Bulletins d'actualité
De Docaposte Cyberdéfense
Classification
SommaireUndernews |
|
[webapps] OpenEMR 7.0.2 - Arbitrary File Read
OpenEMR 7.0.2 - Arbitrary File Read
|
|
[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
|
|
[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection
Drupal Core 10.5.5 - Error-Based SQL Injection
|
|
[webapps] WordPress OrderConvo 14 - Path Traversal
WordPress OrderConvo 14 - Path Traversal
|
|
[remote] Notepad++ 8.9.6 - Arbitrary Code Execution
Notepad++ 8.9.6 - Arbitrary Code Execution
|
|
[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting
YAMCS yamcs-core 5.12.7 - No Rate Limiting
|
|
[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration
YAMCS yamcs-core 5.12.7 - User Enumeration
|
|
[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection
YAMCS yamcs-core 5.12.7 - LDAP Injection
|
|
[remote] Microsoft - NTLMv2 Hash Capture
Microsoft - NTLMv2 Hash Capture
|
|
[webapps] MikroORM 7.0.13 - SQL Injection
MikroORM 7.0.13 - SQL Injection
|
Dark Reading |
Impossible de charger le flux RSS de https://www.darkreading.com/rss_simple.asp : Il y a eu un problème lors de la requête HTTP : 403 Forbidden
ZATAZ |
|
RATP : un pirate revendique 62 208 données d’employés
Un pirate revendique 62 208 données d’employés RATP, avec identifiants, fonctions et informations internes.
|
|
CFake : un Français poursuivi pour 300 000 deepfakes
CFake : un Français poursuivi après la diffusion massive de deepfakes sexuels visant 14 000 victimes.
|
|
Cyber actualités ZATAZ de la semaine du 8 au 14 juin 2026
Les actualités cyber de la semaine : sécurité informatique, identité numérique, piratage et actions de la justice.
|
|
Identité notariale : un pirate revendique une cyber attaque !
Une fuite revendiquée vise 7 729 comptes notariaux et pourrait faciliter hameçonnage ciblé et usurpation.
|
|
Un pirate revendique une série d’intrusions à Paris, Nantes et Lyon
Après Tchap, un pirate revendique des intrusions visant Nantes, Lyon, Bobigny, Paris et Smartbox.
|
|
Des millions de dollars perdus via les distributeurs automatiques de cryptomonnaies.
Selon un nouveau rapport du FBI, les résidents américains ont perdu 388 millions de dollars à cause des bornes de cryptomonnaie en 2025. Le FBI a publié un supplément à son étude annuelle sur les incidents signalés au Centre de plaintes sur la cybercriminalité (IC3), axé sur les distributeurs automatiques de cryptomonnaies qui permettent aux […]
|
|
Dumpsec : sept suspects interpellés en France
Sept suspects liés à Dumpsec ont été arrêtés après le vol présumé de dizaines de millions de données.
|
|
Des alertes américaines avant l’affaire Lyhanna
Avant l’affaire Lyhanna, des alertes américaines éclairaient le rôle du NCMEC et des enquêteurs habilités à traquer les pédocriminels.
|
|
Faux remboursement d’énergie : les pièges à repérer
Un faux remboursement EDF/ENGIE de 219,90 euros révèle un piège conçu pour voler identité et données bancaires des français.
|
|
Faux recrutements FIFA : le piège vole les accès
En plein Mondial 2026, de faux recrutements FIFA ciblent les comptes Google, META et les accès professionnels.
|
';-- |
Identity Leaked |
|
Berkadia - 305,216 breached accounts
In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data.
|
|
Infinite Campus - 137,123 breached accounts
In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets.
|
| University of Nottingham - 454,635 breached accounts
In June 2026, the University of Nottingham was the target of a cyber attack, later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolme...
|
|
Baker Distributing - 102,935 breached accounts
In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site. In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HV...
|
|
BCD Travel - 396,313 breached accounts
In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer na...
|
|
DentaQuest - 2,553,599 breached accounts
In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files (
|
| Edmunds - 177,860 breached accounts
In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached. Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone numbers and vehicle-related records.
|
|
Atlas Menu - 63,926 breached accounts
In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.
|
|
Charter - 4,851,517 breached accounts
In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses....
|
|
Kemper - 269,299 breached accounts
In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they...
|
