Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 13 mars 2025Securité

Les cyberattaques russes contre la France sont complètement « désinhibées », alerte l’ANSSI, le cyber-pompier français

13 mars 2025 à 10:51

L'ANSSI, la sentinelle de la cybersécurité en France, fait le bilan d'une année marquée par une recrudescence des cyberattaques, notamment dans le contexte des Jeux olympiques. L'agence souligne le rôle de la Russie dans de nombreuses opérations de déstabilisation.

Meta Warns of FreeType Vulnerability (CVE-2025-27363) With Active Exploitation Risk

Meta has warned that a security vulnerability impacting the FreeType open-source font rendering library may have been exploited in the wild. The vulnerability has been assigned the CVE identifier CVE-2025-27363, and carries a CVSS score of 8.1, indicating high severity. Described as an out-of-bounds write flaw, it could be exploited to achieve remote code execution when parsing certain font

WARNING: Expiring Root Certificate May Disable Firefox Add-Ons, Security Features, and DRM Playback

Browser maker Mozilla is urging users to update their Firefox instances to the latest version to avoid facing issues with using add-ons due to the impending expiration of a root certificate. "On March 14, 2025, a root certificate used to verify signed content and add-ons for various Mozilla projects, including Firefox, will expire," Mozilla said. "Without updating to Firefox

Cyberattaque sur Lorient : des données d’agents municipaux publiées sur un forum de pirates

13 mars 2025 à 07:20

Une cyberattaque a récemment touché la mairie de la ville de Lorient. Des données personnelles d'agents municipaux ont été mises en vente sur un célèbre forum de pirates.

Browser-Based Data Leaks: 3 Biggest Data Security Challenges Today

12 mars 2025 à 15:02
Traditional Data Loss Prevention (DLP) solutions weren't built for today's browser-driven workplace. Now sensitive data moves moves through SaaS apps, AI tools, and personal accounts, bypassing legacy security controls. Learn from Keep Aware how real-time browser security can stop data leaks before they happen. [...]

Chinese Hackers Breach Juniper Networks Routers With Custom Backdoors and Rootkits

The China-nexus cyber espionage group tracked as UNC3886 has been observed targeting end-of-life MX routers from Juniper Networks as part of a campaign designed to deploy custom backdoors, highlighting their ability to focus on internal networking infrastructure. "The backdoors had varying custom capabilities, including active and passive backdoor functions, as well as an embedded script that

Un acteur de l’espionnage de type « China-Nexus » cible les routeurs de Juniper Networks

Par : UnderNews
12 mars 2025 à 17:02

Après une enquête de plusieurs mois remontant à la mi-2024, Mandiant publie ses conclusions sur une campagne d’espionnage furtive menée par un acteur chinois (UNC3886 ) qui a déployé des logiciels malveillants personnalisés sur des routeurs Junos OS de Juniper Networks en fin de vie. Tribune – Mandiant a travaillé avec Juniper Networks pour enquêter […]

The post Un acteur de l’espionnage de type « China-Nexus » cible les routeurs de Juniper Networks first appeared on UnderNews.
Hier — 12 mars 2025Securité

Cybersécurité – Rapport ANSSI : +15 % d’attaques en 2024 – Comment réagir en temps réel ?

Par : UnderNews
12 mars 2025 à 08:24

L’ANSSI vient de publier son Panorama 2024 de la cybermenace, mettant en avant une hausse de 15 % des cyberattaques par rapport à 2023 et une intensification des opérations de déstabilisation. Cette tendance confirme que la menace cyber ne fait que croître, avec des attaquants qui exploitent des outils de plus en plus sophistiqués. Tribune – […]

The post Cybersécurité – Rapport ANSSI : +15 % d’attaques en 2024 – Comment réagir en temps réel ? first appeared on UnderNews.

Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack

Threat intelligence firm GreyNoise is warning of a "coordinated surge" in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities spanning multiple platforms. "At least 400 IPs have been seen actively exploiting multiple SSRF CVEs simultaneously, with notable overlap between attack attempts," the company said, adding it observed the activity on March 9, 2025. The countries which

Pentesters: Is AI Coming for Your Role?

We’ve been hearing the same story for years: AI is coming for your job. In fact, in 2017, McKinsey printed a report, Jobs Lost, Jobs Gained: Workforce Transitions in a Time of Automation, predicting that by 2030, 375 million workers would need to find new jobs or risk being displaced by AI and automation. Queue the anxiety.  There have been ongoing whispers about what roles would be

URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days

Microsoft on Tuesday released security updates to address 57 security vulnerabilities in its software, including a whopping six zero-days that it said have been actively exploited in the wild. Of the 56 flaws, six are rated Critical, 50 are rated Important, and one is rated Low in severity. Twenty-three of the addressed vulnerabilities are remote code execution bugs and 22 relate to privilege

❌
❌