for-critical-windows-defender-bypass-goes-public www.secnews.physaphae.fr/article.php?IdArticle=8417434 False Vulnerability,Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Exploiter pour le pontage critique de Windows Defender devient public<br>Exploit for Critical Windows Defender Bypass Goes Public Threat actors were actively exploiting CVE-2023-36025 in Windows SmartScreen as a zero-day vulnerability before Microsoft patched it in November.]]> 2023-11-21T21:29:00+00:00 https://www.darkreading.com/vulnerabilities-threats/exploit-critical-windows-defender-bypass-public www.secnews.physaphae.fr/article.php?IdArticle=8415587 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Kinsing Cyberattackers Target Apache ActiveMQ Flaw to Mine Crypto Active exploit of the critical RCE flaw targets Linux systems to achieve full system compromise.]]> 2023-11-21T16:30:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/kinsing-cyberattackers-target-apache-activemq-flaw-to-mine-crypto www.secnews.physaphae.fr/article.php?IdArticle=8417436 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Kinsing Cyberattackers ciblera Apache ActiveMq Flaw to Mine Crypto<br>Kinsing Cyberattackers Target Apache ActiveMQ Flaw to Mine Crypto Active exploit of the critical RCE flaw targets Linux systems to achieve full system compromise.]]> 2023-11-21T16:30:00+00:00 https://www.darkreading.com/attacks-breaches/kinsing-cyberattackers-target-apache-activemq-flaw-to-mine-crypto www.secnews.physaphae.fr/article.php?IdArticle=8415472 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Preuve de concept Exploit disponible publiquement pour les fenêtres critiques de Windows SmartScreen Flaw<br>Proof of Concept Exploit Publicly Available for Critical Windows SmartScreen Flaw Threat actors were actively exploiting CVE-2023-36025 before Microsoft patched it in November.]]> 2023-11-21T00:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/proof-of-concept-exploit-publicly-available-for-critical-windows-smartscreen-flaw www.secnews.physaphae.fr/article.php?IdArticle=8416075 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les vulnérabilités exploitées peuvent prendre des mois pour faire la liste KEV<br>Exploited Vulnerabilities Can Take Months to Make KEV List The Known Exploited Vulnerabilities (KEV) catalog is a high-quality source of information on software flaws being exploited in the wild, but updates are often delayed, so companies need other sources of threat intelligence.]]> 2023-11-20T19:16:03+00:00 https://www.darkreading.com/edge/exploited-vulnerabilities-take-months-to-make-kev-list www.secnews.physaphae.fr/article.php?IdArticle=8415098 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Tirer parti de Sandbox et des aliments de renseignement sur les menaces pour lutter contre les cyber-menaces<br>Leveraging Sandbox and Threat Intelligence Feeds to Combat Cyber Threats Combining a malware sandbox with threat intelligence feeds improves security detection, analysis, and response capabilities.]]> 2023-11-20T08:00:00+00:00 https://www.darkreading.com/threat-intelligence/leveraging-sandbox-and-threat-intelligence-feeds-to-combat-cyber-threats www.secnews.physaphae.fr/article.php?IdArticle=8414726 False Malware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Une référence de détection et de réponse conçue pour le nuage<br>A Detection and Response Benchmark Designed for the Cloud Does your security operation center\'s performance meet the 5/5/5 benchmark for cloud threat detection and incident response?]]> 2023-11-20T08:00:00+00:00 https://www.darkreading.com/cloud/5-5-5-benchmark-cloud-detection-and-response www.secnews.physaphae.fr/article.php?IdArticle=8414727 False Threat,Cloud,Technical None 4.0000000000000000 Dark Reading - Informationweek Branch Dangereux exploit activemq apache permet de contourner EDR furtif<br>Dangerous Apache ActiveMQ Exploit Allows Stealthy EDR Bypass There\'s no time to waste: For organizations on the fence about patching the critical bug in ActiveMQ, the new proof-of-concept exploit should push them towards action.]]> 2023-11-16T22:45:00+00:00 https://www.darkreading.com/application-security/dangerous-apache-activemq-exploit-edr-bypass www.secnews.physaphae.fr/article.php?IdArticle=8413104 False Threat,Patching None 2.0000000000000000 Dark Reading - Informationweek Branch L'investissement en cybersécurité implique plus que la technologie<br>Cybersecurity Investment Involves More Than Just Technology Cybersecurity investment involves more than just buying security technologies - organizations are also looking at threat intelligence, risk assessment, cyber-insurance, and third-party risk management.]]> 2023-11-16T17:00:00+00:00 https://www.darkreading.com/tech-trends/cybersecurity-investment-more-than-technology www.secnews.physaphae.fr/article.php?IdArticle=8413289 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les jours zéro dans les dispositifs de bord deviennent la tactique de cyber-guerre de la Chine de choix<br>Zero-Days in Edge Devices Become China\\'s Cyber Warfare Tactic of Choice While China is already among the world\'s most formidable threat actors, a focus on exploiting public-facing appliances makes its state-sponsored APTs more dangerous than ever.]]> 2023-11-14T20:23:00+00:00 https://www.darkreading.com/vulnerabilities-threats/zero-days-in-edge-devices-china-cyber-warfare-tactic www.secnews.physaphae.fr/article.php?IdArticle=8412076 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les logiciels malveillants à queue de canard ciblent l'industrie de la mode<br>Ducktail Malware Targets the Fashion Industry Threat actors distributed an archive containing images of new products by major clothing companies, along with a malicious executable disguised with a PDF icon.]]> 2023-11-13T19:09:00+00:00 https://www.darkreading.com/threat-intelligence/ducktail-malware-targets-fashion-industry www.secnews.physaphae.fr/article.php?IdArticle=8411237 False Malware,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Chatgpt: OpenAI attribue des pannes régulières aux attaques DDOS<br>ChatGPT: OpenAI Attributes Regular Outages to DDoS Attacks ChatGPT and the associated APIs have been affected by regular outages, citing DDoS attacks as the reason - the Anonymous Sudan group claimed responsibility.]]> 2023-11-10T18:18:00+00:00 https://www.darkreading.com/attacks-breaches/chatgpt-openai-attributes-regular-outages-ddos-attacks www.secnews.physaphae.fr/article.php?IdArticle=8409248 False Threat ChatGPT 2.0000000000000000 Dark Reading - Informationweek Branch \\ 'BLAZESTEALER \\' Python Malware permet une prise de contrôle complète des machines des développeurs<br>\\'BlazeStealer\\' Python Malware Allows Complete Takeover of Developer Machines Checkmarx researchers warn that BlazeStealer can exfiltrate information, steal passwords, disable PCs, and take over webcams.]]> 2023-11-09T23:15:00+00:00 https://www.darkreading.com/application-security/-blazestealer-python-malware-complete-takeover-developer www.secnews.physaphae.fr/article.php?IdArticle=8408794 False Malware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les hacktivistes mondiaux prennent parti sur Gaza, avec peu de choses à montrer pour cela<br>Worldwide Hacktivists Take Sides Over Gaza, With Little to Show for It Keyboard warriors are claiming to contribute to the Gaza war with OT attacks. You should be skeptical.]]> 2023-11-09T15:50:00+00:00 https://www.darkreading.com/dr-global/worldwide-hacktivists-take-sides-over-gaza-with-little-show www.secnews.physaphae.fr/article.php?IdArticle=8408576 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Exploit de bogues atlassian critique maintenant disponible;Patchage immédiat nécessaire<br>Critical Atlassian Bug Exploit Now Available; Immediate Patching Needed In-the-wild exploit activity from dozens of cyberattacker networks is ramping up for the security vulnerability in Confluence, tracked as CVE-2023-22518.]]> 2023-11-03T21:51:00+00:00 https://www.darkreading.com/attacks-breaches/critical-atlassian-bug-exploit-immediate-patching www.secnews.physaphae.fr/article.php?IdArticle=8405538 False Vulnerability,Threat,Patching None 2.0000000000000000 Dark Reading - Informationweek Branch Le PDG saoudien Aramco met en garde contre une nouvelle menace de l'IA générative<br>Saudi Aramco CEO Warns of New Threat of Generative AI Oil executive Amin H. Nasser calls for global cooperation and international standards to combat the dark side of artificial intelligence.]]> 2023-11-02T17:30:00+00:00 https://www.darkreading.com/dr-global/saudi-aramco-ceo-warns-of-new-threat-of-generative-ai www.secnews.physaphae.fr/article.php?IdArticle=8404842 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch La prévention des menaces commence avec l'informatique et la collaboration de l'équipe de sécurité<br>Threat Prevention Begins With IT & Security Team Collaboration As cyber threats evolve, so does the shared responsibility mindset that calls for IT and security to work in tandem.]]> 2023-11-02T14:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/threat-prevention-begins-with-it-security-team-collaboration www.secnews.physaphae.fr/article.php?IdArticle=8404702 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les bibliothèques britanniques de Toronto luttent après les cyber-incidents<br>British, Toronto Libraries Struggle After Cyber Incidents It\'s unknown who the threat actors are and whether the outages are connected.]]> 2023-11-01T21:26:00+00:00 https://www.darkreading.com/attacks-breaches/british-toronto-libraries-struggle-after-cyber-incidents www.secnews.physaphae.fr/article.php?IdArticle=8404363 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Il est bon marché d'exploiter les logiciels - et c'est un problème de sécurité majeur<br>It\\'s Cheap to Exploit Software - and That\\'s a Major Security Problem The solution? Follow in the footsteps of companies that have raised the cost of exploitation.]]> 2023-11-01T14:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/its-cheap-to-exploit-software-major-security-problem www.secnews.physaphae.fr/article.php?IdArticle=8404117 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les États-Unis mènent une alliance de 40 pays pour couper les paiements des ransomwares<br>US Leads 40-Country Alliance to Cut Off Ransomware Payments The parties within the International Counter Ransomware Initiative intend to use information-sharing tools and AI to achieve their goals of cutting off the financial resources of threat actors.]]> 2023-10-31T19:25:00+00:00 https://www.darkreading.com/endpoint/us-leads-alliance-cut-off-ransomware-attack-payments www.secnews.physaphae.fr/article.php?IdArticle=8403702 False Ransomware,Tool,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Google Dynamic Search Ads a abusé pour libérer les logiciels malveillants \\ 'déluge \\'<br>Google Dynamic Search Ads Abused to Unleash Malware \\'Deluge\\' An advanced feature of Google targeted ads can allow a rarely precedented flood of malware infections, rendering machines completely useless.]]> 2023-10-30T22:08:00+00:00 https://www.darkreading.com/endpoint/google-dynamic-search-ads-malware-deluge www.secnews.physaphae.fr/article.php?IdArticle=8403170 False Malware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Octo Tempest Group menace la violence physique en tant que tactique d'ingénierie sociale<br>Octo Tempest Group Threatens Physical Violence As Social Engineering Tactic The financially motivated English-speaking threat actors use advanced social engineering techniques, SIM swapping, and even threats of violence to breach targets.]]> 2023-10-27T19:08:00+00:00 https://www.darkreading.com/threat-intelligence/octo-tempest-group-threatens-physical-violence-social-engineering-tactic www.secnews.physaphae.fr/article.php?IdArticle=8401560 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Iriusrisk apporte la modélisation des menaces aux systèmes d'apprentissage automatique<br>IriusRisk Brings Threat Modeling to Machine Learning Systems The newly launched AI & ML Security Library allows developers to analyze the code used in machine learning systems to identify and address risks.]]> 2023-10-26T22:00:00+00:00 https://www.darkreading.com/dr-tech/iriusrisk-brings-threat-modeling-to-machine-learning www.secnews.physaphae.fr/article.php?IdArticle=8401183 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch L'Iran APT cible la Méditerranée avec des attaques d'arrosage<br>Iran APT Targets the Mediterranean With Watering-Hole Attacks Nation-state hackers are using hybrids to ensnare those in the maritime, shipping, and logistics industries.]]> 2023-10-26T19:35:00+00:00 https://www.darkreading.com/dr-global/iran-apt-targets-mediterranean-watering-hole-attacks www.secnews.physaphae.fr/article.php?IdArticle=8401035 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch BHI Energy libère les détails de l'attaque des ransomwares Akira<br>BHI Energy Releases Details of Akira Ransomware Attack The threat actor exfiltrated 690 gigabytes of uncompressed data, or 767,035 files.]]> 2023-10-25T23:59:00+00:00 https://www.darkreading.com/attacks-breaches/bhi-energy-releases-details-of-akira-ransomware-attack www.secnews.physaphae.fr/article.php?IdArticle=8400611 False Ransomware,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Alors que Citrix exhorte ses clients à patcher, les chercheurs publient un exploit<br>As Citrix Urges Its Clients to Patch, Researchers Release an Exploit In the race over Citrix\'s latest vulnerability, the bad guys have a huge head start, with broad implications for businesses and critical infrastructure providers worldwide.]]> 2023-10-25T19:55:00+00:00 https://www.darkreading.com/vulnerabilities-threats/citrix-urges-clients-patch-researchers-release-exploit www.secnews.physaphae.fr/article.php?IdArticle=8400552 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Alarme virtuelle: VMware émet un avis de sécurité majeur<br>Virtual Alarm: VMware Issues Major Security Advisory VMware vCenter Servers need immediate patch against critical RCE bug as race against threat actors begins.]]> 2023-10-25T19:38:00+00:00 https://www.darkreading.com/vulnerabilities-threats/vmware-issues-alarming-security-advisory www.secnews.physaphae.fr/article.php?IdArticle=8400553 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Winter Vivern apt Blast webmail zéro-day bug avec un clic exploit<br>Winter Vivern APT Blasts Webmail Zero-Day Bug With One-Click Exploit A campaign targeting European governmental organizations and a think tank shows consistency from the low-profile threat group, which has ties to Belarus and Russia.]]> 2023-10-25T15:37:00+00:00 https://www.darkreading.com/endpoint/winter-vivern-blasts-webmail-0day-one-click-exploit www.secnews.physaphae.fr/article.php?IdArticle=8400186 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch 1Password devient la dernière victime de la violation du service client OKTA<br>1Password Becomes Latest Victim of Okta Customer Service Breach Okta\'s IAM platform finds itself in cyberattackers\' sights once again, as threat actors mount a supply chain attack targeting Okta customer support engagements.]]> 2023-10-24T20:14:00+00:00 https://www.darkreading.com/remote-workforce/1password-latest-victim-okta-customer-service-breach www.secnews.physaphae.fr/article.php?IdArticle=8399877 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les conflits israélo-hamas épellent les escrocs en ligne<br>Israeli-Hamas Conflict Spells Opportunity for Online Scammers As the conflict in the Middle East rages, malicious actors look to exploit the situation with bogus charity sites encouraging donations.]]> 2023-10-24T16:08:00+00:00 https://www.darkreading.com/dr-global/israeli-hamas-conflict-spells-opportunity-for-online-scammers www.secnews.physaphae.fr/article.php?IdArticle=8399783 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Cisco trouve un nouveau bug de jour zéro, des correctifs de promesses en jours<br>Cisco Finds New Zero Day Bug, Pledges Patches in Days A patch for the max severity zero-day bug tracked as CVE-2023-20198 is coming soon, but the bug has already led to the compromise of tens of thousands of Cisco devices. And now, there\'s a new unpatched threat.]]> 2023-10-20T20:09:00+00:00 https://www.darkreading.com/application-security/cisco-zero-day-bug-patches-in-days www.secnews.physaphae.fr/article.php?IdArticle=8398390 False Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Ducktail Infoster, Darkgate Rat lié aux mêmes acteurs de la menace<br>Ducktail Infostealer, DarkGate RAT Linked to Same Threat Actors Vietnamese cybercrime groups are using multiple different MaaS infostealers and RATs to target the digital marketing sector.]]> 2023-10-20T18:15:00+00:00 https://www.darkreading.com/vulnerabilities-threats/ducktail-infostealer-darkgate-rat-linked-to-same-threat-actors www.secnews.physaphae.fr/article.php?IdArticle=8398360 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch 23andMe Hacker fuit une nouvelle tranche de données volées<br>23AndMe Hacker Leaks New Tranche of Stolen Data Two weeks after the first data leak from the DNA ancestry service, the threat actor produces an additional 4 million user records they purportedly stole.]]> 2023-10-19T20:45:00+00:00 https://www.darkreading.com/attacks-breaches/23andme-hacker-leaks-new-tranche-of-stolen-data- www.secnews.physaphae.fr/article.php?IdArticle=8397886 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les acteurs de l'État nord-coréen attaquent le bug critique dans TeamCity Server<br>North Korean State Actors Attack Critical Bug in TeamCity Server Known threat groups Diamond Sleet and Onyx Sleet focus on cyber espionage, data theft, network sabotage, and other malicious actions, Microsoft says.]]> 2023-10-19T20:25:00+00:00 https://www.darkreading.com/attacks-breaches/north-korean-state-actors-attack-critical-bug-in-teamcity-server www.secnews.physaphae.fr/article.php?IdArticle=8397887 False Threat None 2.0000000000000000 Dark Reading - Informationweek Branch L'opération de défense israélienne alimentée par Ai \\ 'Cyber Dome prend vie<br>AI-Powered Israeli \\'Cyber Dome\\' Defense Operation Comes to Life The Israelis are building a cyber defense system that will use ChatGPT-like generative AI platforms to parse threat intelligence.]]> 2023-10-19T17:38:00+00:00 https://www.darkreading.com/dr-global/ai-powered-israeli-cyber-dome-defense-operation-comes-to-life www.secnews.physaphae.fr/article.php?IdArticle=8397814 False Threat ChatGPT 3.0000000000000000 Dark Reading - Informationweek Branch Lié à l'Iran \\ 'Muddywater \\' espionne sur le gouvernement du Moyen-Orient \\ 't pendant 8 mois<br>Iran-Linked \\'MuddyWater\\' Spies on Mideast Gov\\'t for 8 Months The state-sponsored threat actors (aka APT34, Crambus, Helix Kitten, or OilRig) spent months seemingly taking whatever government data they wished, using never-before-seen tools.]]> 2023-10-19T14:22:00+00:00 https://www.darkreading.com/dr-global/iran-linked-muddywater-spies-middle-east-govt-eight-months www.secnews.physaphae.fr/article.php?IdArticle=8397738 False Threat APT 34 2.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: les apts continuent de frotter le bug de Winrar<br>Patch Now: APTs Continue to Pummel WinRAR Bug State-sponsored cyberespionage actors from Russia and China continue to target WinRAR users with various info-stealing and backdoor malware, as a patching lag plagues the software\'s footprint.]]> 2023-10-19T13:30:00+00:00 https://www.darkreading.com/attacks-breaches/patch-now-apts-pummel-winrar-bug www.secnews.physaphae.fr/article.php?IdArticle=8397739 False Threat,General Information None 3.0000000000000000