Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

31742 bookmarks
Custom sorting
Fini Starlink ? Un géant de la défense plaide pour se tourner (enfin) vers les satellites européens
Fini Starlink ? Un géant de la défense plaide pour se tourner (enfin) vers les satellites européens
Thales met en garde contre les risques de dépendance aux satellites privés. La fiabilité de Starlink est remise en cause, alors que son dirigeant, Elon Musk, brouille les frontières entre patron d'entreprise et conseiller politique. L'un des plus importants groupe de défense français recommande de prendre ses
·numerama.com·
Fini Starlink ? Un géant de la défense plaide pour se tourner (enfin) vers les satellites européens
37K+ VMware ESXi instances vulnerable to critical zero-day
37K+ VMware ESXi instances vulnerable to critical zero-day
Some customers have been unable to download the patches for three VMware zero-day vulnerabilities due to an issue with the Broadcom Support Portal.
·cybersecuritydive.com·
37K+ VMware ESXi instances vulnerable to critical zero-day
Microsoft says malvertising campaign impacted 1 million PCs
Microsoft says malvertising campaign impacted 1 million PCs
​Microsoft has taken down an undisclosed number of GitHub repositories used in a massive malvertising campaign that impacted almost one million devices worldwide.
·bleepingcomputer.com·
Microsoft says malvertising campaign impacted 1 million PCs
Akira ransomware encrypted network from a webcam to bypass EDR
Akira ransomware encrypted network from a webcam to bypass EDR
The Akira ransomware gang was spotted using an unsecured webcam to launch encryption attacks on a victim's network, effectively circumventing Endpoint Detection and Response (EDR), which was blocking the encryptor in Windows.
·bleepingcomputer.com·
Akira ransomware encrypted network from a webcam to bypass EDR
Who is Responsible and Does it Matter?
Who is Responsible and Does it Matter?
Martin Lee dives into to the complexities of defending our customers from threat actors and covers the latest Talos research in this week's newsletter.
·blog.talosintelligence.com·
Who is Responsible and Does it Matter?
US seizes domain of Garantex crypto exchange used by ransomware gangs
US seizes domain of Garantex crypto exchange used by ransomware gangs
The U.S. Secret Service has seized the domain of the sanctioned Russian cryptocurrency exchange Garantex in collaboration with the Department of Justice's Criminal Division, the FBI, and Europol.
·bleepingcomputer.com·
US seizes domain of Garantex crypto exchange used by ransomware gangs
Cybercrime 'crew' stole $635,000 in Taylor Swift concert tickets
Cybercrime 'crew' stole $635,000 in Taylor Swift concert tickets
New York prosecutors say that two people working at a third-party contractor for the StubHub online ticket marketplace made $635,000 after almost 1,000 concert tickets and reselling them online.
·bleepingcomputer.com·
Cybercrime 'crew' stole $635,000 in Taylor Swift concert tickets
Malvertising campaign leads to info stealers hosted on GitHub
Malvertising campaign leads to info stealers hosted on GitHub
Microsoft detected a large-scale malvertising campaign in early December 2024 that impacted nearly one million devices globally. The attack originated from illegal streaming websites embedded with malvertising redirectors and ultimately redirected users to GitHub to deliver initial access payloads as the start of a modular and multi-stage attack chain.
·microsoft.com·
Malvertising campaign leads to info stealers hosted on GitHub
Ethereum private key stealer on PyPI downloaded over 1,000 times
Ethereum private key stealer on PyPI downloaded over 1,000 times
A malicious Python Package Index (PyPI)  package named "set-utils" has been stealing Ethereum private keys through intercepted wallet creation functions and exfiltrating them via the Polygon blockchain.
·bleepingcomputer.com·
Ethereum private key stealer on PyPI downloaded over 1,000 times
Attackers Target Japanese Firms with Cobalt Strike
Attackers Target Japanese Firms with Cobalt Strike
Attackers are actively exploiting an RCE flaw in Windows PHP-CGI implementations to target Japanese firms, deploying Cobalt Strike for persistence
·infosecurity-magazine.com·
Attackers Target Japanese Firms with Cobalt Strike
37K+ VMware ESXi instances vulnerable to critical zero-day
37K+ VMware ESXi instances vulnerable to critical zero-day
Some customers have been unable to download the patches for three VMware zero-day vulnerabilities due to an issue with the Broadcom Support Portal.
·cybersecuritydive.com·
37K+ VMware ESXi instances vulnerable to critical zero-day
Free vCISO Course: Turning MSPs and MSSPs into Cybersecurity Powerhouses
Free vCISO Course: Turning MSPs and MSSPs into Cybersecurity Powerhouses
The vCISO Academy is a free learning platform to equip service providers with training needed to build and expand their vCISO offerings. Learn more from Cynomi on how the Academy helps you launch or expand your vCISO services.
·bleepingcomputer.com·
Free vCISO Course: Turning MSPs and MSSPs into Cybersecurity Powerhouses
Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
Over 37,000 internet-exposed VMware ESXi instances are vulnerable to CVE-2025-22224, a critical out-of-bounds write flaw that is actively exploited in the wild.
·bleepingcomputer.com·
Over 37,000 VMware ESXi servers vulnerable to ongoing attacks