— Veille & Actualités

Veille & Actualités

Vulnérabilités, actualités et mises à jour cybersécurité — chaque élément est attribué à sa source d'origine. Rien n'est republié en intégral.

dernière MAJ :
EPSS min: 0%

43 résultats

  • Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead

    Feds claim he charged clients more than ransoms, paid up, pocketed the difference

  • Ransomware recovery CEO charged over secret ransom payments

    The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprieta

  • FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

    The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]

  • Hackers hijack Google domains after breaching ccTLD registries

    Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compro

  • Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

    Trusted brand impersonation without the usual browser certificate warnings spells trouble

  • USN-8900-1: Go Networking vulnerabilities

    It was discovered that Go Networking did not properly handle server errors after sending a GOAWAY frame during HTTP/2 connection shutdown, which could cause the connection to hang. A remote attacker c

  • Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

    Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were no

  • Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign

  • AWS launches open-source AI agent sandbox to prevent YOLO mode disasters

    Strands Box is the latest open source AI control tool from the cloud giant; like its predecessors, it promises tighter reins on autonomous agents

  • US states sue popular kitmaker TP-Link over China risks

    Router maker rejects allegations it misled buyers about protection and its reliance on Chinese suppliers

  • SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker