๐ Bloquer une app en รthiopie la bloque aussi en Palestine
Grรขce au Google Play Store 'Rest of the world'
Appli bloquรฉe en รthiopie = indisponible en Palestine
Saviez-vous qu'une application Android bloquรฉe en Afghanistan le sera aussi en Mauritanie ? Et qu'une application qui disparaรฎt du Google Play Store ร Madagascar sera indisponible au Kosovo ?
L'explication ici: open.substack.com/pub/coupecir...
28.07.2025 15:19 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
๐ง Fixes? Every critical and high-severity vuln was remediated through hotfixes. No action is required for Sophos Firewall customers to receive these fixes with the "Allow automatic installation of hotfixes" feature enabled on remediated versions.
25.07.2025 15:47 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐ VulnWatch Friday: CVE-2025-7624 ๐
In a July 21 security advisory, Sophos shared the patches for 5๏ธโฃ vulnerabilities affecting its products.
One of the two critical vulnerabilities, tracked as CVE-2025-7624 is an SQL injection in the legacy SMTP proxy of some Sophos Firewall versions.
25.07.2025 15:47 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Crush11wiki: CompromiseJuly2025
๐ The CrushFTP, LLC security advisory: www.crushftp.com/crush11wiki/...
๐ The Rapid7 blog post: www.rapid7.com/blog/post/cr...
๐พ Download JSON: cveawg.mitre.org/api/cve/CVE-...
23.07.2025 16:13 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
The vulnerability involves a mishandling of AS2 validation in all versions of CrushFTP servers prior to 10.8.5 and prior to 11.3.4_23.
When exploited, it allows remote attackers to obtain admin access via HTTPS.
๐ง Fix? CrushFTP 11.3.4_26 and CrushFTP 10.8.5_12.
23.07.2025 16:13 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐ง VulnWatch Wednesday: CVE-2025-54309 ๐
At least 10,000 CrushFTP instances are vulnerable to a critical flaw, which is currently being exploited by attackers, affecting the file transfer solution, according to @shadowserver.bsky.social and @rapid7.com.
www.infosecurity-magazine.com/news/crushft...
23.07.2025 16:13 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐ฌ Cognizant's response (part 2): "Clorox has tried to blame us for these failures, but the reality is that Clorox hired Cognizant for a narrow scope of help desk services which Cognizant reasonably performed.โ [4/4]
23.07.2025 15:33 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
In a statement sent to me, Cognizant denied being responsible for the cyber-attack.
๐ฌ Cognizant's response (part 1): "It is shocking that a corporation the size of Clorox had such an inept internal cybersecurity system to mitigate this attack." [3/4]
23.07.2025 15:33 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
In a lawsuit filed in California on July 22, Clorox accused Cognizant of being responsible for an attack that cost it months of operational disruption and at least $49m in expenses.
Cognizant allegedly handed over a password to the cybercriminal w/o asking any authentication questions. [2/4]
23.07.2025 15:33 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐๐๐ โ๏ธ The Clorox Company ๐๐ฎ๐๐ฌ Cognizant ๐๐จ๐ซ ๐๐๐ฎ๐ฌ๐ข๐ง๐ 2023 ๐๐ฒ๐๐๐ซ-๐๐ญ๐ญ๐๐๐ค
Clorox, a leading US producer of cleaning products, is suing its former IT service desk provider, London-based Cognizant, over the August 2023 cyber-attack. [1/4]
www.infosecurity-magazine.com/news/clorox-...
23.07.2025 15:33 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
The leak is believed to have been made possible by the compromise, via an infostealer, of a user account linked to a training organization based in Isรจre.
The attackers then gained access to Kairos, an app that enables training organizations to track the training progress of jobseekers. [2/2]
23.07.2025 15:22 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
๐
๐ซ๐๐ง๐๐ ๐ซ๐ท ๐๐๐ฐ ๐๐๐ญ๐ ๐๐ซ๐๐๐๐ก ๐๐จ๐ฎ๐ฅ๐ ๐๐๐๐๐๐ญ 340,000 ๐๐จ๐๐ฌ๐๐๐ค๐๐ซ๐ฌ
France Travail has suffered a data breach that could affect hundreds of thousands of jobseekers.
The breach was detected by the @anssi-fr.bsky.social's @cert-fr.bsky.social on July 12. [1/2]
www.infosecurity-magazine.com/news/france-...
23.07.2025 15:22 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
UPDATE 4/4 | 4๏ธโฃ I reached out to the Paris Police Prefecture to understand the profile of the suspected individual and to enquire about the Jabber server used to intercept communications. They declined to provide further details on the case at this time.
23.07.2025 15:18 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
UPDATE 3/4 | 3๏ธโฃ The involved Ukrainian and French law enforcement agencies have reportedly seized the XSS domains, although several cyber threat intelligence experts noted the site was still up at the time of writing.
23.07.2025 15:18 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
UPDATE 2/4 | 2๏ธโฃ The forumโs suspected administrator was not only a technical operator but is believed to have played a central role in enabling criminal activity.
๐ฌ"He arbitrated disputes between criminals and guaranteed the security of transactions," Europol noted.
23.07.2025 15:18 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
UPDATE 1/4 | 1๏ธโฃA Europol mobile office was deployed this week in Ukraine to support French and Ukrainian teams with on-site coordination and evidence collection.
2๏ธโฃ The name of the image in the Europol statement (see below) suggests that the operation's codename was Operation Ratatouille.
23.07.2025 15:18 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐๐๐ ๐ฎ ๐๐ฎ๐ฌ๐ฉ๐๐๐ญ๐๐ ๐๐๐ ๐
๐จ๐ซ๐ฎ๐ฆ ๐๐๐ฆ๐ข๐ง ๐๐ซ๐ซ๐๐ฌ๐ญ๐๐ ๐ข๐ง ๐๐ค๐ซ๐๐ข๐ง๐
A man suspected of administering the Russian-language cybercrime forum XSS was arrested in Ukraine on July 22.
๐ด The Ukrainian and French law enforcement agencies have also seized the XSS domains.
www.infosecurity-magazine.com/news/suspect...
23.07.2025 11:49 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐๐๐ ๐ ๐๐ก๐๐ซ๐๐๐จ๐ข๐ง๐ญ โ๐๐จ๐จ๐ฅ๐๐ก๐๐ฅ๐ฅโ ๐๐ฎ๐ฅ๐ง๐ฌ ๐๐ฑ๐ฉ๐ฅ๐จ๐ข๐ญ๐๐ ๐๐ฒ ๐๐ก๐ข๐ง๐๐ฌ๐ ๐๐๐๐ค๐๐ซ๐ฌ
Microsoft has observed three China-based threat actors, Linen Typhoon, Violet Typhoon and Storm-2603, exploiting the SharePoint vulnerabilities dubbed as 'ToolShell.'
www.infosecurity-magazine.com/news/sharepo...
22.07.2025 14:56 โ ๐ 0 ๐ 1 ๐ฌ 0 ๐ 0
Chinese Censorship: GreatFire Fights Back โ
Episode 02 of the FreeWeChat saga (Tencent/Group-IB vs @greatfire.org) in the latest edition of @coupecircuit.bsky.socialโคต๏ธ
Also covering the latest internet shutdown news: ๐ต๐ฐ๐ง๐ฉ๐ท๐บ๐น๐ฌ
21.07.2025 16:24 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
๐ VulnWatch Monday: CVE-2025-53770 ๐
CVE-2025-53770, aka 'ToolShell' is the talk of the cybersecurity-focused internet today!
Read the full Infosecurity Magazine analysis: www.infosecurity-magazine.com/news/microso...
๐พ Download JSON here: cveawg.mitre.org/api/cve/CVE-...
21.07.2025 16:15 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Z-ONE Premium Solutions - Google Drive
Z-ONE consulting made a large list of cybersecurity companies in China and gives a broad overview of the Chinese market: drive.google.com/drive/u/1/fo...
www.z1-sec.com/en/
21.07.2025 10:20 โ ๐ 2 ๐ 2 ๐ฌ 0 ๐ 0
Why is a respected Singapore-based cybersecurity company involved in a SLAPP lawsuit against a Chinese anti-censorship NGO?
In the new edition of @coupecircuit.bsky.social, I explore an intriguing case in which Tencent could be leveraging non-Chinese private companies to enforce censorship โฌ๏ธ
15.07.2025 10:03 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
PSIRT | FortiGuard Labs
None
๐ Fortinet's security advisory: fortiguard.fortinet.com/psirt/FG-IR-...
๐พ Download CVRF: fortiguard.fortinet.com/psirt/cvrf/F...
11.07.2025 14:41 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
๐ VulnWatch Friday: CVE-2025-25257 ๐
On July 8, 2025, Fortinet released fixes for a critical vulnerability in FortiWeb that could allow an unauthenticated threat actor to execute SQL commands via crafted HTTP or HTTPS requests.
No in-the-wild exploitation has been observed at the time of writing.
11.07.2025 14:41 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐๐๐ - ๐๐ข๐ค๐๐จ๐ค'๐ฌ ๐๐๐ง๐๐ฅ๐ข๐ง๐ ๐จ๐ ๐๐ ๐๐ฌ๐๐ซ ๐๐๐ญ๐ ๐ข๐ง ๐๐ก๐ข๐ง๐ ๐๐จ๐ฆ๐๐ฌ ๐๐ง๐๐๐ซ ๐๐๐ซ๐ฎ๐ญ๐ข๐ง๐ฒ... ๐๐ ๐๐ข๐ง
๐ช๐บ @dpcireland.bsky.social is launching of a new inquiry into TikTok's storage of European users' data on servers in China, just 2 months after it fined the company โฌ530m.
www.infosecurity-magazine.com/news/tiktok-...
10.07.2025 14:32 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
๐ฅท ๐๐ง๐ฆ๐๐ฌ๐ค๐ข๐ง๐ ๐ญ๐ก๐ ๐๐๐๐๐๐๐ฒ ๐๐๐ง๐ฌ๐จ๐ฆ๐ฐ๐๐ซ๐ ๐๐ซ๐จ๐ฎ๐ฉ ๐ฅท
I dived deeper into the ransomware group's tactics and attack patterns, victimology and its place within the cybercriminal ecosystem, including its ties with defunct and active groups.
www.infosecurity-magazine.com/news-feature...
10.07.2025 10:13 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Security Update Guide - Microsoft Security Response Center
๐ Microsoft's Patch Tuesday list of vulnerabilities: msrc.microsoft.com/update-guide...
๐พ Download JSON for CVE-2025-47981: cveawg.mitre.org/api/cve/CVE-...
09.07.2025 13:00 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Threat Intelligence Team Leader @ Wรผrth Group, CPENT/CEH/CND/CSA/ECSA, owner of SATAYO CTI platform & deepdarkCTI project - member of
@Curatedintel
Startup advisor & coach โ https://marcgg.com
Solopreneur โ https://shadowboxingapp.com
Previously: Director of Engineering BackMarket, VP Eng Europe Getaround, VP Eng Drivy
Rรฉalisatrice @OuvrirLaVoix #unehistoireasoi #Ballroom Autrice #unepoupeeenchocolat Confรฉrenciรจre Filmmaker/Writer/Speaker/Adoptee
https://www.france.tv/slash/ballroom-danser-pour-exister/
Fediverse developer, working on trust & safety tech, advisor to IFTAS; open-source contributor. I'm mostly on the Fediverse: https://hachyderm.io/@thisismissem ๐ณ๏ธโโง๏ธ๐ณ๏ธโ๐
Mostly posting via @thisismissem.hachyderm.io.ap.brid.gy
CDO chez MyGeorges & Owner PulsarEsport. Jโanime des รฉmissions Techโฆ Soon un nouveau podcastโฆ
Cyber Intelligence Analyst at RANE
Journaliste ร Bruxelles pour MLex. Auteur de 'Au coeur du lobbying europรฉen', une enquรชte sur le pouvoir des reprรฉsentants d'intรฉrรชts ร Bruxelles
https://www.msh.uliege.be/cms/c_17661998/fr/au-coeur-du-lobbying-europeen
Your favorite enterprise technology news vultures, flying high in the Bluesky โ On the web since 1998 โ More here: https://www.theregister.com/
Maison d'รฉdition engagรฉe, crรฉative et qui aime surprendre.
๐ https://arenes.fr/
Aggregating media employment opportunities since 2014 โข Host of 60+ media industry events. Sign up for our free weekly list: https://www.linkedin.com/newsletters/meojobs-of-the-week-7017523262062514176/
Academic working on digital citizenship, digital rights, digital authoritarianism, digital disinformation, civic tech, digital surveillance and all that jazz. Free typo with every post.
The fastest growing independent news network in the world. We cover breaking news, politics, law and more. We are unapologetically pro-democracy.
Applied Cybersecurity & Internet Governance (ISSN 2956-3119) is a peer-reviewed, open access journal published by Polish NASK National Research Institute.
#IoT #AI #hightech #cybersecurity
https://www.acigjournal.com/
I teach cryptography at Johns Hopkins. https://blog.cryptographyengineering.com
Innovation & Foresight @ CNIL (French Data Protection Authority) | teacher @SciencesPo | Bike, Music, Venezuela. #PersonalViews
WiFi intimidate turned rogue web server. A bunch of 1s and 0s. Red hue in #PurpleTeam. InfoSec Analyst #Security #Privacy #Education +๐ท+๐+๐น Views mine +5 pts. Creator/dev @cve-notifications.bsky.social
https://incredincomp.com