Bulletins d'actualité
De Docaposte Cyberdéfense
Révision datée du 5 mars 2018 à 15:32 par Scarpentier (discussion | contributions)
Classification
{{#widget:Tweeter|user=perfplanet|id=353950675882885120}}
Offensive Security’s Exploit Database |
|
[remote] Teltonika_RutOS 00.07.06.21 - command injection
Teltonika_RutOS 00.07.06.21 - command injection
|
|
[webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write
TigerGraph_Community_Edition 4.2.4 - arbitrary file write
|
|
[webapps] WordPress 7.0.2 - Path Travesal
WordPress 7.0.2 - Path Travesal
|
|
[webapps] Food-Ordering 1.0 - LFI
Food-Ordering 1.0 - LFI
|
|
[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE
Ecava_ntegraXor IGX_16.0.701.10 - RCE
|
|
[webapps] Krayin CRM 2.2.4 - IDOR
Krayin CRM 2.2.4 - IDOR
|
|
[webapps] SuiteCRM 8.10.1 - Authenticated SSRF
SuiteCRM 8.10.1 - Authenticated SSRF
|
|
[webapps] InvoicePlane 1.7.1 - RCE
InvoicePlane 1.7.1 - RCE
|
|
[webapps] POMS oretnom23v1.0 - SQLi vulnerabilities
POMS oretnom23v1.0 - SQLi vulnerabilities
|
|
[remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE
MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE
|
Dark Reading |
Impossible de charger le flux RSS de https://www.darkreading.com/rss_simple.asp : Il y a eu un problème lors de la requête HTTP : 403 Forbidden
ZATAZ |
|
ZATAZ dans le top 10 tech français : merci à vous !
Damien Bancal, ZATAZ, se classe 6e du Tyto Tech 500 France 2026, 2e journaliste et 1er sur les questions Cyber. Merci à tous ceux qui nous suivent.
|
|
KillSec démantelé, son opérateur présumé a 16 ans
KillSec démantelé : trois arrestations, 110 To sécurisés et un opérateur présumé de 16 ans, selon Europol.
|
|
Réseaux sociaux : les historiques qui deviennent des preuves
Affaire Bardella / Mediapart : historiques des réseaux sociaux. Comment des archives Messenger peuvent étayer une enquête et ses vérifications.
|
|
Facturation électronique : la premiére fuite de données confirmée !
Alerte VosFactures : échanges suspendus avec l’AIFE, obligations de facturation et risques liés aux prestataires.
|
|
Alaxione : une nouvelle vente de données revendiquée
Alaxione : une nouvelle vente revendique 16,2 millions de personnes. Le pirate me communique mes données !
|
|
Le pirate Storm affiche ses victimes sur une carte interactive !
Le pirate Storm affiche des cibles sur une carte interactive et recrute des affiliés en mode 2.0.
|
|
Everest menace de publier des données attribués à Securitas
Everest menace Securitas de publier des données liées à la vidéosurveillance.
|
|
Campus Cyber Summit 2026 : l’IA au cœur des choix cyber
Campus Cyber Summit 2026 à Lille : programme, IA, NIS 2, cyber assurance, OSINT et CTF.
|
|
Élections et ingérences : la CNIL ouvre le débat
Le 16 novembre 2026, la CNIL débattra du ciblage politique, de la désinformation et des ingérences électorales.
|
|
Fuite de données : le guide interactif de ZATAZ
Fuite de données : ZATAZ propose un guide interactif pour sécuriser ses comptes et organiser ses démarches jusqu’à 90 jours.
|
';-- |
Identity Leaked |
|
Medela - 423,947 breached accounts
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consiste...
|
|
LimeLeads - 17,838,396 breached accounts
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including sta...
|
|
Burger King Russia - 3,155,792 breached accounts
In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024. Burger King Russia acknowledged the incident and advised it did not include payment...
|
|
Chess.com (2026) - 4,653,212 breached accounts
In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the ema...
|
|
McKesson - 6,404,340 breached accounts
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data...
|
|
Manchester Airports Group - 8,849,657 breached accounts
In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and...
|
|
Questel - 1,226,209 breached accounts
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M u...
|
|
Carhartt - 12,933,413 breached accounts
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained
|
| NIUS - 6,090 breached accounts
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).
|
|
Golf Canada - 568,972 breached accounts
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
|
