L'actu de la sécu


Les dernières news:

  • Malicious npm Package Targets Atomic Wallet, Exodus Users by Swapping Crypto Addresses
    Publié le April 10, 2025

    Source: HackerNews

    Threat actors are continuing to upload malicious packages to the npm registry so as to tamper with already-installed local versions of legitimate libraries and execute malicious code in what's seen as a sneakier attempt to stage a software supply chain attack. The newly discovered package, named pdf-to-office, masquerades as a utility for converting PDF files to Microsoft Word documents. But, in

    Lien
  • PlayPraetor Reloaded: CTM360 Uncovers a Play Masquerading Party
    Publié le April 10, 2025

    Source: HackerNews

    Overview of the PlayPraetor Masquerading Party Variants CTM360 has now identified a much larger extent of the ongoing Play Praetor campaign. What started with 6000+ URLs of a very specific banking attack has now grown to 16,000+ with multiple variants. This research is ongoing, and much more is expected to be discovered in the coming days.  As before, all the newly discovered play

    Lien
  • The Identities Behind AI Agents: A Deep Dive Into AI & NHI
    Publié le April 10, 2025

    Source: HackerNews

    AI agents have rapidly evolved from experimental technology to essential business tools. The OWASP framework explicitly recognizes that Non-Human Identities play a key role in agentic AI security. Their analysis highlights how these autonomous software entities can make decisions, chain complex actions together, and operate continuously without human intervention. They're no longer just tools,

    Lien
  • Gamaredon Uses Infected Removable Drives to Breach Western Military Mission in Ukraine
    Publié le April 10, 2025

    Source: HackerNews

    The Russia-linked threat actor known as Gamaredon (aka Shuckworm) has been attributed to a cyber attack targeting a foreign military mission based in Ukraine with an aim to deliver an updated version of a known malware called GammaSteel. The group targeted the military mission of a Western country, per the Symantec Threat Hunter team, with first signs of the malicious activity detected on

    Lien
  • Europol Arrests Five SmokeLoader Clients Linked by Seized Database Evidence
    Publié le April 10, 2025

    Source: HackerNews

    Law enforcement authorities have announced that they tracked down the customers of the SmokeLoader malware and detained at least five individuals. "In a coordinated series of actions, customers of the Smokeloader pay-per-install botnet, operated by the actor known as 'Superstar,' faced consequences such as arrests, house searches, arrest warrants or 'knock and talks,'" Europol said in a

    Lien
  • AkiraBot Targets 420,000 Sites with OpenAI-Generated Spam, Bypassing CAPTCHA Protections
    Publié le April 10, 2025

    Source: HackerNews

    Cybersecurity researchers have disclosed details of an artificial intelligence (AI) powered platform called AkiraBot that's used to spam website chats, comment sections, and contact forms to promote dubious search engine optimization (SEO) services such as Akira and ServicewrapGO. "AkiraBot has targeted more than 400,000 websites and successfully spammed at least 80,000 websites since September

    Lien
  • [webapps] flatCore 1.5.5 - Arbitrary File Upload
    Publié le April 10, 2025

    Source: ExploitDB

    flatCore 1.5.5 - Arbitrary File Upload

    Lien
  • [webapps] AquilaCMS 1.409.20 - Remote Command Execution (RCE)
    Publié le April 10, 2025

    Source: ExploitDB

    AquilaCMS 1.409.20 - Remote Command Execution (RCE)

    Lien
  • [webapps] Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
    Publié le April 10, 2025

    Source: ExploitDB

    Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)

    Lien