Mensuel Shaarli

Tous les liens d'un mois sur une page.

September, 2024

D-Link fixes critical RCE, hardcoded password flaws in WiFi 6 routers

D-Link has fixed critical vulnerabilities in three popular wireless router models that allow remote attackers to execute arbitrary code or access the devices using hardcoded credentials.

Vulnérabilité dans SonicWall - CERT-FR

Cette vulnérabilité, de type contrôle d'accès défaillant, permet à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

CISA confirms that SonicWall vulnerability is getting exploited (CVE-2024-40766) - Help Net Security
thumbnail

CISA has added CVE-2024-40766 to its KEV catalog, thus confirming it is being actively exploited by attackers.

PentesterLab Blog: The Certification Trap
thumbnail

Explore the pitfalls of relying on certifications in security, and why real skills, critical thinking, and personalized growth should take priority over collecting badges.

Le groupe Meta interdit les médias d’Etat russes sur Facebook, Instagram et WhatsApp pour éviter toute « activité d’ingérence étrangère »

Le média public russe RT, lancé en 2005, est entre autres considéré par les Occidentaux comme un pur organe de propagande en faveur du Kremlin.

Ivanti Releases Urgent Security Updates for Endpoint Manager Vulnerabilities
thumbnail

Ivanti releases critical security updates for Endpoint Manager, addressing remote code execution vulnerabilities. Users urged to update immediately.

Security Advisory YSA-2024-03 | Yubico
Une faille dans le HDMI permet de voler des mots de passe et des informations sensibles
thumbnail
US Marshals Service disputes ransomware gang's breach claims
thumbnail

The U.S. Marshals Service (USMS) denies its systems were breached by the Hunters International ransomware gang after being listed as a new victim on the cybercrime group's leak site on Monday.

Blog Stéphane Bortzmeyer: Le problème du serveur whois du .mobi
Red Team 2024 - NoLimitSecu

Episode #472 Red Team 2024 Avec Gregory Draperi  

Fortinet confirms data breach after hacker claims to steal 440GB of files

Cybersecurity giant Fortinet has confirmed it suffered a data breach after a threat actor claimed to steal 440GB of files from the company's Microsoft Sharepoint server.

Payment provider data breach exposes credit card information of 1.7 million customers
thumbnail

Payment gateway provider Slim CD has notified 1.7 million users that their credit card information may have been leaked.

ZATAZ » Quinze jours après la cyberattaque, la société OCTAVE fait un point sur la situation
Changes to the OSCP – OffSec Support Portal

Effective November 1, 2024, OffSec will replace the current OSCP exam with an updated version. The updated exam version will include the...