Veille live
Veille CyberInfra — Veille cybersecurite : Ryuk ransomware member sentenced to 24 months in prison Veille CyberInfra — Veille cybersecurite : ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Veille CyberInfra — Veille cybersecurite : Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input Veille CyberInfra — Veille cybersecurite : Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape Veille CyberInfra — Veille cybersecurite : ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Veille CyberInfra — Veille cybersecurite : Arista patches actively exploited VeloCloud Orchestrator zero-day Veille CyberInfra — Veille cybersecurite : Ryuk ransomware member sentenced to 24 months in prison Veille CyberInfra — Veille cybersecurite : ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Veille CyberInfra — Veille cybersecurite : Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input Veille CyberInfra — Veille cybersecurite : Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape Veille CyberInfra — Veille cybersecurite : ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Veille CyberInfra — Veille cybersecurite : Arista patches actively exploited VeloCloud Orchestrator zero-day
Blog

Veille cybersécurité

Les dernières actualités et alertes de sécurité, décryptées pour les PME.

Veille cybersecurite : StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

20/08/2026

Source : The Hacker News Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. « The operation doesn’t rely on a single piece of malware, but on […]

Veille cybersecurite : Rogue ransomware affiliate poses as recovery firm to steal payments

20/08/2026

Source : BleepingComputer A suspected ransomware affiliate is posing as a ransomware recovery service called « Ransom Busters, » contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. […] Lire l’article original Vous vous demandez si votre entreprise est exposee a ce type […]

Veille cybersecurite : Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

20/08/2026

Source : The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting […]

Veille cybersecurite : Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

20/08/2026

Source : The Hacker News Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed […]

Veille cybersecurite : Your Controls Block Known Attacks. What About the Behavior?

19/08/2026

Source : BleepingComputer Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security’s Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. […] Lire l’article original Vous vous demandez si votre entreprise est […]

Veille cybersecurite : TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

19/08/2026

Source : The Hacker News Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. « TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services, » Ontinue said in a technical report shared with The Hacker News. « Tasking flows through SharePoint Online file Lire […]