Nous venons de tourner un nouveau SECHebdo en live sur Youtube. Comme d’habitude, si vous avez raté l’enregistrement, vous pouvez le retrouver sur notre chaîne Youtube (vidéo ci-dessus) ou bien au format podcast audio:
Au sommaire de cette émission :
Notre discord : http://discord.comptoirsecu.fr
A bientôt pour d’autres émissions/podcasts!
Liste des sources :
Découverte de la semaine - Nouveaux outils forensics MacTwitterForensic Utilities - MacGitHub - Rurik/Noriben: Noriben - Portable, Simple, Malware Analysis SandboxBref - Ransomware chez Xefi JuraJura. Une cyber attaque touche l’entreprise XEFI et ses clients jurassiens | Voix du JuraRansomware Bitcoin Wallet Frozen by UK Court to Recover RansomMaze Ransomware Not Getting Paid, Leaks Data Left and RightExposition de données de support MS250 million Microsoft customer service & support records exposedBinaryEdgeAccess Misconfiguration for Customer Support Database - Microsoft Security Response CenterInvisible characters fingerprinthttps://medium.com/@umpox/be-careful-what-you-copy-invisibly-inserting-usernames-into-text-with-zero-width-characters-18b4e6f17b66Amélioration d’attack simulator O365Announcing Updates to the M365 Attack Simulator - Microsoft Tech Community - 1065762Ransomware bisPDF DocumentDOD contractor suffers ransomware infection | ZDNetToll Group tight-lipped on alleged ransomware attack - Security - iTnewsCity of Racine attacked with ransomwareUne cyber-attaque en cours chez l’intégrateur IT belge SPIE ICS - ICT actualité - Data NewsSchool’s out as ransomware attack downs IT systems at Scotland’s Dundee and Angus College • The RegisterITI Technical College latest victim of ransomware attacksInformation on a cyberattack | Bouygues Construction MediaroomData Integrity: Detecting and Responding to Ransomware and Other Destructive Events | NCCoEData Integrity: Identifying and Protecting Assets Against Ransomware and Other Destructive Events | NCCoEhttps://www.cbc.ca/news/technology/unnamed-insurance-company-cyberattack-1.5445326Corner VulnJenkins Security Advisory 2020-01-29TeamViewer - WhyNotSecurityHeap Overflow in F-Secure Internet Gatekeeper · Doyensec’s BlogDjango security releases issued: 3.0.3, 2.2.10, and 1.11.28 | Weblog | DjangoCode injection in Workflows leading to SharePoint RCE (CVE-2020-0646) – MDSechttps://www.qualys.com/2020/01/28/cve-2020-7247/lpe-rce-opensmtpd.txtGitHub - Xh4H/Satellian-CVE-2020-7980: PoC script that shows RCE vulnerability over Intellian Satellite controllerAdobe Security Bulletin