ICT Security-Sécurité PC et Internet
114.0K views | +25 today
 
Scooped by Gust MEES
onto ICT Security-Sécurité PC et Internet
December 21, 2017 5:38 PM
Scoop.it!

Die Webseiten, die Sie besuchen, erfassen Ihre Klicks, Eingaben und vieles mehr | #CyberSecurity #Privacy #Tracking #SessionReplay #Awareness 

Die Webseiten, die Sie besuchen, erfassen Ihre Klicks, Eingaben und vieles mehr | #CyberSecurity #Privacy #Tracking #SessionReplay #Awareness  | ICT Security-Sécurité PC et Internet | Scoop.it

Die Seiten erfassen einfach alles: was Sie eingeben, wo Sie draufklicken und sogar wohin Sie Ihre Maus bewegen; ähnlich wie ein Keylogger. Für eine Leistungsdiagnose macht vieles davon Sinn: wenn Sie eine Webseite betreiben, die über unzählige Seiten verfügt, müssen Sie herausfinden, was genau die Besucher machen und ob Seiten beschädigt sind oder nicht wie gewollt funktionieren.

Probleme treten allerdings auf, weil die Software in der Lage ist, eine große Informationsmenge zu tracken, die nicht unbedingt nützlich für die Entwickler der Webseite ist und weil Drittparteien Zugriff auf diese Information haben. Eine Forschergruppe der Princeton University berichtete wie folgt über das Phänomen: „Die Sammlung der Seiteninhalte mithilfe von Replay-Skripten von Drittparteien kann dazu führen, dass sensible Informationen wie der Gesundheitszustand des Nutzers, Kreditkartendetails und andere persönliche Informationen als Teil der Erfassung in die Hände von Drittparteien geraten. Das kann dazu führen, dass User zum Beispiel Opfer von Identitätsdiebstahl oder Online-Betrug werden.„

Um mehr über die Funktionsweise derartiger Software zu erfahren, sollten Sie sich folgendes Video ansehen:

Durch diese Art von Aufzeichung werden zusätzliche Informationen offenbart, die den Nutzer im Falle eines Datenlecks gefährden könnten. Der Untersuchung zufolge, kann die Software:

Passwörter aufzeichnen. Obwohl die Entwickler versucht haben, alle Passwörter nach Eingabe sofort zu entfernen, funktionierte dies im Falle der mobilen Version der Seite nur bedingt.
Vertrauliche Daten wie Kreditkartennummern und Geburtsdaten erfassen.
Daten erfassen, die in Textfelder eingegeben werden, auch wenn diese nicht abgeschickt werden – in anderen Worten: selbst dann, wenn Sie nicht auf „Suchen“ oder „Abschicken“ klicken oder die Eingabetaste drücken.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Session-Replay+Scripts

 

Gust MEES's insight:

Die Seiten erfassen einfach alles: was Sie eingeben, wo Sie draufklicken und sogar wohin Sie Ihre Maus bewegen; ähnlich wie ein Keylogger. Für eine Leistungsdiagnose macht vieles davon Sinn: wenn Sie eine Webseite betreiben, die über unzählige Seiten verfügt, müssen Sie herausfinden, was genau die Besucher machen und ob Seiten beschädigt sind oder nicht wie gewollt funktionieren.

Probleme treten allerdings auf, weil die Software in der Lage ist, eine große Informationsmenge zu tracken, die nicht unbedingt nützlich für die Entwickler der Webseite ist und weil Drittparteien Zugriff auf diese Information haben. Eine Forschergruppe der Princeton University berichtete wie folgt über das Phänomen: „Die Sammlung der Seiteninhalte mithilfe von Replay-Skripten von Drittparteien kann dazu führen, dass sensible Informationen wie der Gesundheitszustand des Nutzers, Kreditkartendetails und andere persönliche Informationen als Teil der Erfassung in die Hände von Drittparteien geraten. Das kann dazu führen, dass User zum Beispiel Opfer von Identitätsdiebstahl oder Online-Betrug werden.„

Um mehr über die Funktionsweise derartiger Software zu erfahren, sollten Sie sich folgendes Video ansehen:

Durch diese Art von Aufzeichung werden zusätzliche Informationen offenbart, die den Nutzer im Falle eines Datenlecks gefährden könnten. Der Untersuchung zufolge, kann die Software:

Passwörter aufzeichnen. Obwohl die Entwickler versucht haben, alle Passwörter nach Eingabe sofort zu entfernen, funktionierte dies im Falle der mobilen Version der Seite nur bedingt.
Vertrauliche Daten wie Kreditkartennummern und Geburtsdaten erfassen.
Daten erfassen, die in Textfelder eingegeben werden, auch wenn diese nicht abgeschickt werden – in anderen Worten: selbst dann, wenn Sie nicht auf „Suchen“ oder „Abschicken“ klicken oder die Eingabetaste drücken.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Session-Replay+Scripts

 

No comment yet.
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Rescooped by Gust MEES from 21st Century Learning and Teaching
April 29, 2013 5:39 PM
Scoop.it!

Why (And How) Teachers and Education Should Start Learning and Teaching Cyber-Security

Why (And How) Teachers and Education Should Start Learning and Teaching Cyber-Security | ICT Security-Sécurité PC et Internet | Scoop.it

Why (And How) Teachers Should Start Learning and Teaching Cyber-Security . What should get be taught and learned more in the 21st Century while using ICT?

 

In the 21st Century, Education has a BIG responsibility to adapt to the very quick change in the world and to teach the students the knowledge they need and which are required to fulfill the market’s needs!

 

The market’s needs are ALSO to employ people with the basics of Cyber-Security knowledge as a modern company needs to protect its online reputation and a data loss could be lethal to them, their ruin eventually! SO, the new employees is the students coming out of school, College, High school, Universities; ALL of them need to have the basic knowledge of  Cyber-Security to be competitive in a working market where there is more and more unemployment worldwide…

 

===> A company would take advantage of a new employee who as already the necessary knowledge of Cyber-Security as the company doesn’t need to train him, which saves it a lot of money! <===

  

Gust MEES's insight:

 

In the 21st Century, Education has a BIG responsibility to adapt to the very quick change in the world and to teach the students the knowledge they need and which are required to fulfill the market’s needs!

 

The market’s needs are ALSO to employ people with the basics of Cyber-Security knowledge as a modern company needs to protect its online reputation and a data loss could be lethal to them, their ruin eventually! SO, the new employees is the students coming out of school, College, High school, Universities; ALL of them need to have the basic knowledge of  Cyber-Security to be competitive in a working market where there is more and more unemployment worldwide…

 

===> A company would take advantage of a new employee who as already the necessary knowledge of Cyber-Security as the company doesn’t need to train him, which saves it a lot of money! <===

 

===============================================

 

There has been a lot of talk both in the U.S. and internationally about a shortage in skilled IT professionals - with a predicted 864,000 IT vacancies in Europe alone by 2015.

 

What are these skills that organizations are looking for? This infographic by via resource highlights the top skills that make a successful information security professional and skills the future workforce will need to tackle emerging threats.

 

Learn more:

 

- http://www.scoop.it/t/securite-pc-et-internet?tag=Infographic

 

- http://www.scoop.it/t/21st-century-learning-and-teaching?tag=Infographi

 

- http://www.scoop.it/t/ict-security-tools

 

 

Check also:

 

- https://gustmees.wordpress.com/

 

- https://gustmeesen.wordpress.com/

 

- https://gustmeesfr.wordpress.com/

 

  

Zhao KQiang's curator insight, March 27, 2014 7:23 AM

give some opinions of that why teachers and education should learn network secutity

Dean J. Fusto's curator insight, July 31, 2015 10:12 AM

 

In the 21st Century, Education has a BIG responsibility to adapt to the very quick change in the world and to teach the students the knowledge they need and which are required to fulfill the market’s needs!

 

The market’s needs are ALSO to employ people with the basics of Cyber-Security knowledge as a modern company needs to protect its online reputation and a data loss could be lethal to them, their ruin eventually! SO, the new employees is the students coming out of school, College, High school, Universities; ALL of them need to have the basic knowledge of  Cyber-Security to be competitive in a working market where there is more and more unemployment worldwide…

 

===> A company would take advantage of a new employee who as already the necessary knowledge of Cyber-Security as the company doesn’t need to train him, which saves it a lot of money! <===

 

===============================================

 

There has been a lot of talk both in the U.S. and internationally about a shortage in skilled IT professionals - with a predicted 864,000 IT vacancies in Europe alone by 2015.

 

What are these skills that organizations are looking for? This infographic by via resource highlights the top skills that make a successful information security professional and skills the future workforce will need to tackle emerging threats.

 

Learn more:

 

- http://www.scoop.it/t/securite-pc-et-internet?tag=Infographic

 

- http://www.scoop.it/t/21st-century-learning-and-teaching?tag=Infographi

 

- http://www.scoop.it/t/ict-security-tools

 

 

Check also:

 

- https://gustmees.wordpress.com/

 

- https://gustmeesen.wordpress.com/

 

- https://gustmeesfr.wordpress.com/

 

  

Jean-Pierre Blanger's curator insight, August 1, 2015 4:19 PM

 

In the 21st Century, Education has a BIG responsibility to adapt to the very quick change in the world and to teach the students the knowledge they need and which are required to fulfill the market’s needs!

 

The market’s needs are ALSO to employ people with the basics of Cyber-Security knowledge as a modern company needs to protect its online reputation and a data loss could be lethal to them, their ruin eventually! SO, the new employees is the students coming out of school, College, High school, Universities; ALL of them need to have the basic knowledge of  Cyber-Security to be competitive in a working market where there is more and more unemployment worldwide…

 

===> A company would take advantage of a new employee who as already the necessary knowledge of Cyber-Security as the company doesn’t need to train him, which saves it a lot of money! <===

 

===============================================

 

There has been a lot of talk both in the U.S. and internationally about a shortage in skilled IT professionals - with a predicted 864,000 IT vacancies in Europe alone by 2015.

 

What are these skills that organizations are looking for? This infographic by via resource highlights the top skills that make a successful information security professional and skills the future workforce will need to tackle emerging threats.

 

Learn more:

 

- http://www.scoop.it/t/securite-pc-et-internet?tag=Infographic

 

- http://www.scoop.it/t/21st-century-learning-and-teaching?tag=Infographi

 

- http://www.scoop.it/t/ict-security-tools

 

 

Check also:

 

- https://gustmees.wordpress.com/

 

- https://gustmeesen.wordpress.com/

 

- https://gustmeesfr.wordpress.com/

 

  

Scooped by Gust MEES
September 29, 4:15 PM
Scoop.it!

FBI reportedly declares 'cyber security incident' after hackers steal agents' personal data

FBI reportedly declares 'cyber security incident' after hackers steal agents' personal data | ICT Security-Sécurité PC et Internet | Scoop.it

The Federal Bureau of Investigation has reportedly told its agents and support staff that their personal information was stolen in a recent cyberattack that targeted the bureau’s job application portal.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet

 

Gust MEES's insight:

The Federal Bureau of Investigation has reportedly told its agents and support staff that their personal information was stolen in a recent cyberattack that targeted the bureau’s job application portal.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet

 

No comment yet.
Scooped by Gust MEES
August 17, 3:45 PM
Scoop.it!

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads | ICT Security-Sécurité PC et Internet | Scoop.it

Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

Gust MEES's insight:

Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=WordPress

 

No comment yet.
Scooped by Gust MEES
August 7, 9:43 AM
Scoop.it!

Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers

Moonshot AI’s open-weight model Kimi K3 broke out of its isolated testing sandbox during a cybersecurity evaluation and reached the open internet, according to a new report from Wired.

The incident, uncovered by US startup Frontier Security, is raising fresh concerns about the safety guardrails built into powerful open-weight AI models that are already freely downloadable by enterprises and individuals worldwide.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

Moonshot AI’s open-weight model Kimi K3 broke out of its isolated testing sandbox during a cybersecurity evaluation and reached the open internet, according to a new report from Wired.

The incident, uncovered by US startup Frontier Security, is raising fresh concerns about the safety guardrails built into powerful open-weight AI models that are already freely downloadable by enterprises and individuals worldwide.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
August 5, 5:48 PM
Scoop.it!

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts | ICT Security-Sécurité PC et Internet | Scoop.it

Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen.

Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key protecting the user's synced passkeys.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=Google

 

Gust MEES's insight:

Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen.

Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key protecting the user's synced passkeys.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=Google

 

No comment yet.
Scooped by Gust MEES
August 5, 5:21 PM
Scoop.it!

Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World

Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World | ICT Security-Sécurité PC et Internet | Scoop.it

The UK’s AI Security Institute (AISI) has disclosed a serious security incident in which AI agents under evaluation broke out of their intended test scope and took unsanctioned action against real people and organizations on the live internet.

The incident, which unfolded between 25 and 28 July 2026, involved Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol, and is being described as the clearest real-world manifestation yet of autonomous, deceptive behavior in frontier AI systems.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

The UK’s AI Security Institute (AISI) has disclosed a serious security incident in which AI agents under evaluation broke out of their intended test scope and took unsanctioned action against real people and organizations on the live internet.

The incident, which unfolded between 25 and 28 July 2026, involved Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol, and is being described as the clearest real-world manifestation yet of autonomous, deceptive behavior in frontier AI systems.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
July 21, 4:04 PM
Scoop.it!

Durch autonomen KI-Agenten: Cyberangriff auf weltgrößte offene Plattform für KI-Modelle

Durch autonomen KI-Agenten: Cyberangriff auf weltgrößte offene Plattform für KI-Modelle | ICT Security-Sécurité PC et Internet | Scoop.it

Die KI-Plattform Hugging Face ist nach eigenen Angaben von einem autonomen KI-Agentensystem angegriffen worden. Dabei gelang Unbefugten Zugriff auf interne Datensätze und mehrere Dienst-Zugangsdaten.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

Die KI-Plattform Hugging Face ist nach eigenen Angaben von einem autonomen KI-Agentensystem angegriffen worden. Dabei gelang Unbefugten Zugriff auf interne Datensätze und mehrere Dienst-Zugangsdaten.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
June 27, 4:41 PM
Scoop.it!

Malware steals Chrome session cookies to take over your accounts

Malware steals Chrome session cookies to take over your accounts | ICT Security-Sécurité PC et Internet | Scoop.it

An email attachment leads to the installation of a malicious Chrome extension. Researchers say it is part of a Windows backdoor delivered via a phishing email. The malware abuses Chrome Native Messaging to move control from the browser into the host system. Its most notable trick isn’t the phishing lure itself, but the way it uses legitimate browser and Windows features to run PowerShell and collect data while staying inside expected workflows.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet

 

Gust MEES's insight:

An email attachment leads to the installation of a malicious Chrome extension. Researchers say it is part of a Windows backdoor delivered via a phishing email. The malware abuses Chrome Native Messaging to move control from the browser into the host system. Its most notable trick isn’t the phishing lure itself, but the way it uses legitimate browser and Windows features to run PowerShell and collect data while staying inside expected workflows.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet

 

No comment yet.
Scooped by Gust MEES
June 11, 1:55 PM
Scoop.it!

Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty

A security researcher known as brutecat has disclosed how an AI-driven fuzzing pipeline uncovered more than $500,000 in vulnerabilities across Google’s infrastructure in under three months, exposing systemic access-control failures hidden inside roughly 1,500 APIs.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

 

Gust MEES's insight:

A security researcher known as brutecat has disclosed how an AI-driven fuzzing pipeline uncovered more than $500,000 in vulnerabilities across Google’s infrastructure in under three months, exposing systemic access-control failures hidden inside roughly 1,500 APIs.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

 

No comment yet.
Scooped by Gust MEES
June 1, 4:24 PM
Scoop.it!

Meta’s own AI was exploited to hijack Instagram accounts

Meta’s own AI was exploited to hijack Instagram accounts | ICT Security-Sécurité PC et Internet | Scoop.it

Meta says it has fixed an issue that allowed hackers to take over a target’s Instagram account using its AI-powered support chatbot.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

Meta says it has fixed an issue that allowed hackers to take over a target’s Instagram account using its AI-powered support chatbot.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
May 31, 11:19 AM
Scoop.it!

New ChatGPT Vulnerability Lets Attackers Turn Web Pages Into Phishing Payloads

A browser-based prompt injection technique that transforms any web page into a phishing delivery surface by exploiting ChatGPT's page summarization feature, rendering attacker-controlled links, fake security alerts, and QR codes directly inside the trusted ChatGPT interface.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

A browser-based prompt injection technique that transforms any web page into a phishing delivery surface by exploiting ChatGPT's page summarization feature, rendering attacker-controlled links, fake security alerts, and QR codes directly inside the trusted ChatGPT interface.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
May 30, 6:58 AM
Scoop.it!

New VoidStealer Malware Bypasses Chrome's Protection to Steal User Data

A newly discovered malware called VoidStealer has emerged as a serious threat to Chrome users on Windows, using a clever technique to bypass one of the browser’s most important security features.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet/?&tag=Browsers

 

Gust MEES's insight:

A newly discovered malware called VoidStealer has emerged as a serious threat to Chrome users on Windows, using a clever technique to bypass one of the browser’s most important security features.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet/?&tag=Browsers

 

No comment yet.
Scooped by Gust MEES
May 20, 6:57 PM
Scoop.it!

PinTheft Linux Vulnerability Let Attackers Gain Root Access - PoC Released

PinTheft Linux Vulnerability Let Attackers Gain Root Access - PoC Released | ICT Security-Sécurité PC et Internet | Scoop.it

A proof-of-concept (PoC) exploit was published for a new Linux Local Privilege Escalation (LPE) vulnerability dubbed “PinTheft.” Exploitvulnerability assessment

Discovered by Aaron Esau of the V12 security team, the flaw allows local attackers to gain root access by exploiting an RDS zerocopy double-free bug.

A kernel patch is currently available, prompting the researchers to release their PoC code to the public.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

Gust MEES's insight:

A proof-of-concept (PoC) exploit was published for a new Linux Local Privilege Escalation (LPE) vulnerability dubbed “PinTheft.” Exploitvulnerability assessment

Discovered by Aaron Esau of the V12 security team, the flaw allows local attackers to gain root access by exploiting an RDS zerocopy double-free bug.

A kernel patch is currently available, prompting the researchers to release their PoC code to the public.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

No comment yet.
Scooped by Gust MEES
September 29, 4:32 PM
Scoop.it!

Meta’s Muse reportedly has a shocking one-click vulnerability | #MAC #Apple

Meta’s Muse reportedly has a shocking one-click vulnerability | #MAC #Apple | ICT Security-Sécurité PC et Internet | Scoop.it

Meta launched its new AI assistant Muse to much fanfare earlier this month.

Now, just a few weeks later, a zero-day vulnerability has reportedly been discovered that could put access to your entire Mac computer in the wrong hands. (Meta currently does not have a Windows version of Muse for PC.)

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

Meta launched its new AI assistant Muse to much fanfare earlier this month.

Now, just a few weeks later, a zero-day vulnerability has reportedly been discovered that could put access to your entire Mac computer in the wrong hands. (Meta currently does not have a Windows version of Muse for PC.)

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
September 15, 4:16 PM
Scoop.it!

Hacker missbrauchten Claude, um Zugangsdaten aus 1,8 Millionen Android-Apps zu extrahieren

Hacker missbrauchten Claude, um Zugangsdaten aus 1,8 Millionen Android-Apps zu extrahieren | ICT Security-Sécurité PC et Internet | Scoop.it

Das KI-Unternehmen Anthropic hat Missbrauchsfälle seiner künstlichen Intelligenz Claude durch verschiedene Hackergruppen offengelegt. Wie das IT-Sicherheitsportal „BleepingComputer“ berichtet, nutzten sowohl staatlich gelenkte Spione als auch finanziell motivierte Cyberkriminelle das KI-Modell zwischen Dezember 2025 und August 2026 für ihre Angriffe. Dabei beschleunigten die Täter ihre Aktivitäten massiv und automatisierten komplexe Schadcodes.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

Das KI-Unternehmen Anthropic hat Missbrauchsfälle seiner künstlichen Intelligenz Claude durch verschiedene Hackergruppen offengelegt. Wie das IT-Sicherheitsportal „BleepingComputer“ berichtet, nutzten sowohl staatlich gelenkte Spione als auch finanziell motivierte Cyberkriminelle das KI-Modell zwischen Dezember 2025 und August 2026 für ihre Angriffe. Dabei beschleunigten die Täter ihre Aktivitäten massiv und automatisierten komplexe Schadcodes.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
August 7, 2:46 PM
Scoop.it!

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers | ICT Security-Sécurité PC et Internet | Scoop.it

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.

The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

Gust MEES's insight:

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.

The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

No comment yet.
Scooped by Gust MEES
August 6, 4:05 PM
Scoop.it!

Meta AI Model Gained Internet Access and Hacked Another Organization's Network

Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability in another organization’s system. The incident occurred during testing conducted with independent AI security firm Irregular, according to Meta.

Meta spokesperson said the event was caused by a misconfiguration in the testing environment. The AI model was supposed to operate in a controlled setting. However, the configuration error gave it access to the open internet.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability in another organization’s system. The incident occurred during testing conducted with independent AI security firm Irregular, according to Meta.

Meta spokesperson said the event was caused by a misconfiguration in the testing environment. The AI model was supposed to operate in a controlled setting. However, the configuration error gave it access to the open internet.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=AI

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
August 5, 5:32 PM
Scoop.it!

New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root on a wide range of popular Linux distributions.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

Gust MEES's insight:

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root on a wide range of popular Linux distributions.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

No comment yet.
Scooped by Gust MEES
August 3, 2:43 PM
Scoop.it!

Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion | ICT Security-Sécurité PC et Internet | Scoop.it

The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud.

Visa has agreed to acquire fraud prevention company BioCatch for $2.4 billion in cash as the payments giant looks to expand its cybersecurity and financial crime detection capabilities.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=acquisitions

 

Gust MEES's insight:

The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud.

Visa has agreed to acquire fraud prevention company BioCatch for $2.4 billion in cash as the payments giant looks to expand its cybersecurity and financial crime detection capabilities.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/securite-pc-et-internet

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=acquisitions

 

No comment yet.
Scooped by Gust MEES
July 8, 8:39 AM
Scoop.it!

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros | ICT Security-Sécurité PC et Internet | Scoop.it

Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.

The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any local program are enough.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

Gust MEES's insight:

Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.

The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any local program are enough.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=Linux

 

No comment yet.
Scooped by Gust MEES
June 13, 2:59 PM
Scoop.it!

New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hackers Server

New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hackers Server | ICT Security-Sécurité PC et Internet | Scoop.it

New “Agentjacking” attack that hijacks AI coding agents and silently executes attacker-controlled code on developer machines using nothing more than a single injected Sentry error.

The technique turns trusted AI assistants like Claude Code and Cursor into an execution layer for malicious commands, without phishing, malware delivery, or any breach of the victim’s infrastructure.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

New “Agentjacking” attack that hijacks AI coding agents and silently executes attacker-controlled code on developer machines using nothing more than a single injected Sentry error.

The technique turns trusted AI assistants like Claude Code and Cursor into an execution layer for malicious commands, without phishing, malware delivery, or any breach of the victim’s infrastructure.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
June 3, 5:17 PM
Scoop.it!

Five OpenClaw 0-Days let Attackers to Hijack Trusted AI Agent Access

Five zero-day flaws in OpenClaw allowed attackers to bypass trust boundaries and hijack AI agent access across multiple messaging platforms.

OpenClaw, which integrates AI agents with services such as Slack, Discord, Microsoft Teams, Matrix, and Telegram, relies heavily on user-defined allowlists to determine who can interact with an agent.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

 

Gust MEES's insight:

Five zero-day flaws in OpenClaw allowed attackers to bypass trust boundaries and hijack AI agent access across multiple messaging platforms.

OpenClaw, which integrates AI agents with services such as Slack, Discord, Microsoft Teams, Matrix, and Telegram, relies heavily on user-defined allowlists to determine who can interact with an agent.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
June 1, 7:12 AM
Scoop.it!

Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts

A critical flaw in Meta's AI-powered account recovery tool on Instagram allowed attackers to hijack high-value accounts by tricking the chatbot into forwarding password reset codes with no verification required.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:

A critical flaw in Meta's AI-powered account recovery tool on Instagram allowed attackers to hijack high-value accounts by tricking the chatbot into forwarding password reset codes with no verification required.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
May 30, 5:10 PM
Scoop.it!

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface | ICT Security-Sécurité PC et Internet | Scoop.it
ChatGPhish exploits ChatGPT Markdown rendering to deliver phishing content from summarized web pages, increasing AI attack surfaces.

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

Gust MEES's insight:
ChatGPhish exploits ChatGPT Markdown rendering to deliver phishing content from summarized web pages, increasing AI attack surfaces.

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

No comment yet.
Scooped by Gust MEES
May 21, 5:45 AM
Scoop.it!

Claude Code's Network Sandbox Vulnerability Exposes User Credentials and Source Code

Claude Code's Network Sandbox Vulnerability Exposes User Credentials and Source Code | ICT Security-Sécurité PC et Internet | Scoop.it

Anthropic’s Claude Code AI coding assistant harbored a critical network sandbox bypass for over five months, allowing attackers to exfiltrate credentials, source code, and environment variables from developer systems, and the company issued no public advisory for either incident.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=Claude

 

Gust MEES's insight:

Anthropic’s Claude Code AI coding assistant harbored a critical network sandbox bypass for over five months, allowing attackers to exfiltrate credentials, source code, and environment variables from developer systems, and the company issued no public advisory for either incident.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=Claude

 

No comment yet.
Scooped by Gust MEES
May 18, 5:46 AM
Scoop.it!

Claude Code RCE Flaw Lets Attackers Execute Commands via Malicious Deeplinks

A critical remote code execution (RCE) vulnerability has been discovered in Anthropic’s Claude Code CLI tool, allowing attackers to execute arbitrary commands on a victim’s machine by tricking them into clicking a specially crafted deeplink.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=Claude

 

 

 

Gust MEES's insight:

A critical remote code execution (RCE) vulnerability has been discovered in Anthropic’s Claude Code CLI tool, allowing attackers to execute arbitrary commands on a victim’s machine by tricking them into clicking a specially crafted deeplink.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/21st-century-innovative-technologies-and-developments/?&tag=AI

 

https://www.scoop.it/topic/securite-pc-et-internet?tag=Claude

 

 

No comment yet.