Parce que… c’est l’épisode 0x629!
Shameless plug
12 au 17 octobre 2025 - Objective by the sea v814 et 15 octobre 2025 - ATT&CKcon 6.014 et 15 octobre 2025 - Forum inCyber CanadaCode rabais de 30% - CA25KDUX924 et 5 novembre 2025 - FAIRCON 202510 au 12 novembre 2025 - IAQ - Le Rendez-vous IA Québec17 au 20 novembre 2025 - European Cyber Week25 et 26 février 2026 - SéQCure 2026Description
Notes
AppleMemory Integrity Enforcement: A complete vision for memory safety in Apple devicesiCloud Calendar abused to send phishing emails from Apple’s serversDormant macOS Backdoor ChillyHell ResurfacesMicrosoftMicrosoft Patch Tuesday September 2025 Fixes Risky Kernel FlawsSenator blasts Microsoft for making default Windows vulnerable to “Kerberoasting”Senator blasts Microsoft for ‘dangerous, insecure software’ that helped pwn US hospitalsMicrosoft adds malicious link warnings to Teams private chatsMicrosoft cloud services disrupted by Red Sea cable cutsMicrosoft is officially sending employees back to the office. Read the memoSupply chainHackers Booked Very Little Profit with Widespread npm Supply Chain AttackHackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly DownloadsDéfensifThe Quiet Revolution in Kubernetes SecurityTailGuard - La solution Docker qui marie WireGuard et Tailscale pour du VPN surpuissantGeedge & MESA Leak: Analyzing the Great Firewall’s Largest Document LeakForget disappearing messages – now Signal will store 100MB of them for you for freeIntroducing Signal Secure BackupsWe have early access to Android Security Bulletin patchesMISP 2.5.21 Released with a new recorrelate feature, various fixes and updatesThreat Actor Installed EDR on Their Systems, Revealing Workflows and Tools UsedOffensifJaguar Land Rover discloses a data breach after recent cyberattackJaguar Land Rover extends shutdown after cyber attackSalty2FA Takes Phishing Kits to Enterprise LevelPolice Body Camera Apps Sending Data to Cloud Servers Hosted in China Via TLS Port 9091Weaponizing Ads: How Governments Use Google Ads and Facebook Ads to Wage Propaganda WarsSpectre haunts CPUs again: VMSCAPE vulnerability leaks cloud secretsVirusTotal finds hidden malware phishing campaign in SVG filesIACVE-2025-58444 - MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP ServerCursor AI Code Editor RCE Vulnerability Enables “autorun” of Malicious on your MachineThe Software Engineers Paid to Fix Vibe Coded MessesTheAuditor - L’outil de sécurité qui rend vos assistants IA moins laxistes sur la sécurité de votre codeInsolite / DiversBrussels faces privacy crossroads over encryption backdoorsMy Latest Book: Rewiring DemocracyA love letter to Internet Relay ChatCollaborateurs
Nicolas-Loïc FortinCrédits
Montage par Intrasecure incLocaux réels par Intrasecure inc