Mensuel Shaarli

Tous les liens d'un mois sur une page.

June, 2023

La Commission européenne publie sa proposition pour la 3e Directive sur les services de paiement (DSP3)
Hackers infect Linux SSH servers with Tsunami botnet malware
thumbnail

An unknown threat actor is brute-forcing Linux SSH servers to install a wide range of malware, including the Tsunami DDoS (distributed denial of service) bot, ShellBot, log cleaners, privilege escalation tools, and an XMRig (Monero) coin miner.

Zero-Day Alert: Apple Releases Patches for Actively Exploited Flaws in iOS, macOS, and Safari
thumbnail
ASUS urges customers to patch critical router vulnerabilities
thumbnail

ASUS has released new firmware with cumulative security updates that address vulnerabilities in multiple router models, warning customers to immediately update their devices or restrict WAN access until they're secured.

Microsoft says early June disruptions to Outlook, cloud platform, were cyberattacks
thumbnail

Microsoft has now disclosed that DDoS attacks by a murky upstart were to blame for serious service disruptions back in early June.

Third Flaw Uncovered in MOVEit Transfer App Amidst Cl0p Ransomware Mass Attack
thumbnail

🚨 Alert: Progress Software has disclosed a 3rd critical flaw in MOVEit Transfer app—an SQL injection—allowing unauthorized access.

La Russie a créé des copies de médias français pour propager des fausses informations - Numerama
thumbnail
Bulletin d’actualité CERTFR-2023-ACT-025 – CERT-FR
Fortinet fixes critical RCE flaw in Fortigate SSL-VPN devices, patch now
thumbnail
MOVEit Transfer zero-day was exploited by Cl0p gang (CVE-2023-34362) - Help Net Security
thumbnail
SAS Airlines hit by $3 million ransom demand following DDoS attacks
thumbnail
‘Gravity Forms’ WordPress Plugin Found Vulnerable to PHP Object Injection
thumbnail
Urgent WordPress Update Fixes Critical Flaw in Jetpack Plugin on Million of Sites
thumbnail

⚠️ If you're using the Jetpack plugin, listen up! A critical flaw has been discovered, leaving your WordPress site vulnerable to attacks.

Critical Firmware Vulnerability in Gigabyte Systems Exposes ~7 Million Devices
thumbnail

Gigabyte systems have been found with backdoor-like behavior, allowing unsecure Windows executable downloads via UEFI firmware.

Microsoft Sysmon now detects when executables files are created
Nessus Plugin Flaw Let Attackers Escalate the Privileges

This vulnerability exists on the binary of filesystem location that can allow threat actors to escalate privileges by abusing the plugin.

Cyberattaque au centre hospitalier universitaire de Rennes : point de situation | Agence régionale de santé Bretagne
thumbnail
KeePassXC Vulnerability CVE-2023–35866 | by CyberCitizen | Jun, 2023 | Medium
Publicité personnalisée : CRITEO sanctionné d’une amende de 40 millions d’euros | CNIL
Researchers Bypassed BIOS Password on Lenovo Laptops
thumbnail
Témoignage. Cyberattaque et rançon : un réseau d'agents immobiliers des Hauts-de-France lui aussi victime de hackers
thumbnail

Depuis près d'une semaine la ville de Lille mais aussi des entreprises font face à du piratage informatique ou plus exactement des cyberattaques d'ampleur. Ces rançongiciels se multiplient : des pirates bloquent tout et veulent...

Sept idées reçues en matière de cybersécurité et de protection de sa vie numérique
thumbnail

Certains conseils en matière de protection de la vie numérique méritent d’être considérablement nuancés.

Fake Researcher Profiles Spread Malware through GitHub Repositories as PoC Exploits
thumbnail

Several fake researcher GitHub accounts are pushing malicious code, claiming to exploit zero-day flaws in Discord, Google Chrome.

Experts Unveil Exploit for Recent Windows Vulnerability Under Active Exploitation
thumbnail

Experts Unveil Exploit for Recent Windows Vulnerability Under Active Exploitation | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.

Zero-Day Alert: Google Issues Patch for New Chrome Vulnerability - Update Now!
thumbnail

Google has released a security update to fix a new high-severity zero-day vulnerability in Chrome browser that is being actively exploited by hackers

Zyxel shares guidance for protecting devices from ongoing attacks
thumbnail

Zyxel has published guidance for protecting firewall and VPN devices from the ongoing attacks recently discovered.

“Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware | Ars Technica
thumbnail
« Le but est clair, plomber l'économie russe » : à la rencontre des nouveaux hackers au service de l'Ukraine - Numerama
thumbnail

Depuis le début de l'invasion totale de l'Ukraine par la Russie, des dizaines de milliers d'hacktivistes ont pris à cœur la cause du pays attaqué. Ces nouveaux hackers nous racontent leur quotidien de pirate engagé. Un jour, le site de la région de Moscou tombe en panne. Puis celui d'une grande assurance russe, puis

Microsoft Teams vulnerability discovered to bypass file sending restrictions - gHacks Tech News
Hackers steal data of 45,000 New York City students in MOVEit breach
thumbnail

The New York City Department of Education (NYC DOE) says hackers stole documents containing the sensitive personal information of up to 45,000 students from its MOVEit Transfer server.

Critical Flaw Found in WordPress Plugin for WooCommerce Used by 30,000 Websites
thumbnail
Exploit released for Cisco AnyConnect bug giving SYSTEM privileges
thumbnail
Reddit hackers threaten to leak data stolen in February breach
thumbnail
US government hit in global cyberattack
thumbnail

Several US federal government agencies have been hit in a global cyberattack by Russian cybercriminals that exploits a vulnerability in widely used software, according to a top US cybersecurity agency.

Oil and gas giant Shell confirms it was impacted by Clop ransomware attacks
thumbnail
WordPress Stripe payment plugin bug leaks customer order details
thumbnail

The WooCommerce Stripe Gateway plugin for WordPress was found to be vulnerable to a bug that allows any unauthenticated user to view order details placed through the plugin.

Critical FortiOS and FortiProxy Vulnerability Actively Exploited - Patch Now!
thumbnail

Hackers are actively exploiting the latest Fortinet's FortiOS and FortiProxy flaw, targeting government, manufacturing, and critical infrastructure.

Sextortionists are making AI nudes from your social media images
thumbnail
Bulletin d’actualité CERTFR-2023-ACT-024 – CERT-FR
La faille de données de SuperVPN a exposé 360 millions d’enregistrements de données d’utilisateurs en ligne – Le Journal du Hack
thumbnail

Y compris des adresses électroniques, des données de géolocalisation et des identifiants Un service VPN gratuit bien connu, SuperVPN ,

Sénégal : une « Mysterious Team » derrière les cyberattaques contre l’Etat
thumbnail

Plusieurs sites Web du gouvernement, dont celui de la présidence, ont été attaqués par des hackeurs ces derniers jours. Derrière cette campagne de piratage, un groupe qui semble opposé au président Macky Sall.