19 Décembre 2020
Shameless plug
Février 2021 - Séminaire de Sherbrooke - Cybersécurité en entrepriseRevoyez Hackfest Holiday Event + CTF via le BBS de StackFaultURL formulaire village santé mentaleQuebecSec à venir: 2e table ronde & phishing workshop/talksShownotes and Links
SolarWindshttps://www.solarwinds.com/-/media/solarwinds/swdcv2/landing-pages/trust-center/resources/secure-configuration-in-the-orion-platform.ashxhttps://support.solarwinds.com/SuccessCenter/s/article/Files-and-directories-to-exclude-from-antivirus-scanning-for-Orion-Platform-products?language=en_UShttps://newsla.localad.com/2020/12/15/breaking-pentagon-imposes-emergency-shutdown-of-its-secret-internet-protocol-router-network-handles-classified-information-up-to-the-secret-level/http://d18rn0p25nwr6d.cloudfront.net/CIK-0001739942/57108215-4458-4dd8-a5bf-55bd5e34d451.pdfhttps://twitter.com/Rothbard1776/status/1338626722321879045https://github.com/fireeye/sunburst_countermeasureshttps://www.sans.org/webcasts/emergency-webcast-about-solarwinds-supply-chain-attack-118015https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/https://dev.to/k0p1/update-fireeye-hacked-red-team-tools-leaked-8c1https://mobile.twitter.com/lordx64/status/1338526166051934213https://versprite.com/blog/security-research/exploitation-of-remote-services/https://cyber.dhs.gov/ed/21-01/#cisa-actionshttps://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.htmlhttps://www.sans.org/webcasts/emergency-webcast-about-solarwinds-supply-chain-attack-118015https://www.solarwinds.com/securityadvisoryhttps://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/Solorigate.C!dha&ThreatID=2147771132https://twitter.com/KyleHanslovan/status/1338851535342727168?s=19https://arstechnica.com/information-technology/2020/12/solarwinds-hackers-have-a-clever-way-to-bypass-multi-factor-authentication/#p3https://malicious.link/post/2020/solarflare-release-password-dumper-for-solarwinds-orion/Protégez-vous fuite de 330 000 clientsBeneva - Pas de mal?Promutuel Assurance - toujours down.Gouvernement Quebec down[Fuite de données : Desjardins connaissait sa vulnérabilité mais n’a rien fait]Le SCRS pourrait avoir violé la loiPornhub suspends over 10 million videos to eradicate illegal contentLes services intelligents d’Hydro connaissent déjà des ratés12 Oct 2020 - [QC ONLY] $440 Hydro-Quebec Hilo smart hub & 6x Zigbee thermostat with free install, save $ during peak usage eventshttps://forums.redflagdeals.com/qc-only-440-hydro-quebec-hilo-smart-hub-6x-zigbee-thermostat-free-install-save-during-peak-usage-events-2408287/https://www.hiloenergie.com/en-ca/legal/application-privacy-policy/Ministre Fitzgibbon impliqué avec HikvisionChronique/Opinion littéraire - C’est arrivé la nuit de Marc LevySolarWinds: Un véritable conte de Noël :Noel Passé: Comment la Chine aurait infiltré l’approvisionnement en serveurs de Dell, Apple, Amazon, etcNoel Présent: Comment Microsoft commente l’affaire SolarWindsNoel Futur: Comment Microsoft gère les vulnérabilités XSS/RCE persistantes dans TeamsCyberattaques Air canadaL’état de la R&D en matière d’analyse de data énergétiqueCrew
VirginieSteve WaterhousePatrick MathieuDamien BancalGuillaume MorissetteCrédits
Montage audio par Hackfest CommunicationMusic Space Kablooie - Open Source – Ego KillerLocaux virtuels par 8x8