Bulletins d'actualité : Différence entre versions

De Docaposte Cyberdéfense
Aller à : navigation, rechercher
Ligne 6 : Ligne 6 :
 
<br>
 
<br>
  
−
{{#widget:Tweeter}}
+
{{#widget:Tweetter|user=perfplanet|id=353950675882885120}}
  
 
{| style="color: black; background-color: #ffffcc; width: 100%;"
 
{| style="color: black; background-color: #ffffcc; width: 100%;"

Version du 5 mars 2018 à 15:32

Classification


{{#widget:Tweetter|user=perfplanet|id=353950675882885120}}


Edb-2015-theme-logo641.png

Offensive Security’s Exploit Database



Doc.png

[remote] Teltonika_RutOS 00.07.06.21 - command injection
Teltonika_RutOS 00.07.06.21 - command injection

Doc.png

[webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write
TigerGraph_Community_Edition 4.2.4 - arbitrary file write

Doc.png

[webapps] WordPress 7.0.2 - Path Travesal
WordPress 7.0.2 - Path Travesal

Doc.png

[webapps] Food-Ordering 1.0 - LFI
Food-Ordering 1.0 - LFI

Doc.png

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE
Ecava_ntegraXor IGX_16.0.701.10 - RCE

Doc.png

[webapps] Krayin CRM 2.2.4 - IDOR
Krayin CRM 2.2.4 - IDOR

Doc.png

[webapps] SuiteCRM 8.10.1 - Authenticated SSRF
SuiteCRM 8.10.1 - Authenticated SSRF

Doc.png

[webapps] InvoicePlane 1.7.1 - RCE
InvoicePlane 1.7.1 - RCE

Doc.png

[webapps] POMS oretnom23v1.0 - SQLi vulnerabilities
POMS oretnom23v1.0 - SQLi vulnerabilities

Doc.png

[remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE
MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE


Darkreading-logo.gif

Dark Reading



Impossible de charger le flux RSS de https://www.darkreading.com/rss_simple.asp : Il y a eu un problème lors de la requête HTTP : 403 Forbidden


Logo-3-1.png

ZATAZ



Doc.png

CJIS Online : une fuite de 469 169 fiches revendiquée
CJIS Online : une fuite de 469 169 fiches revendiquée en octobre 2026, avec des coordonnées de policiers américains.

Doc.png

ZATAZ dans le top 10 tech français : merci à vous !
Damien Bancal, ZATAZ, se classe 6e du Tyto Tech 500 France 2026, 2e journaliste et 1er sur les questions Cyber. Merci à tous ceux qui nous suivent.

Doc.png

KillSec démantelé, son opérateur présumé a 16 ans
KillSec démantelé : trois arrestations, 110 To sécurisés et un opérateur présumé de 16 ans, selon Europol.

Doc.png

Réseaux sociaux : les historiques qui deviennent des preuves
Affaire Bardella / Mediapart : historiques des réseaux sociaux. Comment des archives Messenger peuvent étayer une enquête et ses vérifications.

Doc.png

Facturation électronique : la premiére fuite de données confirmée !
Alerte VosFactures : échanges suspendus avec l’AIFE, obligations de facturation et risques liés aux prestataires.

Doc.png

Alaxione : une nouvelle vente de données revendiquée
Alaxione : une nouvelle vente revendique 16,2 millions de personnes. Le pirate me communique mes données !

Doc.png

Le pirate Storm affiche ses victimes sur une carte interactive !
Le pirate Storm affiche des cibles sur une carte interactive et recrute des affiliés en mode 2.0.

Doc.png

Everest menace de publier des données attribués à Securitas
Everest menace Securitas de publier des données liées à la vidéosurveillance.

Doc.png

Campus Cyber Summit 2026 : l’IA au cœur des choix cyber
Campus Cyber Summit 2026 à Lille : programme, IA, NIS 2, cyber assurance, OSINT et CTF.

Doc.png

Élections et ingérences : la CNIL ouvre le débat
Le 16 novembre 2026, la CNIL débattra du ciblage politique, de la désinformation et des ingérences électorales.

';--

Identity Leaked



Doc.png

Medela - 423,947 breached accounts
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consiste...

Doc.png

LimeLeads - 17,838,396 breached accounts
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including sta...

Doc.png

Burger King Russia - 3,155,792 breached accounts
In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024. Burger King Russia acknowledged the incident and advised it did not include payment...

Doc.png

Chess.com (2026) - 4,653,212 breached accounts
In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the ema...

Doc.png

McKesson - 6,404,340 breached accounts
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data...

Doc.png

Manchester Airports Group - 8,849,657 breached accounts
In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and...

Doc.png

Questel - 1,226,209 breached accounts
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M u...

Doc.png

Carhartt - 12,933,413 breached accounts
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained

Doc.png

NIUS - 6,090 breached accounts
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).

Doc.png

Golf Canada - 568,972 breached accounts
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.