L'actu de la sécu


Les dernières news:

  • [remote] Invision Community 5.0.6 - Remote Code Execution (RCE)
    Publié le May 18, 2025

    Source: ExploitDB

    Invision Community 5.0.6 - Remote Code Execution (RCE)

    Lien
  • [local] Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation
    Publié le May 18, 2025

    Source: ExploitDB

    Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation

    Lien
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
    Publié le May 17, 2025

    Source: HackerNews

    Modern apps move fast—faster than most security teams can keep up. As businesses rush to build in the cloud, security often lags behind. Teams scan code in isolation, react late to cloud threats, and monitor SOC alerts only after damage is done. Attackers don’t wait. They exploit vulnerabilities within hours. Yet most organizations take days to respond to critical cloud alerts. That delay isn’t

    Lien
  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
    Publié le May 16, 2025

    Source: HackerNews

    Cybersecurity researchers are calling attention to a new botnet malware called HTTPBot that has been used to primarily single out the gaming industry, as well as technology companies and educational institutions in China. "Over the past few months, it has expanded aggressively, continuously leveraging infected devices to launch external attacks," NSFOCUS said in a report published this week. "By

    Lien
  • Top 10 Best Practices for Effective Data Protection
    Publié le May 16, 2025

    Source: HackerNews

    Data is the lifeblood of productivity, and protecting sensitive data is more critical than ever. With cyber threats evolving rapidly and data privacy regulations tightening, organizations must stay vigilant and proactive to safeguard their most valuable assets. But how do you build an effective data protection framework? In this article, we'll explore data protection best practices from meeting

    Lien
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
    Publié le May 16, 2025

    Source: HackerNews

    Researchers at ETH Zürich have discovered yet another security flaw that they say impacts all modern Intel CPUs and causes them to leak sensitive data from memory, showing that the vulnerability known as Spectre continues to haunt computer systems after more than seven years. The vulnerability, referred to as Branch Privilege Injection (BPI), "can be exploited to misuse the prediction

    Lien
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
    Publié le May 16, 2025

    Source: HackerNews

    Cybersecurity researchers have shed light on a new malware campaign that makes use of a PowerShell-based shellcode loader to deploy a remote access trojan called Remcos RAT. "Threat actors delivered malicious LNK files embedded within ZIP archives, often disguised as Office documents," Qualys security researcher Akshay Thorve said in a technical report. "The attack chain leverages mshta.exe for

    Lien
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
    Publié le May 15, 2025

    Source: HackerNews

    Austrian privacy non-profit noyb (none of your business) has sent Meta's Irish headquarters a cease-and-desist letter, threatening the company with a class action lawsuit if it proceeds with its plans to train users' data for training its artificial intelligence (AI) models without an explicit opt-in. The move comes weeks after the social media behemoth announced its plans to train its AI models

    Lien
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
    Publié le May 15, 2025

    Source: HackerNews

    Cryptocurrency exchange Coinbase has disclosed that unknown cyber actors broke into its systems and stole account data for a small subset of its customers. "Criminals targeted our customer support agents overseas," the company said in a statement. "They used cash offers to convince a small group of insiders to copy data in our customer support tools for less than 1% of Coinbase monthly

    Lien