www.secnews.physaphae.fr This is the RSS 2.0 feed from www.secnews.physaphae.fr. IT's a simple agragated flow of multiple articles soruces. Liste of sources, can be found on www.secnews.physaphae.fr. 2024-05-08T20:11:20+00:00 www.secnews.physaphae.fr Dark Reading - Informationweek Branch Le catalogue KEV de CISA \\ accélère-t-il la correction de la remédiation?<br>Does CISA\\'s KEV Catalog Speed Up Remediation? Vulnerabilities added to the CISA known exploited vulnerability (KEV) list do indeed get patched faster, but not fast enough.]]> 2024-05-07T20:50:29+00:00 https://www.darkreading.com/vulnerabilities-threats/cisa-kev-catalog-speed-up-remediation www.secnews.physaphae.fr/article.php?IdArticle=8495461 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Milliards d'appareils Android ouverts à \\ 'stream stream \\' attaque<br>Billions of Android Devices Open to \\'Dirty Stream\\' Attack Microsoft has uncovered a common vulnerability pattern in several apps allowing code execution; at least four of the apps have more than 500 million installations each; and one, Xiaomi\'s File Manager, has at least 1 billion installations.]]> 2024-05-02T21:59:01+00:00 https://www.darkreading.com/cloud-security/billions-android-devices-open-dirty-stream-attack www.secnews.physaphae.fr/article.php?IdArticle=8492625 False Vulnerability,Mobile None 2.0000000000000000 Dark Reading - Informationweek Branch Verizon DBIR: Gaffes de sécurité de base sous-tendre la récolte exceptionnelle de violations<br>Verizon DBIR: Basic Security Gaffes Underpin Bumper Crop of Breaches MOVEit drove a big chunk of the increase, but human vulnerability to social engineering and failure to patch known bugs led to a doubling of breaches since 2023, said Verizon Business.]]> 2024-05-01T04:01:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/verizon-dbir-basic-security-gaffes-underpin-bumper-crop-of-breaches www.secnews.physaphae.fr/article.php?IdArticle=8491604 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Le bogue de programmation R expose les organisations à un vaste risque de chaîne d'approvisionnement<br>R Programming Bug Exposes Orgs to Vast Supply Chain Risk The CVE-2024-27322 security vulnerability in R\'s deserialization process gives attackers a way to execute arbitrary code in target environments via specially crafted files.]]> 2024-04-29T20:51:03+00:00 https://www.darkreading.com/application-security/r-programming-language-exposes-orgs-to-supply-chain-risk www.secnews.physaphae.fr/article.php?IdArticle=8491279 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Des milliers de serveurs Sense Qlik ouverts aux ransomwares du cactus<br>Thousands of Qlik Sense Servers Open to Cactus Ransomware The business intelligence servers contain vulnerabilities that Qlik patched last year, but which Cactus actors have been exploiting since November. Swathes of organizations have not yet been patched.]]> 2024-04-26T20:55:10+00:00 https://www.darkreading.com/cyber-risk/more-than-3-000-qlik-sense-servers-vuln-to-cactus-ransomware-attacks www.secnews.physaphae.fr/article.php?IdArticle=8489268 False Ransomware,Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Intel exploite des hackathons pour lutter contre les vulnérabilités matérielles<br>Intel Harnesses Hackathons to Tackle Hardware Vulnerabilities The semiconductor manufacturing giant\'s security team describes how hardware hackathons, such as Hack@DAC, have helped chip security by finding and sharing hardware vulnerabilities.]]> 2024-04-26T20:16:23+00:00 https://www.darkreading.com/endpoint-security/intel-harnesses-hackathons-to-tackle-hardware-vulnerabilities www.secnews.physaphae.fr/article.php?IdArticle=8489269 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Palo Alto met à jour l'assainissement du bug du pare-feu maximum<br>Palo Alto Updates Remediation for Max-Critical Firewall Bug Though PAN originally described the attacks exploiting the vulnerability as being limited, they are increasingly growing in volume, with more exploits disclosed by outside parties.]]> 2024-04-26T19:51:58+00:00 https://www.darkreading.com/vulnerabilities-threats/palo-alto-updates-remediation-for-max-critical-firewall-bug www.secnews.physaphae.fr/article.php?IdArticle=8489271 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch MANUEL DE TANK MILITAINE, ancrage zéro-jour 2017 Dernières cyberattaques ukrainiennes<br>Military Tank Manual, 2017 Zero-Day Anchor Latest Ukraine Cyberattack The targeted operation utilized CVE-2017-8570 as the initial vector and employed a notable custom loader for Cobalt Strike, yet attribution to any known threat actor remains elusive.]]> 2024-04-26T13:45:02+00:00 https://www.darkreading.com/cyberattacks-data-breaches/military-tank-manual-zero-day-ukraine-cyberattack www.secnews.physaphae.fr/article.php?IdArticle=8489087 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: Exploit de nuages de nuages Crushftp Zero-Day cible les orgs américains<br>Patch Now: CrushFTP Zero-Day Cloud Exploit Targets US Orgs An exploit for the vulnerability allows unauthenticated attackers to escape a virtual file system sandbox to download system files and potentially achieve RCE.]]> 2024-04-24T13:24:44+00:00 https://www.darkreading.com/cloud-security/patch-crushftp-zero-day-cloud-exploit-targets-us-orgs www.secnews.physaphae.fr/article.php?IdArticle=8488006 False Vulnerability,Threat,Cloud None 2.0000000000000000 Dark Reading - Informationweek Branch Siemens travaillant sur Corre<br>Siemens Working on Fix for Device Affected by Palo Alto Firewall Bug Growing attacks targeting the flaw prompted CISA to include it in the known exploited vulnerabilities catalog earlier this month.]]> 2024-04-23T20:40:36+00:00 https://www.darkreading.com/ics-ot-security/siemens-working-on-fix-for-device-affected-by-palo-alto-firewall-bug www.secnews.physaphae.fr/article.php?IdArticle=8487612 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Tenage sur le bord: VPNS, pare-feu \\ 'La télémétrie non existante attire Apts<br>Teetering on the Edge: VPNs, Firewalls\\' Nonexistent Telemetry Lures APTs State-sponsored groups are targeting critical vulnerabilities in virtual private network (VPN) gateways, firewall appliances, and other edge devices to make life difficult for incident responders, who rarely have visibility into the devices.]]> 2024-04-23T12:00:00+00:00 https://www.darkreading.com/endpoint-security/edge-vpns-firewalls-nonexistent-telemetry-apts www.secnews.physaphae.fr/article.php?IdArticle=8487357 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Le domaine Nespresso sert une tasse de phish torride, pas de crème ou de sucre<br>Nespresso Domain Serves Up Steamy Cup of Phish, No Cream or Sugar An open direct vulnerability in the Nespresso Web domain lets attackers bypass detection as they attempt to steal victims\' Microsoft credentials.]]> 2024-04-22T19:35:01+00:00 https://www.darkreading.com/cyberattacks-data-breaches/nespresso-domain-phish-cream-sugar www.secnews.physaphae.fr/article.php?IdArticle=8486986 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch GPT-4 peut exploiter la plupart des vulnes simplement en lisant les avis de menace<br>GPT-4 Can Exploit Most Vulns Just by Reading Threat Advisories Existing AI technology can allow hackers to automate exploits for public vulnerabilities in minutes flat. Very soon, diligent patching will no longer be optional.]]> 2024-04-18T20:23:46+00:00 https://www.darkreading.com/threat-intelligence/gpt-4-can-exploit-most-vulns-just-by-reading-threat-advisories www.secnews.physaphae.fr/article.php?IdArticle=8484931 False Vulnerability,Threat,Patching None 2.0000000000000000 Dark Reading - Informationweek Branch Ivanti verse des correctifs pour plus de 2 douzaines de vulnérabilités<br>Ivanti Releases Fixes for More Than 2 Dozen Vulnerabilities Users will need to download the latest version of Ivanti\'s Avalanche to apply fixes for all of the bugs.]]> 2024-04-17T18:07:07+00:00 https://www.darkreading.com/vulnerabilities-threats/ivanti-releases-fixes-for-more-than-2-dozen-vulnerabilities www.secnews.physaphae.fr/article.php?IdArticle=8484299 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Palo Alto Network émet des chaussettes pour un bug zéro-jour dans son pare-feu OS<br>Palo Alto Network Issues Hotfixes for Zero-Day Bug in Its Firewall OS A sophisticated threat actor is leveraging the bug to deploy a Python backdoor for stealing data and executing other malicious actions.]]> 2024-04-15T19:28:57+00:00 https://www.darkreading.com/cyberattacks-data-breaches/palo-alto-network-issues-hot-fixes-for-zero-day-bug-in-its-firewall-os www.secnews.physaphae.fr/article.php?IdArticle=8482930 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch LG Smart TV à risque d'attaques, grâce à 4 vulnérabilités du système d'exploitation<br>LG Smart TVs at Risk of Attacks, Thanks to 4 OS Vulnerabilities Scans showed that 91,000 devices are exposed and at risk for unauthorized access and TV set takeover.]]> 2024-04-09T20:44:38+00:00 https://www.darkreading.com/vulnerabilities-threats/researchers-discover-thousands-of-lg-smart-tvs-at-risk-of-attacks www.secnews.physaphae.fr/article.php?IdArticle=8478910 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Les bornes de recharge EV sont encore criblées de vulnérabilités de cybersécurité<br>EV Charging Stations Still Riddled With Cybersecurity Vulnerabilities As more electric vehicles are sold, the risk to compromised charging stations looms large alongside the potential for major cybersecurity exploits.]]> 2024-04-09T18:31:16+00:00 https://www.darkreading.com/ics-ot-security/ev-charging-stations-still-riddled-with-cybersecurity-vulnerabilities www.secnews.physaphae.fr/article.php?IdArticle=8478857 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Le défaut de sécurité critique expose 1 million de sites WordPress à l'injection SQL<br>Critical Security Flaw Exposes 1 Million WordPress Sites to SQL Injection A researcher received a $5,500 bug bounty for discovering a vulnerability (CVE-2024-2879) in LayerSlider, a plug-in with more than a million active installations.]]> 2024-04-04T15:15:37+00:00 https://www.darkreading.com/remote-workforce/critical-security-flaw-wordpress-sql-injection www.secnews.physaphae.fr/article.php?IdArticle=8475975 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Comment apprivoiser l'injection SQL<br>How to Tame SQL injection As part of its Secure by Design initiative, the Cybersecurity and Infrastructure Security Agency urged companies to redouble efforts to quash SQL injection vulnerabilities. Here\'s how.]]> 2024-04-03T19:58:52+00:00 https://www.darkreading.com/application-security/tools-and-techniques-to-tame-sql-injection www.secnews.physaphae.fr/article.php?IdArticle=8475869 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch NIST veut aider à sortir de son arriéré NVD<br>NIST Wants Help Digging Out of Its NVD Backlog The National Vulnerability Database can\'t keep up, and the agency is calling for a public-private partnership to manage it going forward.]]> 2024-04-02T20:54:44+00:00 https://www.darkreading.com/vulnerabilities-threats/nist-needs-help-digging-out-of-its-vulnerability-backlog www.secnews.physaphae.fr/article.php?IdArticle=8474822 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Coin Ciso: escroquerie cyber-pro;Nouveaux visages de risque;Cyber stimule l'évaluation<br>CISO Corner: Cyber-Pro Swindle; New Faces of Risk; Cyber Boosts Valuation Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps. Also included: Australia gets its cyber-groove back, and 2023\'s zero-day field day.]]> 2024-03-29T20:51:51+00:00 https://www.darkreading.com/cloud-security/ciso-corner-cyber-pro-swindle-risk-valuation www.secnews.physaphae.fr/article.php?IdArticle=8472757 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les bogues IOS de Cisco permettent des attaques DOS non authentifiées et distantes<br>Cisco IOS Bugs Allow Unauthenticated, Remote DoS Attacks Several Cisco products, including IOS, IOS XE, and AP software, need patching against various high-risk security vulnerabilities.]]> 2024-03-28T21:15:17+00:00 https://www.darkreading.com/application-security/cisco-ios-bugs-unauthenticated-remote-dos-attacks www.secnews.physaphae.fr/article.php?IdArticle=8472251 False Vulnerability,Patching None 2.0000000000000000 Dark Reading - Informationweek Branch 10 étapes pour détecter, prévenir et résoudre la vulnérabilité de la terrapine<br>10 Steps to Detect, Prevent, and Remediate the Terrapin Vulnerability You don\'t have to stop using SSH keys to stay safe. This Tech Tip explains how to protect your system against CVE-2023-48795.]]> 2024-03-27T22:25:13+00:00 https://www.darkreading.com/vulnerabilities-threats/10-steps-to-detect-prevent-and-remediate-the-terrapin-vulnerability www.secnews.physaphae.fr/article.php?IdArticle=8471993 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch La vulnérabilité pomme sans patch pomme m permet de contourner la cryptographie<br>Patchless Apple M-Chip Vulnerability Allows Cryptography Bypass The available options for addressing the flaw are limited, leaving many Macs vulnerable to a "GoFetch" attack that steals keys - even quantum-resistant ones.]]> 2024-03-27T20:06:33+00:00 https://www.darkreading.com/application-security/patchless-apple-m-chip-vulnerability-cryptography-bypass www.secnews.physaphae.fr/article.php?IdArticle=8471601 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Le bonanza zéro-jour conduit plus d'exploits contre les entreprises<br>Zero-Day Bonanza Drives More Exploits Against Enterprises Advanced adversaries are increasingly focused on enterprise technologies and their vendors, while end-user platforms are having success stifling zero-day exploits with cybersecurity investments, according to Google.]]> 2024-03-27T15:27:37+00:00 https://www.darkreading.com/threat-intelligence/zero-day-bonanza-exploits-enterprises www.secnews.physaphae.fr/article.php?IdArticle=8471451 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: bug critique de Fortinet RCE sous attaque active<br>Patch Now: Critical Fortinet RCE Bug Under Active Attack A proof-of-concept exploit released last week has spurred attacks on the vulnerability, which the CISA has flagged as an urgent patch priority.]]> 2024-03-26T15:13:15+00:00 https://www.darkreading.com/cloud-security/patch-critical-fortinet-rce-bug-active-attack www.secnews.physaphae.fr/article.php?IdArticle=8470826 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch L'équipe Tesla Hack gagne 200 000 $ et une nouvelle voiture<br>Tesla Hack Team Wins $200K and a New Car Zero Day Initiative awarded a total of $732,000 to researchers who found 19 unique cybersecurity vulnerabilities during the first day of Pwn2Own.]]> 2024-03-21T22:32:49+00:00 https://www.darkreading.com/threat-intelligence/team-s-tesla-hack-wins-them-200k-and-a-new-car www.secnews.physaphae.fr/article.php?IdArticle=8468149 False Hack,Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Un avertissement fédéral met en évidence la cyber-vulnérabilité des systèmes d'eau américains<br>Federal Warning Highlights Cyber Vulnerability of US Water Systems The White House urged operators of water and wastewater systems to review and beef up their security controls against attacks by Iran- and China-based groups.]]> 2024-03-20T21:45:25+00:00 https://www.darkreading.com/ics-ot-security/new-us-warning-highlights-vulnerability-of-us-water-systems-to-cyberattacks www.secnews.physaphae.fr/article.php?IdArticle=8467542 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'ghostrace \\' L'attaque d'exécution spéculative a un impact<br>\\'GhostRace\\' Speculative Execution Attack Impacts All CPU, OS Vendors Like Spectre, the new GhostRace exploit could give attackers a way to access sensitive information from system memory and take other malicious actions.]]> 2024-03-15T21:09:49+00:00 https://www.darkreading.com/cyber-risk/ghostrace-speculative-execution-attack-cpu-os-vendors www.secnews.physaphae.fr/article.php?IdArticle=8464559 False Vulnerability,Threat None 4.0000000000000000 Dark Reading - Informationweek Branch Windows SmartScreen Bypass Flaw exploité pour déposer Darkgate Rat<br>Windows SmartScreen Bypass Flaw Exploited to Drop DarkGate RAT Attackers use Google redirects in their phishing attack leveraging a now-patched vulnerability that spreads the multifaceted malware.]]> 2024-03-14T14:23:05+00:00 https://www.darkreading.com/endpoint-security/windows-smartscreen-bypass-flaw-exploited-to-drop-darkgate-rat www.secnews.physaphae.fr/article.php?IdArticle=8463835 False Malware,Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Claroty Team82: 63% des vulnérabilités exploitées connues suivis par CISA sont sur les réseaux d'organisation de soins de santé<br>Claroty Team82: 63% of Known Exploited Vulnerabilities Tracked by CISA Are on Healthcare Organization Networks 2024-03-13T23:16:34+00:00 https://www.darkreading.com/ics-ot-security/claroty-team-82-63-of-known-exploited-vulnerabilities-tracked-by-cisa-are-on-healthcare-organization-networks www.secnews.physaphae.fr/article.php?IdArticle=8463462 False Vulnerability,Medical None 2.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: Kubernetes RCE Flaw permet une prise de contrôle complète des nœuds Windows<br>Patch Now: Kubernetes RCE Flaw Allows Full Takeover of Windows Nodes Attackers can remotely execute code with system privileges by exploiting a vulnerability in the source code of the open source container management system.]]> 2024-03-13T17:13:35+00:00 https://www.darkreading.com/cloud-security/patch-now-kubernetes-flaw-allows-for-full-takeover-of-windows-nodes www.secnews.physaphae.fr/article.php?IdArticle=8463320 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Les vulnérabilités du plugin Critical Chatgpt exposent des données sensibles<br>Critical ChatGPT Plugin Vulnerabilities Expose Sensitive Data The vulnerabilities found in ChatGPT plugins - since remediated - heighten the risk of proprietary information being stolen and the threat of account takeover attacks.]]> 2024-03-13T12:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/critical-chatgpt-plugin-vulnerabilities-expose-sensitive-data www.secnews.physaphae.fr/article.php?IdArticle=8463142 False Vulnerability,Threat ChatGPT 2.0000000000000000 Dark Reading - Informationweek Branch \\ 'aimant gobelin \\' exploite Ivanti Bug 1 jour en quelques heures<br>\\'Magnet Goblin\\' Exploits Ivanti 1-Day Bug in Mere Hours A prolific but previously hidden threat actor turns public vulnerabilities into working exploits before companies have time to patch.]]> 2024-03-12T20:00:35+00:00 https://www.darkreading.com/threat-intelligence/magnet-goblin-exploits-ivanti-1-day-bug-mere-hours www.secnews.physaphae.fr/article.php?IdArticle=8462802 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch La lutte en cours pour protéger les PLC<br>The Ongoing Struggle to Protect PLCs A decade after Stuxnet, vulnerabilities in OT systems and programmable logic controllers remain exposed.]]> 2024-03-08T15:00:00+00:00 https://www.darkreading.com/ics-ot-security/ongoing-struggle-to-protect-plcs www.secnews.physaphae.fr/article.php?IdArticle=8460849 False Vulnerability,Industrial None 3.0000000000000000 Dark Reading - Informationweek Branch JetBrains TeamCity Mass Exploitation en cours, les comptes voyous prospèrent<br>JetBrains TeamCity Mass Exploitation Underway, Rogue Accounts Thrive Just one day after disclosure, adversaries began targeting the vulnerabilities to take complete control of affected instances of the popular developer platform.]]> 2024-03-07T22:51:32+00:00 https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive www.secnews.physaphae.fr/article.php?IdArticle=8460536 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: Apple Zero-Day Exploits contourner la sécurité du noyau<br>Patch Now: Apple Zero-Day Exploits Bypass Kernel Security A pair of critical bugs could open the door to complete system compromise, including access to location information, iPhone camera and mic, and messages. Rootkitted attackers could theoretically perform lateral movement to corporate networks, too.]]> 2024-03-06T19:15:07+00:00 https://www.darkreading.com/ics-ot-security/patch-now-apple-zero-day-exploits-bypass-kernel-security www.secnews.physaphae.fr/article.php?IdArticle=8459979 False Vulnerability,Threat,Mobile None 3.0000000000000000 Dark Reading - Informationweek Branch Critical TeamCity Bugs met en danger la chaîne d'approvisionnement des logiciels<br>Critical TeamCity Bugs Endanger Software Supply Chain Customers should immediately patch critical vulnerabilities in on-prem deployments of the CI/CD pipeline tool JetBrains TeamCity that could allow threat actors to gain admin control over servers.]]> 2024-03-04T23:05:43+00:00 https://www.darkreading.com/application-security/critical-teamcity-bugs-endanger-software-supply-chain www.secnews.physaphae.fr/article.php?IdArticle=8459026 False Tool,Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les applications cloud plaident pour la pentisting en tant que service<br>Cloud Apps Make the Case for Pentesting-as-a-Service Applications are increasingly distributed, expanding companies\' cloud attack surfaces, and requiring regular testing to find and fix vulnerabilities - else companies risk a growing sprawl of services.]]> 2024-02-29T20:48:36+00:00 https://www.darkreading.com/application-security/pentesting-as-a-service-cloud-applications www.secnews.physaphae.fr/article.php?IdArticle=8457256 False Vulnerability,Cloud None 3.0000000000000000 Dark Reading - Informationweek Branch MTTR: La métrique de sécurité la plus importante<br>MTTR: The Most Important Security Metric Measuring and tracking your mean time to remediate shows whether vulnerability management is reducing risk and closing opportunities for adversaries.]]> 2024-02-29T15:00:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/mttr-most-important-security-metric www.secnews.physaphae.fr/article.php?IdArticle=8457001 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch 4 façons dont les organisations peuvent stimuler la demande de formation de sécurité des logiciels<br>4 Ways Organizations Can Drive Demand for Software Security Training Developer-driven security programs place the development team at the center of reducing vulnerabilities.]]> 2024-02-27T18:00:00+00:00 https://www.darkreading.com/cybersecurity-operations/4-ways-organizations-drive-demand-for-software-security-training www.secnews.physaphae.fr/article.php?IdArticle=8455990 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch La Maison Blanche exhorte le passage aux langues sûres de la mémoire<br>White House Urges Switching to Memory Safe Languages The Office of the National Cyber Director technical report focuses on reducing memory-safety vulnerabilities in applications and making it harder for malicious actors to exploit them.]]> 2024-02-27T00:12:58+00:00 https://www.darkreading.com/application-security/white-house-switch-memory-safe-languages www.secnews.physaphae.fr/article.php?IdArticle=8455963 False Vulnerability,Threat,Technical None 2.0000000000000000 Dark Reading - Informationweek Branch La vulnérabilité des raccourcis Apple zéro cliquez sur un vol de données silencieux<br>Zero-Click Apple Shortcuts Vulnerability Allows Silent Data Theft Vulnerability CVE-2024-23204, affecting Apple\'s popular Shortcuts app, suggests a critical need for ongoing security awareness in the macOS and iOS ecosystem.]]> 2024-02-22T20:39:07+00:00 https://www.darkreading.com/application-security/zero-click-apple-shortcuts-vulnerability-allows-silent-data-theft www.secnews.physaphae.fr/article.php?IdArticle=8453834 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch La vulnérabilité critique dans le plug-in VMware vSphere permet un détournement de session<br>Critical Vulnerability in VMware vSphere Plug-in Allows Session Hijacking Admins are urged to remove vSphere\'s vulnerable Enhanced Authentication Plug-in, which was discontinued nearly three years ago but is still widely in use.]]> 2024-02-21T15:22:14+00:00 https://www.darkreading.com/application-security/critical-vulnerability-vmware-vsphere-plugin-session-hijacking www.secnews.physaphae.fr/article.php?IdArticle=8453255 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'keytrap \\' dns bogue menace des pannes Internet généralisées<br>\\'KeyTrap\\' DNS Bug Threatens Widespread Internet Outages Thanks to a 24-year-old security vulnerability tracked as CVE-2023-50387, attackers could stall DNS servers with just a single malicious packet, effectively taking out wide swaths of the Internet.]]> 2024-02-20T18:16:24+00:00 https://www.darkreading.com/cloud-security/keytrap-dns-bug-threatens-widespread-internet-outages www.secnews.physaphae.fr/article.php?IdArticle=8452837 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Les applications Salesforce personnalisées à tort erronées exposent les données de l'entreprise<br>Misconfigured Custom Salesforce Apps Expose Corporate Data Enterprises typically use the Java-like programming language to customize their Salesforce instances, but attackers are hunting for vulnerabilities in the apps.]]> 2024-02-20T14:00:00+00:00 https://www.darkreading.com/cloud-security/misconfigurated-custom-salesforce-apps-expose-corporate-data www.secnews.physaphae.fr/article.php?IdArticle=8452725 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les correctifs générés par l'IA pourraient faciliter le développeur, la charge de travail des opérations<br>AI-Generated Patches Could Ease Developer, Operations Workload Using information from a common technique for finding vulnerabilities, Google\'s Gemini can currently produce patches for 15% of such bugs. And it\'s not the only way to help automate bug fixing.]]> 2024-02-15T22:57:53+00:00 https://www.darkreading.com/application-security/ai-patch-ease-developer-operations-workload www.secnews.physaphae.fr/article.php?IdArticle=8453049 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Les vulnérabilités de logiciels critiques ayant un impact sur les coopératives de crédit découvertes par le chercheur en sécurité LMG<br>Critical Software Vulnerabilities Impacting Credit Unions Discovered by LMG Security Researcher 2024-02-15T21:33:39+00:00 https://www.darkreading.com/cloud-security/critical-software-vulnerabilities-impacting-credit-unions-discovered-by-lmg-security-researcher www.secnews.physaphae.fr/article.php?IdArticle=8450579 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Flaw Microsoft Exchange Server exploité comme un bogue zéro jour<br>Microsoft Exchange Server Flaw Exploited as a Zero-Day Bug Microsoft has observed signs of active exploits targeting CVE-2024-2140.]]> 2024-02-15T21:30:32+00:00 https://www.darkreading.com/cyberattacks-data-breaches/microsoft-exchange-server-flaw-exploited-zero-day-bug www.secnews.physaphae.fr/article.php?IdArticle=8450580 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les attaquants exploitent Microsoft Security-Bypass Zero-Day Bogs<br>Attackers Exploit Microsoft Security-Bypass Zero-Day Bugs The Water Hydra cyberattacker group is one adversary using the zero-days to get past built-in Windows protections.]]> 2024-02-13T22:26:26+00:00 https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-microsoft-security-bypass-zero-day-bugs www.secnews.physaphae.fr/article.php?IdArticle=8449759 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Flaw ivanti VPN exploité pour injecter une nouvelle porte dérobée;Des centaines de pwned<br>Ivanti VPN Flaw Exploited to Inject Novel Backdoor; Hundreds Pwned A SAML vulnerability in Ivanti appliances has led to persistent remote access and full control for opportunistic cyberattackers.]]> 2024-02-13T20:44:32+00:00 https://www.darkreading.com/cloud-security/ivanti-flaw-exploited-inject-novel-backdoor www.secnews.physaphae.fr/article.php?IdArticle=8449718 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Fortinet, Ivanti occupe les clients avec des bugs encore plus critiques<br>Fortinet, Ivanti Keep Customers Busy With Yet More Critical Bugs Brand-new vulnerabilities from both vendors this week - one exploited in the wild - add to a steady stream of critical security issues in the security platforms.]]> 2024-02-12T14:00:00+00:00 https://www.darkreading.com/cloud-security/fortinet-ivanti-keep-customers-busy-with-yet-more-critical-bugs www.secnews.physaphae.fr/article.php?IdArticle=8449260 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Les réseaux IoT sont confrontés à des adversaires avancés, à Bug Barrage<br>IoT Networks Face Advancing Adversaries, Bug Barrage Cyberattacks on critical infrastructure targeting IoT and OS networks are increasing in sophistication, while ICS vulnerabilities surge, new data shows.]]> 2024-02-08T13:00:00+00:00 https://www.darkreading.com/iot/iot-networks-face-bug-barrage-advancing-adversaries www.secnews.physaphae.fr/article.php?IdArticle=8448001 False Vulnerability,Industrial None 2.0000000000000000 Dark Reading - Informationweek Branch Distros Linux frappés par la vulnérabilité RCE dans la cale de démarrage<br>Linux Distros Hit By RCE Vulnerability in Shim Bootloader However, not everyone agrees with the NVD\'s assessment of CVE-2023-40547 being a near-maximum severity bug.]]> 2024-02-07T22:17:19+00:00 https://www.darkreading.com/vulnerabilities-threats/rce-vulnerability-in-shim-bootloader-impacts-all-linux-distros www.secnews.physaphae.fr/article.php?IdArticle=8447817 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: le bogue Critical TeamCity permet les prises de contrôle du serveur<br>Patch Now: Critical TeamCity Bug Allows for Server Takeovers Cyberattackers can exploit a vulnerability in JetBrain\'s continuous integration and delivery (CI/CD) server (a popular APT target) to gain administrative control.]]> 2024-02-07T18:17:02+00:00 https://www.darkreading.com/vulnerabilities-threats/patch-critical-teamcity-bug-server-takeover www.secnews.physaphae.fr/article.php?IdArticle=8447759 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les bogues critiques dans les petites imprimantes de bureau canon permettent l'exécution du code, DDOS<br>Critical Bugs in Canon Small Office Printers Allow Code Execution, DDoS A grouping of serious printer bugs, unveiled at last summer\'s Pwn2Own, were patchless for months, but are finally fixed now.]]> 2024-02-06T22:41:20+00:00 https://www.darkreading.com/endpoint-security/critical-bugs-canon-small-office-printers-code-execution-ddos www.secnews.physaphae.fr/article.php?IdArticle=8447443 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Les bogues de la sévérité max de jumeaux ouvrent Siem de Fortinet \\ à l'exécution du code<br>Twin Max-Severity Bugs Open Fortinet\\'s SIEM to Code Execution Full 10s on the CVSS vulnerability severity scale have been assigned to two flaws discovered in Fortinet\'s FortiSIEM cybersecurity operations platform.]]> 2024-02-06T20:02:40+00:00 https://www.darkreading.com/vulnerabilities-threats/fortinet-fortisiem-hit-with-twin-max-severity-bugs www.secnews.physaphae.fr/article.php?IdArticle=8447395 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Google: les gouvernements stimulent une forte croissance des logiciels espions commerciaux<br>Google: Govs Drive Sharp Growth of Commercial Spyware Cos Private spyware vendors were behind nearly half of all zero-day exploits in Google products since 2014.]]> 2024-02-06T10:00:00+00:00 https://www.darkreading.com/threat-intelligence/govts-are-driving-sharp-growth-in-commercial-spyware-industry-google-warns www.secnews.physaphae.fr/article.php?IdArticle=8447205 False Vulnerability,Threat,Commercial None 2.0000000000000000 Dark Reading - Informationweek Branch Google Open Sources Frazing Fuzzing Ai-boosted<br>Google Open Sources AI-Boosted Fuzzing Framework The fuzzing framework uses AI to boost code coverage and to speed up vulnerability discovery.]]> 2024-02-05T18:00:00+00:00 https://www.darkreading.com/application-security/google-open-sources-ai-boosted-fuzzing-framework www.secnews.physaphae.fr/article.php?IdArticle=8447278 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch FritzFrog Botnet exploite log4shell sur les hôtes internes négligés<br>FritzFrog Botnet Exploits Log4Shell on Overlooked Internal Hosts Everyone knows to patch vulnerabilities for Internet-facing assets, but what about internal ones? One botnet is counting on your complacency.]]> 2024-02-01T19:39:00+00:00 https://www.darkreading.com/threat-intelligence/fritzfrog-botnet-exploits-log4shell-overlooked-internal-hosts www.secnews.physaphae.fr/article.php?IdArticle=8445689 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'navires qui fuisent \\' Les bogues cloud autorisent les évasions du conteneur à l'échelle mondiale<br>\\'Leaky Vessels\\' Cloud Bugs Allow Container Escapes Globally The four security vulnerabilities are found in Docker and beyond, and one affecting runC affects essentially every cloud-native developer worldwide.]]> 2024-01-31T22:00:00+00:00 https://www.darkreading.com/cloud-security/leaky-vessel-cloud-bugs-container-escapes-globally www.secnews.physaphae.fr/article.php?IdArticle=8445347 False Vulnerability,Cloud None 3.0000000000000000 Dark Reading - Informationweek Branch Les correctifs Ivanti Zero-Day sont retardés comme \\ 'Krustyloader \\' Attacks Mount<br>Ivanti Zero-Day Patches Delayed as \\'KrustyLoader\\' Attacks Mount The RCE/auth bypass bugs in Connect Secure VPNs have gone unpatched for 20 days as state-sponsored groups continue to backdoor Ivanti gear.]]> 2024-01-30T23:22:00+00:00 https://www.darkreading.com/endpoint-security/ivanti-zero-day-patches-delayed-krustyloader-attacks-mount www.secnews.physaphae.fr/article.php?IdArticle=8444979 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Cisco Unified Communications RCE Bug permet un accès root<br>Critical Cisco Unified Communications RCE Bug Allows Root Access The vulnerability, tracked as CVE-2024-20253, makes enterprise communications infrastructure and customer service call centers sitting ducks for unauthenticated cyberattackers.]]> 2024-01-25T17:46:00+00:00 https://www.darkreading.com/remote-workforce/critical-cisco-unified-communications-rce-bug-root-access www.secnews.physaphae.fr/article.php?IdArticle=8443068 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Quelques jours après Google, Apple révèle que le moteur du navigateur a exploité le moteur de navigateur<br>Days After Google, Apple Reveals Exploited Zero-Day in Browser Engine The new bug is Apple\'s 12th WebKit zero-day in the last year, highlighting the increasing enterprise exposure to browser-borne threats.]]> 2024-01-23T23:30:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/days-after-google-apple-discloses-actively-exploited-0-day-in-its-browser-engine www.secnews.physaphae.fr/article.php?IdArticle=8442318 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les espions chinois ont exploité le bug de VMware critique pendant près de 2 ans<br>Chinese Spies Exploited Critical VMware Bug for Nearly 2 Years Even the most careful VMware customers may need to go back and double check that they weren\'t compromised by a zero-day exploit for CVE-2023-34048.]]> 2024-01-22T22:08:00+00:00 https://www.darkreading.com/endpoint-security/chinese-spies-exploited-critical-vmware-bug-2-years www.secnews.physaphae.fr/article.php?IdArticle=8441859 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Troisième vulnérabilité ivanti exploitée dans la nature, rapporte CISA<br>Third Ivanti Vulnerability Exploited in the Wild, CISA Reports Though reports say this latest Ivanti bug is being exploited, it\'s unclear exactly how threat actors are using it.]]> 2024-01-19T19:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/third-ivanti-vulnerability-exploited-in-the-wild-cisa-reports www.secnews.physaphae.fr/article.php?IdArticle=8440748 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Citrix découvre 2 vulnérabilités, toutes deux exploitées dans la nature<br>Citrix Discovers 2 Vulnerabilities, Both Exploited in the Wild These vulnerabilities are the second and third for Citrix but are not expected to be as detrimental as "CitrixBleed."]]> 2024-01-18T22:30:00+00:00 https://www.darkreading.com/vulnerabilities-threats/citrix-discovers-two-vulnerabilities-both-exploited-in-the-wild www.secnews.physaphae.fr/article.php?IdArticle=8440444 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Google Chrome Zero-Day Bug attaqué, permet l'injection de code<br>Google Chrome Zero-Day Bug Under Attack, Allows Code Injection The first Chrome zero-day bug of 2024 adds to a growing list of actively exploited vulnerabilities found in Chromium and other browser technologies.]]> 2024-01-17T21:15:00+00:00 https://www.darkreading.com/cloud-security/google-chrome-zero-day-bug-attack-code-injection www.secnews.physaphae.fr/article.php?IdArticle=8440044 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Les exploits d'Ivanti Zero-Day montent en flèche dans le monde;Pas encore de correctifs<br>Ivanti Zero-Day Exploits Skyrocket Worldwide; No Patches Yet Anyone who hasn\'t mitigated two zero-day security bugs in Ivanti VPNs may already be compromised by a Chinese nation-state actor.]]> 2024-01-16T21:25:00+00:00 https://www.darkreading.com/cloud-security/ivanti-zero-day-exploits-skyrocket-no-patches www.secnews.physaphae.fr/article.php?IdArticle=8439675 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Le thermostat Smart Bosch ressent la chaleur du bug du micrologiciel<br>Bosch Smart Thermostat Feels the Heat From Firmware Bug The vulnerability in a popular hospitality industry gadget allows attackers to take over the device, pivot into the user\'s network, or brick the device entirely, rendering HVAC unusable.]]> 2024-01-16T19:55:00+00:00 https://www.darkreading.com/ics-ot-security/bosch-smart-thermostat-firmware-bug www.secnews.physaphae.fr/article.php?IdArticle=8439650 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch CISA ajoute 9.8 \\ 'Critical \\' Microsoft SharePoint Bug à son catalogue KEV<br>CISA Adds 9.8 \\'Critical\\' Microsoft SharePoint Bug to its KEV Catalog It\'s a tale as old as time: an old, long-since patched vulnerability that remains actively exploited.]]> 2024-01-12T22:32:00+00:00 https://www.darkreading.com/vulnerabilities-threats/cisa-adds-critical-microsoft-sharepoint-bug-kev-catalog www.secnews.physaphae.fr/article.php?IdArticle=8438418 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch GitLab publie des mises à jour pour aborder les vulnérabilités critiques<br>GitLab Releases Updates to Address Critical Vulnerabilities Two vulnerabilities are critical, and three others are determined to be of high, medium, and low severity.]]> 2024-01-12T22:30:00+00:00 https://www.darkreading.com/vulnerabilities-threats/gitlab-releases-updates-to-address-critical-vulnerabilities- www.secnews.physaphae.fr/article.php?IdArticle=8438419 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Les chercheurs de l'Ivanti signalent deux vulnérabilités critiques à jour zéro<br>Ivanti Researchers Report Two Critical Zero-Day Vulnerabilities Patches will be available in late January and February, but until then, customers must take mitigation measures.]]> 2024-01-11T21:43:00+00:00 https://www.darkreading.com/vulnerabilities-threats/ivanti-researchers-report-of-two-critical-zero-day-vulnerabilities www.secnews.physaphae.fr/article.php?IdArticle=8438016 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: le bogue Critical Windows Kerberos contourne Microsoft Security<br>Patch Now: Critical Windows Kerberos Bug Bypasses Microsoft Security A second, easy-to-exploit critical security vulnerability in Microsoft\'s first 2024 Patch Tuesday allows RCE within Hyper-Virtualization.]]> 2024-01-09T23:00:00+00:00 https://www.darkreading.com/ics-ot-security/critical-windows-kerberos-bug-microsoft-security-bypass www.secnews.physaphae.fr/article.php?IdArticle=8437327 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Outil de surveillance des cactus enrichi par une vulnérabilité critique d'injection SQL<br>Cacti Monitoring Tool Spiked by Critical SQL Injection Vulnerability Attackers can exploit the issue to access all data in Cacti database; and, it enables RCE when chained with a previous vulnerability.]]> 2024-01-08T23:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/cacti-monitoring-tool-critical-sql-injection-vulnerability www.secnews.physaphae.fr/article.php?IdArticle=8436853 False Tool,Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Signal de risque de défenseur industriel, une solution de gestion de vulnérabilité basée sur les risques pour la sécurité OT<br>Industrial Defender Risk Signal, a Risk-Based Vulnerability Management Solution for OT Security 2024-01-04T22:24:00+00:00 https://www.darkreading.com/ics-ot-security/industrial-defender-risk-signal-an-intelligent-risk-based-vulnerability-management-solution-for-ot-security www.secnews.physaphae.fr/article.php?IdArticle=8434717 True Vulnerability,Industrial None 3.0000000000000000 Dark Reading - Informationweek Branch Apache Erp Zero-Day souligne les dangers des correctifs incomplets<br>Apache ERP Zero-Day Underscores Dangers of Incomplete Patches Apache fixed a vulnerability in its OfBiz enterprise resource planning (ERP) framework last month, but attackers and researchers found a way around the patch.]]> 2024-01-03T21:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/apache-erp-0day-underscores-dangers-of-incomplete-patches www.secnews.physaphae.fr/article.php?IdArticle=8434658 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Google libère le huitième patch zéro-jour de 2023 pour Chrome<br>Google Releases Eighth Zero-Day Patch of 2023 for Chrome CVE-2023-7024, exploited in the wild prior to patching, is a Chrome vulnerability that allows remote code execution within the browser\'s WebRTC component.]]> 2023-12-22T18:00:00+00:00 https://www.darkreading.com/cloud-security/google-eighth-zero-day-patch-2023-chrome www.secnews.physaphae.fr/article.php?IdArticle=8427494 False Vulnerability,Threat,Patching None 3.0000000000000000 Dark Reading - Informationweek Branch Vulnérabilité F5 ciblée \\ 'mise à jour \\' délivre des essuie-glaces aux victimes israéliennes<br>Targeted F5 Vulnerability \\'Update\\' Delivers Wiper to Israeli Victims Files purporting to be an F5 vulnerability patch are deleting server contents.]]> 2023-12-20T15:00:00+00:00 https://www.darkreading.com/cyberattacks-data-breaches/targeted-f5-vulnerability-update-delivers-wiper-israeli-victims www.secnews.physaphae.fr/article.php?IdArticle=8426183 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch BugCrowd annonce des cotes de vulnérabilité pour les LLM<br>Bugcrowd Announces Vulnerability Ratings for LLMs The update to the company\'s Vulnerability Rating Taxonomy offers vulnerability researchers a framework for assessing and prioritizing vulnerabilities in large language models.]]> 2023-12-20T02:00:00+00:00 https://www.darkreading.com/application-security/bugcrowd-announces-vulnerability-ratings-for-llms www.secnews.physaphae.fr/article.php?IdArticle=8426117 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Flaws de sécurité Microsoft Outlook Zero-Click déclenché par un fichier son<br>Microsoft Outlook Zero-Click Security Flaws Triggered by Sound File Attackers can chain the vulnerabilities to gain full remote code execution.]]> 2023-12-19T20:55:00+00:00 https://www.darkreading.com/vulnerabilities-threats/researchers-release-details-on-two-patched-outlook-zero-click-flaws www.secnews.physaphae.fr/article.php?IdArticle=8425663 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch La mise en place d'une valeur en dollars sur les vulnérabilités aidera-t-elle à les prioriser?<br>Will Putting a Dollar Value on Vulnerabilities Help Prioritize Them? Zoom\'s Vulnerability Impact Scoring System calculates the impact of a vulnerability to assign a cash payout for bugs, leading hackers to prioritize more severe flaws. Can it do the same for companies?]]> 2023-12-18T19:00:00+00:00 https://www.darkreading.com/application-security/putting-dollar-value-vulnerabilities-prioritize www.secnews.physaphae.fr/article.php?IdArticle=8424994 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Établir des critères de récompense pour la déclaration des bogues dans les produits de l'IA<br>Establishing Reward Criteria for Reporting Bugs in AI Products Bug hunter programs can help organizations foster third-party discovery and reporting of issues and vulnerabilities specific to AI systems.]]> 2023-12-15T19:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/establishing-reward-criteria-for-reporting-bugs-in-ai-products www.secnews.physaphae.fr/article.php?IdArticle=8423441 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Le système de notation des insectes de Zoom \\ priorise les vulnes les plus risquées pour les cyber équipes<br>Zoom\\'s Bug-Scoring System Prioritizes Riskiest Vulns for Cyber Teams New vulnerability impact scoring system aims to help cyber defenders find threats and patch against bugs most likely to disrupt their environments.]]> 2023-12-14T14:00:00+00:00 https://www.darkreading.com/cybersecurity-analytics/zoom-bug-scoring-system-prioritizes-riskiest-vulns www.secnews.physaphae.fr/article.php?IdArticle=8422639 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Microsoft donne aux administrateurs un sursis avec une mise à jour de correctif plus légère que d'habitude<br>Microsoft Gives Admins a Reprieve With Lighter-Than-Usual Patch Update The company\'s final patch release for 2023 contained fixes for a total of just 36 vulnerabilities - none of which, for a change, were zero-days.]]> 2023-12-12T23:14:00+00:00 https://www.darkreading.com/vulnerabilities-threats/microsoft-gives-admins-a-reprieve-with-lighter-than-usual-patch-update www.secnews.physaphae.fr/article.php?IdArticle=8421763 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Fortress Information Security & CodeSecure Team pour analyser SBOMS et résoudre les vulnérabilités critiques<br>Fortress Information Security & CodeSecure Team Up to Analyze SBOMs & Remediate Critical Vulnerabilities Partnership expands comprehensive approach to software supply chain security.]]> 2023-12-11T22:00:00+00:00 https://www.darkreading.com/application-security/fortress-information-security-codesecure-team-up-to-analyze-sboms-remediate-critical-vulnerabilities www.secnews.physaphae.fr/article.php?IdArticle=8421238 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Le groupe Lazarus est toujours à la main Log4Shell, en utilisant des rats écrits en \\ 'd \\'<br>Lazarus Group Is Still Juicing Log4Shell, Using RATs Written in \\'D\\' The infamous vulnerability may be on the older side at this point, but North Korea\'s primo APT Lazarus is creating new, unique malware around it at a remarkable clip.]]> 2023-12-11T16:15:00+00:00 https://www.darkreading.com/threat-intelligence/lazarus-group-still-juicing-log4shell-rats-written-d www.secnews.physaphae.fr/article.php?IdArticle=8421118 False Malware,Vulnerability APT 38 2.0000000000000000 Dark Reading - Informationweek Branch Russian Espionage Group Hammers zéro cliquez sur Microsoft Outlook Bug<br>Russian Espionage Group Hammers Zero-Click Microsoft Outlook Bug State-sponsored actors continue to exploit CVE-2023-23397, a dangerous no-interaction vulnerability in Microsoft\'s Outlook email client that was patched in March, in a widespread global campaign.]]> 2023-12-08T15:00:00+00:00 https://www.darkreading.com/ics-ot-security/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug www.secnews.physaphae.fr/article.php?IdArticle=8420259 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: les bogues Atlassian critiques mettent en danger les applications d'entreprise<br>Patch Now: Critical Atlassian Bugs Endanger Enterprise Apps Four RCE vulnerabilities in Confluence, Jira, and other platforms, allow instance takeover and environment infestation.]]> 2023-12-06T22:56:00+00:00 https://www.darkreading.com/application-security/patch-now-critical-atlassian-bugs-endanger-enterprise-apps www.secnews.physaphae.fr/article.php?IdArticle=8419700 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Google corrige un autre chrome zéro-jour à mesure que les attaques du navigateur montent<br>Google Patches Another Chrome Zero-Day as Browser Attacks Mount The vulnerability is among a rapidly growing number of zero-day bugs that major browser vendors have reported recently.]]> 2023-11-29T20:15:00+00:00 https://www.darkreading.com/vulnerabilities-threats/google-patches-another-chrome-zero-day-as-browser-attacks-mount www.secnews.physaphae.fr/article.php?IdArticle=8417898 False Vulnerability,Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Patch maintenant: les attaquants frappent la faille Owncloud critique et facile à exploiter<br>Patch Now: Attackers Pummel Critical, Easy-to-Exploit OwnCloud Flaw A vulnerability in the file server and collaboration platform earned a 10 in severity on the CVSS, allowing access to admin passwords, mail server credentials, and license keys.]]> 2023-11-29T19:31:00+00:00 https://www.darkreading.com/cloud-security/patch-now-attackers-pummel-critical-easy-to-exploit-owncloud-flaw www.secnews.physaphae.fr/article.php?IdArticle=8417883 False Vulnerability,Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Vulns critiques trouvés dans le cadre open source Ray pour les charges de travail AI / ML<br>Critical Vulns Found in Ray Open Source Framework for AI/ML Workloads Anyscale has dismissed the vulnerabilities as non-issues, according to researchers who reported the bugs to the company.]]> 2023-11-28T21:55:00+00:00 https://www.darkreading.com/vulnerabilities-threats/researchers-discover-trio-of-critical-vulns-in-ray-open-source-framework-for-scaling-ai-ml-workloads www.secnews.physaphae.fr/article.php?IdArticle=8417636 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch Les chercheurs affirment que la conception a une faille dans Google Workspace met les organisations en danger<br>Researchers Claim Design Flaw in Google Workspace Puts Organizations at Risk Google says the issue has to do with organizations ensuring they implement least-privilege principles.]]> 2023-11-28T15:05:00+00:00 https://www.darkreading.com/cloud-security/vendor-claims-design-flaw-in-google-workspace-is-putting-organizations-at-risk www.secnews.physaphae.fr/article.php?IdArticle=8417532 False Vulnerability None 2.0000000000000000 Dark Reading - Informationweek Branch AutoZone Files Moveit Data Breach Avis avec l'état du Maine<br>AutoZone Files MOVEit Data Breach Notice With State of Maine The company temporarily disabled the application and patched the vulnerability, though affected individuals should still remain vigilant.]]> 2023-11-21T21:35:00+00:00 https://www.darkreading.com/attacks-breaches/autozone-moveit-data-breach-state-of-maine www.secnews.physaphae.fr/article.php?IdArticle=8415586 False Data Breach,Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Exploit for Critical Windows Defender Bypass Goes Public Threat actors were actively exploiting CVE-2023-36025 in Windows SmartScreen as a zero-day vulnerability before Microsoft patched it in November.]]> 2023-11-21T21:29:00+00:00 https://www.darkreading.com/vulnerabilities-threats/exploit-for-critical-windows-defender-bypass-goes-public www.secnews.physaphae.fr/article.php?IdArticle=8417434 False Vulnerability,Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch Exploiter pour le pontage critique de Windows Defender devient public<br>Exploit for Critical Windows Defender Bypass Goes Public Threat actors were actively exploiting CVE-2023-36025 in Windows SmartScreen as a zero-day vulnerability before Microsoft patched it in November.]]> 2023-11-21T21:29:00+00:00 https://www.darkreading.com/vulnerabilities-threats/exploit-critical-windows-defender-bypass-public www.secnews.physaphae.fr/article.php?IdArticle=8415587 False Vulnerability,Threat None 2.0000000000000000 Dark Reading - Informationweek Branch Les vulnérabilités exploitées peuvent prendre des mois pour faire la liste KEV<br>Exploited Vulnerabilities Can Take Months to Make KEV List The Known Exploited Vulnerabilities (KEV) catalog is a high-quality source of information on software flaws being exploited in the wild, but updates are often delayed, so companies need other sources of threat intelligence.]]> 2023-11-20T19:16:03+00:00 https://www.darkreading.com/edge/exploited-vulnerabilities-take-months-to-make-kev-list www.secnews.physaphae.fr/article.php?IdArticle=8415098 False Vulnerability,Threat None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'Cachewarp \\' AMD VM Bug ouvre la porte à l'escalade des privilèges<br>\\'CacheWarp\\' AMD VM Bug Opens the Door to Privilege Escalation Academics in Germany figured out how to reverse time in AMD virtualization environments, then reap the spoils.]]> 2023-11-16T21:00:00+00:00 https://www.darkreading.com/vulnerabilities-threats/cachewarp-amd-vm-bug-opens-door-to-privilege-escalation www.secnews.physaphae.fr/article.php?IdArticle=8413060 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch Les vulnérabilités critiques non corrigées ouvrent les modèles d'IA à la prise de contrôle<br>Unpatched Critical Vulnerabilities Open AI Models to Takeover The security holes can allow server takeover, information theft, model poisoning, and more.]]> 2023-11-16T17:47:00+00:00 https://www.darkreading.com/vulnerabilities-threats/unpatched-critical-vulnerabilities-ai-models-takeover www.secnews.physaphae.fr/article.php?IdArticle=8412993 False Vulnerability None 3.0000000000000000 Dark Reading - Informationweek Branch \\ 'Randstorm \\' Bug: des millions de portefeuilles crypto ouverts au vol<br>\\'Randstorm\\' Bug: Millions of Crypto Wallets Open to Theft The security vulnerability in a component of a widely used JavaScript implementation of Bitcoin makes passwords guessable via brute-force attacks.]]> 2023-11-16T17:40:00+00:00 https://www.darkreading.com/application-security/randstorm-bug-crypto-wallets-theft www.secnews.physaphae.fr/article.php?IdArticle=8412994 False Vulnerability None 3.0000000000000000