— Veille & Actualités

Veille & Actualités

Vulnérabilités, actualités et mises à jour cybersécurité — chaque élément est attribué à sa source d'origine. Rien n'est republié en intégral.

dernière MAJ :
EPSS min: 0%

346 résultats

  • ToxicPanda Android malware uses VPN permissions to block Google Play

    The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

  • DSA-6461-1 thunderbird - security update

    Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure https://security-tracker.debian.org/tracker/DSA-6461-1

  • DSA-6460-1 openjdk-25 - security update

    Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service or information disclosure. https://security-tracker.debian.org/tracker/DSA-6460-1

  • TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

    The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.

  • Hackers infect Android car head units with proxy botnet malware

    A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [..

  • Named Pipes Under Attack: Securing Windows Interprocess Communication

    Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command au

  • Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Sp

  • DSA-6459-1 libnet-dns-perl - security update

    Two vulnerabilities were discovered in libnet-dns-perl, a Perl module to perform DNS queries, which could result in denial of service or remote code execution. https://security-tracker.debian.org/trac

  • USN-8658-2: Linux kernel (IBM) vulnerabilities

    Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SC

  • USN-8661-2: Linux kernel (Low Latency) vulnerabilities

    Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE