FACTUALRISK Cyber Intelligence
Mise à jour : 29 May 2026 · 18:02
← Accueil
🗞 Briefing🛡 Dashboard💥 Attaques🔧 Patches🦠 Ransomware📡 Exploitation🌍 Géopolitique🕵️ Acteurs Supply Chain🎯 IOC Tracker📋 Compliance📰 News📈 Statistiques
← Retour FactualRisk
Total incidents
40
Critique
4
Élevé
0
APT actifs
2
Domaine
Catégorie
Sévérité
Visible : 40
🟢 il y a 16h SecurityWeek
The notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April. The post Charter Communications Data Breach…
🟢 il y a 16h TheHackerNews
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following t…
🔗 CVEs liés : CVE-2026-39987
MODÉRÉ Phishing
🟢 il y a 16h SecurityWeek
MokN's platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse o…
🟢 il y a 16h BleepingComputer
DDoS attacks are increasingly being sold like subscription services, complete with pricing tiers, support, and reseller programs. Flare explores how the DDoS-as…
🟢 il y a 16h BleepingComputer
Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. […
🟢 il y a 16h SecurityWeek
The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with…
🟢 il y a 16h BleepingComputer
Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account ta…
🟢 il y a 16h RecordedFuture
Each vulnerability was published with working proof-of-concept code to the Microsoft-owned code repository GitHub, making them immediately available to both att…
🟢 il y a 16h TheHackerNews
A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities sinc…
🟢 il y a 16h SecurityWeek
Attorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March. The post Calif…
🟢 il y a 16h TheHackerNews
Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full applications with AI, wiring…
🟢 il y a 16h SecurityWeek
The browser update resolves critical-severity security defects that could potentially lead to remote code execution. The post Chrome 148 Update Patches 151 V…
🟢 il y a 16h BleepingComputer
A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based…
🟢 il y a 16h TheHackerNews
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest cooper…
🟢 il y a 16h BleepingComputer
The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April,…
🟢 il y a 16h Securelist
What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspe…
🟢 il y a 16h TheHackerNews
The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean …
🟢 il y a 16h BleepingComputer
Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private …
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans Centreon Web. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et u…
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges,…
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de pri…
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de pr…
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbi…
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à dis…
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de p…
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de …
🟢 il y a 16h CERT-FR
De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié …
MODÉRÉ APT
🟢 il y a 16h Exploit-DB
Microsoft - NTLMv2 Hash Capture
🟡 hier BleepingComputer
A likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools. [...]
🟡 hier BleepingComputer
An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. [.…
🟡 hier SecurityWeek
Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will op…
🟡 hier BleepingComputer
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented cred…
🔗 CVEs liés : CVE-2026-35616
🟡 hier TheHackerNews
A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitr…
🟡 hier SecurityWeek
The funding round was led by Balderton Capital, with additional support from Crosspoint Capital and previous investors General Catalyst and Ten Eleven Ventures.…
🟡 hier TheHackerNews
Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver cred…
🟡 hier SecurityWeek
Data breach leaves nearly 6 million Carnival customers navigating identity theft risks. The post Carnival Data Breach Exposed 6 Million People appeared firs…
🟡 hier BleepingComputer
An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. [.…
🟡 hier BleepingComputer
MSPs don't lack security data. They struggle to separate real threats from alert noise. Kaseya explains how SIEM helps MSPs improve visibility, reduce fatigue, …
🟡 hier TheHackerNews
Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected …
🟡 hier TheHackerNews
Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installe…