Accueil > Accueil > Global Security Mag Online
http://www.globalsecuritymag.fr/
Articles
-
Cato Networks analyse une campagne ClickFix visant les utilisateurs de macOS
26 août, par CATO Networks — afficheLa société analyse une campagne ClickFix diffusée via un résultat sponsorisé et Google Sites, avec une chaîne d'infection proche de celle d'Atomic macOS Stealer.
Cato Networks, réseau convergé et cloud de sécurité pour l'IA, annonce que son équipe de recherche sur les menaces, Cato CTRL, a analysé une campagne visant les utilisateurs à la recherche d'une version de Codex pour macOS.Lorsqu'ils effectuent cette recherche, une publicité affichée au-dessus du résultat officiel d'OpenAI les redirige vers une page Google Sites imitant un portail de téléchargement. Un contenu contrôlé par les attaquants demande ensuite à la victime de copier une commande dans Terminal. La campagne assemble plusieurs éléments familiers pour gagner la confiance des internautes. Le résultat sponsorisé lui donne une forte visibilité, Google Sites apporte la crédibilité d'un service reconnu et la page reprend l'apparence d'un outil destiné aux développeurs. Le contenu malveillant n'est toutefois pas hébergé directement sur Google Sites. Une page externe intégrée au faux portail le diffuse et peut être modifiée sans changer la page d'approche.
Cette technique, appelée ClickFix, évite le téléchargement traditionnel d'un fichier malveillant. Le faux installateur persuade l'utilisateur de réaliser lui-même l'étape qui déclenche l'attaque. La commande copiée lance une chaîne en trois étapes qui masque l'origine et la nature du programme final. Celui-ci est compatible avec les Mac Intel et Apple Silicon. Le processus supprime aussi certains attributs de quarantaine afin de limiter les avertissements associés aux fichiers téléchargés depuis Internet. La chaîne de diffusion présente de fortes similitudes avec des activités documentées d'Atomic macOS Stealer, un logiciel malveillant conçu pour dérober des informations sur les Mac. Les chercheurs de Cato CTRL ont notamment retrouvé l'enregistrement de l'exécution de la commande avant le téléchargement du programme final, un mécanisme déjà observé dans des chaînes de diffusion associées à ce malware. Ce seul élément ne permet toutefois pas de déterminer le protocole de commande et contrôle utilisé par le programme final après son exécution.
Les attaquants cherchent également à échapper aux outils d'analyse. Le faux installateur n'apparaît que lorsque l'utilisateur consulte la bonne adresse depuis un appareil macOS. Les autres visiteurs peuvent voir une page inoffensive, ce qui complique l'identification de la campagne par les scanners automatisés. Cato CTRL a observé trois ensembles d'infrastructures utilisant plusieurs pages Google Sites et serveurs externes, dont certains éléments ont été réutilisés d'une version à l'autre. Cato Networks indique avoir bloqué les sites et les serveurs malveillants identifiés, empêchant notamment le chargement du faux installateur depuis l'une des pages observées.
Les organisations peuvent rechercher les connexions aux fausses pages et vérifier si un utilisateur a suivi les instructions affichées. L'ouverture inhabituelle de Terminal après la consultation d'un résultat sponsorisé lié à l'IA constitue un signal à examiner.
Plus d'informations sont disponibles dans l'article de blog dédié.À propos de Cato Networks
Cato Networks, éditeur de la principale plateforme de sécurité réseau pour l'ère de l'IA, fournit un accès sécurisé zero trust partout à des milliers de clients dans le monde. Conçue pour les organisations opérant dans tous les environnements cloud et hybrides, la plateforme Cato SASE unifie les réseaux, la sécurité et les accès, en les proposant sous forme de capacités élastiques et modulaires que les organisations peuvent adopter facilement et faire évoluer au fil du temps. Cato Networks associe le Cato Cloud, un réseau mondial conçu à cet effet, à une expérience opérationnelle simplifiée, le tout au sein d'une plateforme robuste pilotée par l'IA. Avec Cato, les organisations modernisent en toute confiance, gagnent en résilience et innovent plus rapidement, sans complexité ni risques supplémentaires. Vous souhaitez découvrir pourquoi des milliers d'organisations sécurisent leur avenir avec Cato ?
Rendez-vous sur www.catonetworks.com. -
FBI investigates newly disclosed breach of U.S. water technology supplier – Expert Comments
26 août, par Xcape, Inc. and Suzu Labs — afficheThe FBI is investigating a previously unreported cyberattack on Micro-Comm, a Kansas company that makes programmable logic controllers (PLCs) used by wastewater facilities. Micro-Comm discovered the breach on July 31, and the Barracuda ransomware group subsequently published what it claimed were nearly 850,000 stolen files totaling roughly 644 GB of data.
What makes this incident different from the recent attacks on individual water utilities is that the hackers compromised a supplier of the technology used to operate water infrastructure. A list of the stolen files reportedly references specific government customers, including local governments and a U.S. military facility, as well as employee information and product diagrams. Roughly 200 Micro-Comm SCADAview CSX systems currently in use across the U.S. are accessible from the internet.
Micro-Comm said passwords, customer credentials and information enabling remote access to its devices were not exposed, and there is no evidence that the breach resulted in the operational compromise of a water system. The FBI also told the company that the attack appeared opportunistic and separate from the recent campaign targeting water utilities in at least seven states.
Experts with Xcape, Inc. and Suzu Labs offer perspectives on the matter.
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“The Micro-Comm incident may well have been an opportunistic ransomware/data-theft attack which is unconnected to the other recent attacks on OT. Nevertheless, that does not make the information stolen from it unimportant.”
“An attack on one utility gives you one victim. An attack on a control-system supplier can potentially give you a map to hundreds of victims. Customer identities, engineering information, product diagrams and other technical data can significantly reduce the reconnaissance burden for somebody who wants to attack those systems later.”
“Moreover, AI changes the economics of exploiting a large data dump. An adversary can use AI to help sift through the information, correlate customers with products and configurations, analyze engineering documentation, and if source code or other implementation details are available, look for product vulnerabilities worth exploiting. This matters all the more when roughly two hundred Micro-Comm systems are already reachable from the internet.”
“You don't need to steal the remote-access password for stolen engineering information to have intelligence value.”
“Micro-Comm isn't Siemens, Schneider or Rockwell. Despite manufacturing their own line of PLCs, it is a much smaller specialist manufacturer whose scale is closer to that of many regional control-system integrators than to the major global automation vendors.”
“And that raises a broader concern: if we're anticipating targeted adversarial activity rather than simply reacting to opportunistic ransomware, the integrator community deserves particular attention. The system integrators are often small regional engineering companies, but they may hold PLC programs, network diagrams, customer configurations and remote-access pathways for dozens of critical-infrastructure operators. From an adversary's perspective, that's an extraordinarily valuable concentration of information.”
“The company maintaining the keys and blueprints to a few hundred water systems may have fifty employees. That doesn't make it a small target.”
Denis Calderone, CTO, Suzu Labs:
“The ICS threat landscape is getting much more sophisticated. In 2023, CyberAv3ngers were simply changing default passwords on Unitronics PLCs and putting political messages on HMI screens. But by July of this year, CISA confirmed that actors were exfiltrating PLC project files using the vendors' own engineering software and modifying Add-On Instructions to disable safety shutdowns while leaving the operator displays looking normal. Last week, five federal agencies warned that attackers are now using AI to generate working exploitation scripts against Siemens S7 controllers, calling it an evolution that 'dramatically reduces the technical expertise and time required.' That's the trajectory, and the Micro-Comm breach feeds into that narrative.”
“What makes the Micro-Comm breach so dangerous is the stolen proprietary data. The five-agency advisory said threat actors are collecting public information about PLC vulnerabilities and using AI to generate scripts that act on it. Now, imagine what becomes possible with a non-public disclosure? There are product diagrams, system architecture documents, customer-specific configurations, details about how SCADAview CSX communicates with the controllers it monitors. You hand that documentation to an unguardrailed AI model and the output is not generic Modbus reads on port 502, it's targeted tooling built against a specific vendor's implementation, informed by the manufacturer's own engineering materials. That's the difference between FrostyGoop's 300 lines of Go sending blind register writes and something purpose-built to manipulate the logic in a specific way that an operator won't notice.”
“The FBI says this was opportunistic ransomware, and the attackers probably didn't know what they had. Barracuda is selling it for $30,000. But there are roughly 200 SCADAview CSX systems sitting on the public internet right now according to Censys, and the buyers of this data may have very different intent than the people who stole it. The joint advisory (AA26-231A) pointed out that the Siemens attack had pre-positioning as one of its goals, so utilities running Micro-Comm equipment should be getting those systems off the internet today, rotating every credential, and asking their integrator to verify that PLC project files match a known-good baseline. If you rely on this vendor's products, you need to stay diligent. The window between when this data hit the market and when someone with real capability decides to use it is the only time you have to close the gap.”
-
Cyberattack disrupts Boston Scientific’s global operations and customer shipments – Expert Comments
26 août, par Suzu Labs and Xcape, Inc. — afficheMedical device manufacturer Boston Scientific said it is experiencing a global operational disruption after detecting a cyberattack on August 25.
The incident has restricted access to information systems and business applications used across the company, including systems needed to process and ship customer orders. Boston Scientific said the disruptions are expected to continue while recovery efforts are underway, and it does not yet have a timeline for full restoration.
In Ireland, staff at its Cork facility were sent home Tuesday, and employees able to work remotely were subsequently instructed to do so.
Experts with Suzu Labs and Xcape, Inc. offer perspectives on the matter.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A cardiac device that misses its ship date can mean a cancelled surgery. That's what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn't need to destroy anything. They just need to make downtime more expensive than whatever they're asking for."
“Medical devices also aren't something a hospital can always swap out at the last minute. Physicians have selected specific devices, patients are scheduled, inventory is already in place, and procedures have been planned around them. Disrupt order processing and shipping and the consequences show up in hospitals pretty quickly."
“The harder problem is getting manufacturing back online. These aren't ordinary IT systems. Software involved in producing and tracking FDA-regulated devices sits inside a validated quality system. Restoring a server is one thing. Establishing that the data coming out of that system can still be trusted is another."
“You can't ship something that gets implanted in a human body on trust alone. If production or quality systems were affected, Boston Scientific may have to establish that records are intact and trustworthy before normal operations resume."
“That's why employees at Boston Scientific's manufacturing facility in Cork, Ireland being sent home matters. This isn't just people losing access to email. The company has already confirmed disruption to order processing and shipping, and Cork shows that disruption reaching manufacturing operations. If quality or production data was also affected, getting the servers running could be the easy part.”
Damon Small, Board of Directors, Xcape, Inc.:
“When a cyberattack halts order fulfillment and logistics across a global enterprise, an IT security incident becomes an immediate revenue and medical supply chain crisis. Because details regarding the initial attack vector remain sparse, it is not possible to recommend specific preventive technical steps for other organizations. That said, cybercriminals are often opportunistic and exploit vulnerable systems as soon as they discover them; it is currently unknown whether this was a targeted attack or just bad luck. Regardless of the entry point, disruption to core business applications forces defensive network isolation to stop lateral movement."
"To maintain operational continuity during an ongoing intrusion, security teams must enforce strict logical boundaries between corporate administrative networks and fulfillment environments, maintain immutable offline backups, and regularly validate manual failover protocols."
“Critical Takeaways:
• When enterprise applications stall, cyber incidents rapidly escalate from IT disruptions to severe supply chain and revenue crises.
• Attack vectors remain unconfirmed because threat actors frequently exploit opportunistic vulnerabilities rather than executing targeted campaigns.
• Maintaining operational continuity requires enforcing strict network segmentation between administrative and fulfillment environments before an incident occurs."“Whether hit by targeted sophistication or bad luck on an unpatched system, the operational result remains the same without proper segmentation.”
-
Ransomware : la France rejoint les six pays les plus ciblés au monde
25 août, par Bitdefender — afficheAvec 131 victimes revendiquées au premier semestre 2026 et une hausse de plus de 40 % du nombre de victimes en Europe occidentale en un an, la France concentre près d'un tiers des organisations touchées dans la région. Les secteurs des technologies, de l'industrie manufacturière, de la construction et du secteur public figurent parmi les plus exposés.
Bitdefender, leader mondial de la cybersécurité, publie son rapport sur les attaques de ransomware revendiquées au premier semestre 2026.
La France figure désormais parmi les pays les plus ciblés par les groupes de ransomware, avec 131 organisations publiquement désignées comme victimes, ce qui la place au 6ᵉ rang mondial. La France concentre également près de 30 % des victimes recensées en Europe occidentale.
À l'échelle mondiale, les groupes de ransomware ont revendiqué 4 641 victimes au premier semestre 2026, contre 4 381 sur la même période en 2025, soit une progression de 5,9 %. L'Amérique du Nord demeure la région la plus touchée.
En Europe occidentale, la progression est encore plus marquée en Europe occidentale. Le nombre de victimes revendiquées est passé de 310 au premier semestre 2025 à 436 un an plus tard, soit une progression de plus de 40 %. À elles seules, la France et l'Allemagne concentrent près de 70 % des victimes recensées dans la région, confirmant qu'elles constituent les principales cibles des groupes de ransomware en Europe occidentale.
« Les chiffres du premier semestre confirment une évolution durable de la menace. Les groupes de ransomware ne cherchent plus uniquement à multiplier les attaques : ils affinent leurs stratégies pour cibler les organisations dont l'interruption d'activité est susceptible de générer la plus forte pression. Dans le même temps, ils élargissent leurs campagnes aux PME et exploitent davantage les chaînes d'approvisionnement pour atteindre leurs objectifs. Face à cette professionnalisation, la cyber-résilience devient un enjeu de continuité d'activité autant que de sécurité informatique. » commente Jade Brown, Threat Researcher at Bitdefender.Des secteurs critiques particulièrement exposés
Au-delà du volume d'attaques, le rapport montre une concentration des victimes dans plusieurs secteurs stratégiques. En France, les technologies, l'industrie manufacturière et la construction figurent parmi les secteurs les plus ciblés, tandis que les administrations et organismes publics occupent la quatrième place. Le mois de mars a enregistré le plus grand nombre de victimes revendiquées (39), tandis que The Gentlemen et Qilin figurent parmi les groupes ayant le plus revendiqué d'attaques contre des organisations françaises. Cette répartition confirme que les cybercriminels privilégient les organisations dont une interruption d'activité est susceptible d'entraîner des conséquences économiques ou opérationnelles majeures, en ciblant aussi bien les entreprises disposant de systèmes critiques que les administrations assurant des services essentiels.
Des attaques plus automatisées et des cibles plus diversifiées
L'analyse de Bitdefender met également en évidence une évolution des modes opératoires des cybercriminels. Les groupes de ransomware s'appuient de plus en plus sur des outils automatisés, des voleurs d'informations (infostealers) et des solutions capables de neutraliser les systèmes de détection et de réponse sur les terminaux (EDR), afin d'accélérer les compromissions et de contourner plus efficacement les dispositifs de sécurité.
Parallèlement, les attaquants élargissent leurs campagnes aux petites et moyennes organisations, souvent moins bien protégées, tout en exploitant davantage les chaînes d'approvisionnement, les fournisseurs et les équipements exposés en périphérie des réseaux pour atteindre leurs cibles.Réduire l'exposition avant l'attaque
Face à cette évolution, Bitdefender recommande aux organisations de renforcer simultanément leurs capacités de prévention, de détection et de réponse : « Les organisations les plus résilientes ne sont pas celles qui empêchent toutes les attaques, mais celles qui sont capables de les détecter rapidement, d'en limiter les conséquences et de reprendre leurs activités dans les meilleurs délais. La préparation est aujourd'hui un facteur de résilience aussi important que la prévention. » explique Prénom, nom et fonction, Bitdefender « Dans un contexte où les groupes de ransomware poursuivent leur professionnalisation et diversifient leurs modes opératoires, les organisations françaises doivent désormais considérer la cyber-résilience comme un enjeu de continuité d'activité autant que de cybersécurité. »
À propos du rapport
Le rapport Bitdefender sur les attaques de ransomware revendiquées au premier semestre 2026 s'appuie sur l'analyse des organisations publiquement revendiquées par les groupes de ransomware entre janvier et juin 2026. Il recense 4 641 victimes dans le monde, dont 436 en Europe occidentale et 131 en France. Ces données permettent de suivre l'évolution des principaux acteurs de la cyber extorsion, de leurs cibles et des tendances observées. Elles ne couvrent toutefois que les attaques rendues publiques par les groupes de ransomware et non l'ensemble des incidents survenus durant la période.
À propos de Bitdefender
Bitdefender est un leader de la cybersécurité proposant dans le monde entier des solutions de prévention, de détection et de réponse aux menaces parmi les plus performantes du marché. Protecteur de millions d'environnements de particuliers, d'entreprises et d'administrations publiques, Bitdefender est l'un des experts les plus fiables du secteur pour éliminer les menaces, protéger la vie privée, l'identité numérique et les données, et renforcer la cyber-résilience. Grâce à des investissements importants en recherche et développement, Bitdefender Labs découvre chaque minute des centaines de nouvelles menaces et valide quotidiennement des milliards de requêtes liées aux menaces. L'entreprise est à l'origine d'innovations de rupture dans les domaines de la lutte contre les logiciels malveillants, de la sécurité de l'IoT, de l'analyse comportementale et de l'intelligence artificielle, et sa technologie est utilisée sous licence par plus de 180 des marques technologiques les plus reconnues au monde. Fondée en 2001, Bitdefender compte des clients dans plus de 170 pays et possède des bureaux dans le monde entier. Pour plus d'informations, rendez-vous sur https://www.bitdefender.com.
-
CISA orders federal agencies to patch actively exploited Oracle flaw by August 27– Expert Comments
25 août, par Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs — afficheCISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
The flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS.
The vulnerability can be exploited remotely over HTTP without authentication or valid credentials, potentially allowing attackers to access, modify or delete critical data.Oracle originally disclosed and patched CVE-2026-21962 on January 20, 2026, as part of its January Critical Patch Update. In March, researchers reported exploitation attempts after exploit code became publicly available.
CISA has ordered federal agencies to address the vulnerability by August 27.
An expert with Suzu Labs offers perspective on the matter.Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“CVE-2026-21962 had a patch on January 20, and CloudSEK recorded exploitation attempts against its honeypot on January 22, followed by broader automated scanning. CISA added it to the KEV catalog on August 24, 216 days after the patch. Federal agencies now have three days to remediate something attackers have had seven months to exploit.
“In January, agencies could have applied the Critical Patch Update inside a normal maintenance window and moved on. Seven months of delay while exploitation attempts and automated scanning were already being observed from rented VPS infrastructure changed the math. BOD 26-04 requires forensic triage at this severity tier, so agencies now have to assess whether compromise occurred during that seven-month exposure period alongside applying the patch.
“BOD 26-04's 16-tier remediation matrix is well-designed for the problem it solves. For a vulnerability in the KEV, automatable, and yielding total control of a public-facing asset, the clock is three days with forensic triage. In this case, CISA's August 24 KEV addition produced an August 27 federal remediation deadline, while CISA's obligation is to update the catalog "as quickly as possible," with no numerical SLA. EPSS ranked this in the top 1.4%, Shodan shows roughly 79,000 exposed Oracle HTTP Server instances, and CISA's own SSVC record dates active exploitation to January 21 while classifying the vulnerability as automatable with total technical impact.
“Three days to remediate is the right call. Seven months to trigger it turned a maintenance window into a forensic investigation.”
GS Days