L'actu de la sécu


Les dernières news:

  • AI Threats Are Evolving Fast — Learn Practical Defense Tactics in this Expert Webinar
    Publié le April 3, 2025

    Source: HackerNews

    The rules have changed. Again. Artificial intelligence is bringing powerful new tools to businesses. But it's also giving cybercriminals smarter ways to attack. They’re moving quicker, targeting more precisely, and slipping past old defenses without being noticed. And here's the harsh truth: If your security strategy hasn’t evolved with AI in mind, you’re already behind. But you’re not alone—and

    Lien
  • AI Adoption in the Enterprise: Breaking Through the Security and Compliance Gridlock
    Publié le April 3, 2025

    Source: HackerNews

    AI holds the promise to revolutionize all sectors of enterpriseーfrom fraud detection and content personalization to customer service and security operations. Yet, despite its potential, implementation often stalls behind a wall of security, legal, and compliance hurdles. Imagine this all-too-familiar scenario: A CISO wants to deploy an AI-driven SOC to handle the overwhelming volume of security

    Lien
  • Google Patches Quick Share Vulnerability Enabling Silent File Transfers Without Consent
    Publié le April 3, 2025

    Source: HackerNews

    Cybersecurity researchers have disclosed details of a new vulnerability impacting Google's Quick Share data transfer utility for Windows that could be exploited to achieve a denial-of-service (DoS) or send arbitrary files to a target's device without their approval. The flaw, tracked as CVE-2024-10668 (CVSS score: 5.9), is a bypass for two of the 10 shortcomings that were originally disclosed by

    Lien
  • Triada Malware Preloaded on Counterfeit Android Phones Infects 2,600+ Devices
    Publié le April 3, 2025

    Source: HackerNews

    Counterfeit versions of popular smartphone models that are sold at reduced prices have been found to be preloaded with a modified version of an Android malware called Triada. "More than 2,600 users in different countries have encountered the new version of Triada, the majority in Russia," Kaspersky said in a report. The infections were recorded between March 13 and 27, 2025.  Triada is the

    Lien
  • Legacy Stripe API Exploited to Validate Stolen Payment Cards in Web Skimmer Campaign
    Publié le April 3, 2025

    Source: HackerNews

    Threat hunters are warning of a sophisticated web skimmer campaign that leverages a legacy application programming interface (API) from payment processor Stripe to validate stolen payment information prior to exfiltration. "This tactic ensures that only valid card data is sent to the attackers, making the operation more efficient and potentially harder to detect," Jscrambler researchers Pedro

    Lien
  • Europol Dismantles Kidflix With 72,000 CSAM Videos Seized in Major Operation
    Publié le April 3, 2025

    Source: HackerNews

    In one of the largest coordinated law enforcement operations, authorities have dismantled Kidflix, a streaming platform that offered child sexual abuse material (CSAM). "A total of 1.8 million users worldwide logged on to the platform between April 2022 and March 2025," Europol said in a statement. "On March 11, 2025, the server, which contained around 72,000 videos at the time, was seized by

    Lien
  • [webapps] Nagios Log Server 2024R1.3.1 - Stored XSS
    Publié le April 3, 2025

    Source: ExploitDB

    Nagios Log Server 2024R1.3.1 - Stored XSS

    Lien
  • [local] ollama 0.6.4 - Server Side Request Forgery (SSRF)
    Publié le April 3, 2025

    Source: ExploitDB

    ollama 0.6.4 - Server Side Request Forgery (SSRF)

    Lien
  • [webapps] ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
    Publié le April 3, 2025

    Source: ExploitDB

    ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)

    Lien