D
Cybersécurité : les Etats-Unis font fuiter leurs identifiants cloud

L'agence américaine de cybersécurité CISA a exposé publiquement ses identifiants cloud et mots de passe via un dépôt GitHub maintenu par un contractant. Cette fuite, qualifiée de "pire leak" jamais observé par les experts, révèle des défaillances majeures au cœur de l'appareil de défense cyber américain.

Attacken bei Signal und WhatsApp: Immer mehr Spuren beim Messenger-Phishing weisen auf Russland

Betroffen sind die Messenger WhatsApp und Signal. – Alle Rechte vorbehalten IMAGO / photothekSeit Monaten versuchen bislang unbekannte Angreifer, die Accounts von Personen aus Politik, Militär und Journalismus auf Messengern zu übernehmen. Eine Medienrecherche hat nun weitere Spuren entdeckt, die auf eine russische Urheberschaft hinweisen.

N
Trump’s Civil Service Cuts Are Now Putting Americans in Danger

As the United States continues to pursue war with Iran, the infrastructure that would have helped respond to threats has been hollowed out by the Trump administration’s efforts to dramatically shrink the federal government. The overall loss in institutional knowledge wrought by massive personnel cuts and other efforts to decimate the civil service might not just affect the future of this war, it…

Read more →
Chromeにゼロデイ脆弱性、Googleが緊急対処

修正前から攻撃されていた。世界で最も使われているウェブブラウザで、すでに実環境で悪用が確認された脆弱性が見つかりました。Googleは3月12日と13日、Chromeに存在する2件のゼロデイ脆弱性に対処する緊急セキュリティアップデートを公開しました。Chrome利用者は世界で約3...

[smhn.infoにアクセスすると、全文を読むことができます。

](https://smhn.info/202603-google-chrome-two-zero-day-vulnerabilities-emergency-update)

Why zero trust breaks down in IoT and OT environments

Zero trust solves the wrong problem in OT

Zero trust has become the dominant security narrative of the past decade, and rightly so. Its core principles, never trust, always verify; assume breach; enforce least privilege, have reshaped how organizations think about identity, access and lateral movement. In enterprise IT environments, these principles have produced measurable gains. Identity is…

Read more →
February’s Patch Tuesday release fixes 59 flaws, including 6 being exploited

Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company’s Patch Tuesday release for February addresses 59 CVEs across the company’s product family — roughly half the volume of January’s 159 patches.

Six vulnerabilities, affecting Windows Shell, MSHTML, Desktop Window Manager, Remote Desktop, Remote…

Read more →
Page 1