L'actu de la sécu


Les dernières news:

  • Triada Malware Preloaded on Counterfeit Android Phones Infects 2,600+ Devices
    Publié le April 3, 2025

    Source: HackerNews

    Counterfeit versions of popular smartphone models that are sold at reduced prices have been found to be preloaded with a modified version of an Android malware called Triada. "More than 2,600 users in different countries have encountered the new version of Triada, the majority in Russia," Kaspersky said in a report. The infections were recorded between March 13 and 27, 2025.  Triada is the

    Lien
  • Legacy Stripe API Exploited to Validate Stolen Payment Cards in Web Skimmer Campaign
    Publié le April 3, 2025

    Source: HackerNews

    Threat hunters are warning of a sophisticated web skimmer campaign that leverages a legacy application programming interface (API) from payment processor Stripe to validate stolen payment information prior to exfiltration. "This tactic ensures that only valid card data is sent to the attackers, making the operation more efficient and potentially harder to detect," Jscrambler researchers Pedro

    Lien
  • Europol Dismantles Kidflix With 72,000 CSAM Videos Seized in Major Operation
    Publié le April 3, 2025

    Source: HackerNews

    In one of the largest coordinated law enforcement operations, authorities have dismantled Kidflix, a streaming platform that offered child sexual abuse material (CSAM). "A total of 1.8 million users worldwide logged on to the platform between April 2022 and March 2025," Europol said in a statement. "On March 11, 2025, the server, which contained around 72,000 videos at the time, was seized by

    Lien
  • [webapps] AppSmith 1.47 - Remote Code Execution (RCE)
    Publié le April 3, 2025

    Source: ExploitDB

    AppSmith 1.47 - Remote Code Execution (RCE)

    Lien
  • [webapps] Nagios Log Server 2024R1.3.1 - Stored XSS
    Publié le April 3, 2025

    Source: ExploitDB

    Nagios Log Server 2024R1.3.1 - Stored XSS

    Lien
  • [local] ollama 0.6.4 - Server Side Request Forgery (SSRF)
    Publié le April 3, 2025

    Source: ExploitDB

    ollama 0.6.4 - Server Side Request Forgery (SSRF)

    Lien
  • [webapps] ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)
    Publié le April 3, 2025

    Source: ExploitDB

    ABB Cylon Aspect 3.07.02 - File Disclosure (Authenticated)

    Lien
  • [webapps] Webmin Usermin 2.100 - Username Enumeration
    Publié le April 3, 2025

    Source: ExploitDB

    Webmin Usermin 2.100 - Username Enumeration

    Lien
  • [remote] Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
    Publié le April 3, 2025

    Source: ExploitDB

    Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure

    Lien