Bulletins d'actualité
De Docaposte Cyberdéfense
Révision datée du 6 mars 2018 à 00:06 par Scarpentier (discussion | contributions)
Classification
SommaireUndernews |
|
Flare lance « Darkroom », un laboratoire de formation immersif et gratuit dédié au renseignement sur le Dark Web
Flare, expert du renseignement sur les cybermenaces axées sur l’identité, annonce le lancement de Darkroom by Flare Academy, une plateforme de formation interactive et gratuite qui offre aux professionnels de la sécurité, aux analystes et aux étudiants de se familiariser, en conditions immersives, avec les écosystèmes clandestins qu’ils sont amenés à surveiller et à combattre. […] The post
|
| Offensive Security’s Exploit Database |
|
[remote] PCMan 2.0.7 - Buffer Overflow
PCMan 2.0.7 - Buffer Overflow
|
|
[dos] NanaZip 6.5 - DoS
NanaZip 6.5 - DoS
|
|
[webapps] flyto-core 2.26.7 - Arbitrary File Write
flyto-core 2.26.7 - Arbitrary File Write
|
|
[webapps] Nodemailer 9.0.0 - File Read/ SSRF
Nodemailer 9.0.0 - File Read/ SSRF
|
|
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
Linuxfabrik monitoring_plugins_6.0.0 - SSRF
|
|
[dos] NanaZip 6.5 - DoS
NanaZip 6.5 - DoS
|
|
[webapps] flyto_core 2.26.7 - Server-Side Request Forgery
flyto_core 2.26.7 - Server-Side Request Forgery
|
|
[webapps] Probo 0.222.2 - IDOR
Probo 0.222.2 - IDOR
|
|
[webapps] webpack_devserver 5.2.5 - CSRF
webpack_devserver 5.2.5 - CSRF
|
|
[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
phpSysInfo 3.4.5 - IP Allowlist Bypass
|
Dark Reading |
Impossible de charger le flux RSS de https://www.darkreading.com/rss_simple.asp : Il y a eu un problème lors de la requête HTTP : 403 Forbidden
ZATAZ |
|
Club One Casino revendiqué par 3AM puis PEAR
Hack Twins : Un nouveau casino apparaît chez deux groupes de pirates informatiques différents.
|
|
Fuite Stripe : au moins 200 Français concernés
Fuite Stripe : ZATAZ confirme au moins 200 Français concernés et propose une vérification gratuite et humaine.
|
|
Stripe visé par une fuite revendiquée de 662 bases de données !
Stripe est visé par une fuite revendiquée avec, selon le pirate, clés API et des données clients sensibles.
|
|
Éducation nationale : le ministère confirme le piratage
Aprés le Ministére des Finances, le Ministére de l'Éducation confirme un piratage de son informatique. Maintenant à savoir si les informations diffusées par le pirate sont vraies.
|
|
Intraverse : 16,9 millions d’entrées exposées
Un casino en ligne aurait exposé 16,9 millions d’entrées, révélant joueurs, bots, portefeuilles et infrastructure Web3.
|
|
Belgique : 148 251 profils exposés par un pirate
Une base belge piratée de 148 251 profils, avec IBAN et données personnelles, aurait été exposée selon un pirate sans authentification.
|
|
SpyGuard et MVT traquent les spywares mobiles
SpyGuard et MVT aident à rechercher des traces de spyware sur smartphones grâce au réseau et à l’analyse forensique.
|
|
Fuite fiscale, pas de panique !
Fuite DGFiP : pas de panique. Pourquoi vos réactions publiques peuvent aider les pirates à cibler leurs futures campagnes de phishing.
|
|
Éducation nationale : un pirate annonce une fuite qui exposerait des millions de données
Un pirate informatique revendiqué une intrusion dans des systèmes de l’Éducation nationale : élèves et enseignants impactés ?
|
|
Cyberharcèlement : la Belgique prépare un bannissement numérique
La Belgique prépare un bannissement numérique contre le cyberharcèlement, avec identification judiciaire et contrôle des comptes.
|
';-- |
Identity Leaked |
|
Oz Hair and Beauty - 1,988,331 breached accounts
In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.
|
|
Fanlore - 144,520 breached accounts
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.
|
|
RingCentral - 1,596,490 breached accounts
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers.
|
| Alcon - 218,395 breached accounts
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.
|
|
Brinks Home - 732,162 breached accounts
In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data a...
|
|
Exact Sciences - 10,869,543 breached accounts
In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and heal...
|
|
Inter-Con Security - 276,114 breached accounts
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.
|
|
SplitVPN - 865,336 breached accounts
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
|
|
Houston City College - 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.
|
|
Suno - 55,282,226 breached accounts
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe record...
|
