Filtrer
Actualités (150 résultats)
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library fo...
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched...
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into ent...
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are...
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers a...
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that inst...
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sext...
What Is Pickaxe Mountain, Iran’s Underground Nuclear Site That Trump Is Threatening?
La montagne Pickaxe est une installation nucléaire souterraine iranienne qui fait régulièrement la une des débats géopol...
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Des cybercriminels nord-coréens du groupe BlueNoroff mènent des campagnes de phishing sophistiquées en usurpant l'identi...
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Une faille de sécurité critique baptisée Certighost a été découverte dans Active Directory, le système de gestion des id...
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Des chercheurs en cybersécurité ont découvert une faille de sécurité majeure dans ChatGPT Workspace Agents d'OpenAI, bap...
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Des chercheurs en sécurité ont découvert une faille critique dans le service Bing Images de Microsoft qui permettait d'e...