LAPSUS$: AstraZeneca Breach
Sensitive data theft via a Cloud misconfiguration. Analysis of privileged access compromise.
I use Feedly every day to stay up to date in real time on new cyber threats and critical vulnerabilities.
Sensitive data theft via a Cloud misconfiguration. Analysis of privileged access compromise.
Using AI to create spear-phishing campaigns undetectable by traditional filters. Need for reinforced Endpoint defense.
Discovery of 0-day vulnerabilities in several enterprise VPN gateways. Priority on remote access patching.
DNS Hijacking campaign targeting public services. Importance of DNSSEC implementation.
The new security standard for connected devices in enterprise environments. Focus on strong authentication.
Surge in Ransomware attacks targeting unpatched ESXi hypervisors.
Record increase in DDoS attack power driven by IoT botnets. Layer 4 and 7 protection.
Analysis of new side-channel attacks impacting WPA3 security.
Phase-out of traditional VPNs in favor of the Zero Trust model in multi-site environments.
Retrospective on major cyberattacks and anticipation of new malicious encryption techniques.
CERT-FR analysis of the surge in ransomware targeting the healthcare sector. Focus on network segmentation.
Active exploitation of a Kerberos flaw allowing privilege escalation (Domain Admin). Urgent AD updating needed.
Overview of Denial of Service (DDoS) and phishing attempts during the event. Success of perimeter defense.
Technical analysis of remote code execution via SSL-VPN. Recommendation to transition to ZTNA.
International Operation "Cronos" against the infrastructure of the largest Ransomware-as-a-Service group.
Personal data theft affecting 43 million users. Analysis of exfiltration methods via agent access.