Flux RSS

— Sources secondaires
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
Gouvernance & RégulationKrebs on Securityil y a 4 jours

A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran's time zone or have Farsi set as the default language.

Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
Gouvernance & RégulationKrebs on Securityil y a 16 jours

A hacktivist group with links to Iran's intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of Ireland, Stryker's largest hub outside of the United States, said the company sent home more than 5,000 workers there today. Meanwhile, a voicemail message at Stryker's main U.S. headquarters says the company is currently experiencing a building emergency.

Microsoft Patch Tuesday, March 2026 Edition
Gouvernance & RégulationKrebs on Securityil y a 17 jours

Microsoft Corp. today pushed security updates to fix at least 77 vulnerabilities in its Windows operating systems and other software. There are no pressing "zero-day" flaws this month (compared to February's five zero-day treat), but as usual some patches may deserve more rapid attention from organizations using Windows. Here are a few highlights from this month's Patch Tuesday.

‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
Gouvernance & RégulationKrebs on Securityil y a 35 jours

Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and security firms. But a stealthy new phishing-as-a-service offering lets customers sidestep both of these pitfalls: It uses cleverly disguised links to load the target brand's real website, and then acts as a relay between the target and the legitimate site -- forwarding the victim's username, password and multi-factor authentication (MFA) code to the legitimate site and returning its responses.

Patch Tuesday, February 2026 Edition
Gouvernance & RégulationKrebs on Securityil y a 45 jours

Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six "zero-day" vulnerabilities that attackers are already exploiting in the wild.

Please Don’t Feed the Scattered Lapsus ShinyHunters
Gouvernance & RégulationKrebs on Securityil y a 53 jours

A prolific data ransom gang that calls itself Scattered Lapsus ShinyHunters (SLSH) has a distinctive playbook when it seeks to extort payment from victim firms: Harassing, threatening and even swatting executives and their families, all while notifying journalists and regulators… Read More »

Microsoft Patch Tuesday: 74 CVEs plus 2 “Exploit Detected” advisories
Gouvernance & RégulationSophos Serious Securityil y a 961 jours

74 CVEs, and two "Exploitation Detected" advisories, which are nearly but not quite the same as 0-days. Also, two potential Teams treacheries that you really want to fix. Categories: Naked Security Tags: Patch Tuesday, vulnerability, Zero-day