Accueil > Accueil > Global Security Mag Online
http://www.globalsecuritymag.fr/
Articles
-
ShinyHunters revendique une compromission du FBI
23 septembre, par Valentin Jangwa, Global Security Mag — afficheÀ la suite de la revendication de ShinyHunters, qui affirme avoir compromis des systèmes du FBI et dérobé des données concernant des agents et des candidats à l'agence, le commentaire d'Etay Maor, Vice President of Threat Intelligence chez Cato Networks.
Etay MaorVice President of Threat Intelligence, Cato Networks« En revendiquant une compromission du FBI, ShinyHunters franchit un cap particulièrement provocateur dans le bras de fer qui oppose les forces de l'ordre aux groupes cybercriminels, et cette revendication doit être prise très au sérieux. Nous avons vu d'innombrables fois des acteurs malveillants cibler des entreprises, et des États ou des groupes liés à des États ont déjà compromis des organisations chargées de l'application de la loi, la cyberattaque contre l'OPM en 2015 reste l'exemple le plus marquant, mais voir un groupe cybercriminel revendiquer publiquement une compromission du FBI est d'une autre nature.
Un petit indice opérationnel mérite d'être relevé : la publication du groupe est horodatée au 23 septembre, alors que l'information est apparue le 22 septembre aux États-Unis. Si cet horodatage correspond réellement à l'environnement dans lequel opère le groupe, cela pourrait indiquer une activité située en Asie. Cela ne permet pas d'établir une attribution définitive, mais il s'agit d'un élément que les enquêteurs examineront aux côtés des preuves techniques.
ShinyHunters a démontré à plusieurs reprises qu'il ne se résume pas à un groupe fixe d'individus ou à une infrastructure donnée. Il s'agit d'une marque criminelle résiliente, qui a survécu aux opérations de démantèlement, aux arrestations et aux saisies de forums en faisant évoluer ses méthodes et en attirant de nouveaux opérateurs. Récemment, son mode opératoire a surtout consisté à exploiter des mécanismes de confiance liés aux identités, notamment par le biais de techniques d'ingénierie sociale visant les services d'assistance, d'applications OAuth malveillantes et de jetons d'intégration SaaS volés, plutôt qu'à simplement franchir un périmètre technique. C'est là l'enseignement le plus important. Les organisations, y compris les administrations publiques, doivent protéger les identités et les relations de confiance avec des tiers que les attaquants cherchent de plus en plus à exploiter. » -
« FBI Hacked by ShinyHunters »
22 septembre, par Denis Calderone, CTO, Suzu Labs — afficheIt's been reported that threat actor group ShinyHunters said to 404 Media: ‘We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees. A top cybersecurity expert with Suzu Labs offers some interesting context and perspective to this news.
Denis Calderone, CTO, Suzu Labs
“ShinyHunters has spent the last week picking fights. On Friday they took over Cl0p's leak site and put up a 'seized by ShinyHunters' banner, and by Tuesday the same banner was on the FBI's jobs portal. Both were framed as payback, one for threats from a rival gang and one for an FBI advisory that told victims not to pay them. The FBI hasn't confirmed anything yet, but if this holds up, it doesn't look like the ShinyHunters we've been seeing all year. Their model has always been breach, extort, then settle or leak, and that only works when the victim can pay. The FBI isn't going to pay, and it isn't going to pull an advisory because a criminal group demanded it. Not sure what's going to happen in a week, but I seriously doubt the FBI will act on this threat.”
“They also say this isn't financially motivated, but I'd take that with a grain of salt. I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.”
“That zero-day is where everyone else should focus, since ShinyHunters says they plan to use it more broadly. If you run PeopleSoft, don't wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren't reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”
“Limiting your blast radius is the best precautionary play here.”
-
Vigilance.fr - Webmin : Cross Site Scripting via Configuration, analysé le 22/07/2026
22 septembre, par Vigilance.frUn attaquant peut provoquer un Cross Site Scripting de Webmin, via Configuration, afin d'exécuter du code JavaScript dans le contexte du site web.
Voir en ligne : https://vigilance.fr/vulnerabilite/... -
Vigilance.fr - Webmin : Cross Site Scripting via Configuration, analyzed on 22/07/2026
22 septembre, par Vigilance.frAn attacker can trigger a Cross Site Scripting of Webmin, via Configuration, in order to run JavaScript code in the context of the web site.
View online : https://vigilance.fr/vulnerability/... -
Vigilance.fr - RSYSLOG : déni de service via imptcp, analysé le 22/07/2026
22 septembre, par Vigilance.frUn attaquant peut provoquer une erreur fatale de RSYSLOG, via imptcp, afin de mener un déni de service.
Voir en ligne : https://vigilance.fr/vulnerabilite/...
GS Days