Accueil > Accueil > Global Security Mag Online
http://www.globalsecuritymag.fr/
Articles
-
Multiples vulnérabilités dans Oracle Java SE (19 août 2026)
19 août, par CERT-FRDe multiples vulnérabilités ont été découvertes dans Oracle Java SE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Voir en ligne : https://www.cert.ssi.gouv.fr/avis/C... -
Vulnérabilité dans Apereo CAS (19 août 2026)
19 août, par CERT-FRUne vulnérabilité a été découverte dans Apereo CAS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
Voir en ligne : https://www.cert.ssi.gouv.fr/avis/C... -
Multiples vulnérabilités dans Oracle PeopleSoft (19 août 2026)
19 août, par CERT-FRDe multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un déni de service.
Voir en ligne : https://www.cert.ssi.gouv.fr/avis/C... -
Hacker claims 3.6 million records stolen from major companies’ Azure environments – Expert Comments
18 août, par BreachLock and Xcape, Inc. — afficheA threat actor known as TheHatman is selling databases allegedly stolen from the Microsoft Azure environments of major companies after gaining access with compromised credentials. Cybercrime intelligence company Hudson Rock investigated the leaks and said they contain "foundational corporate directory attributes," "active domains, and tenant-specific .onmicrosoft.com structures" and are "highly likely authentic."
The attacker claims to have obtained 3.64 million records from organizations including McDonald's, Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels, Gap, Wyndham Hotels, Hexaware and Kyndryl.
The largest alleged dataset contains more than 1.7 million McDonald's employee records, followed by more than 800,000 from Tata Consultancy Services and 425,000 from Vodafone. The data reportedly includes names, employee IDs, email addresses, job titles, phone numbers, addresses, service accounts and other Azure tenant information.
Seemant Sehgal, Founder & CEO, BreachLock:
“This is a reminder that the perimeter most organizations are defending is not where the adversary is operating. A valid credential, once stolen, moves through an environment the same way a legitimate user does. The attacker does not need to break anything. What makes this particularly significant is the nature of the data itself. Directory attributes, tenant structures, and employee identifiers are the raw materials for follow-on attacks, targeted phishing, or supply chain access.
Security teams need to ask whether a credential that was exposed six months ago is still giving someone access to a cloud environment today. Perimeter controls can be strong and still leave that kind of access untouched. The organizations downstream from the initial compromise are often the ones who feel it most. The real test is understanding what an attacker could do with a compromised credential, where it could take them, and whether anyone would know it was being used."
John Carberry, Solution Sleuth, Xcape, Inc.:
“Exfiltrating internal directory structures and employee credentials across corporate cloud tenants creates an immediate risk of targeted spear phishing, business email compromise, and privilege escalation. The mass exposure of 3.64 million records from Fortune 500 Microsoft Azure environments highlights a widespread failure in identity boundary enforcement rather than a cloud platform vulnerability. Organizations must continuously audit user account activity, paying special attention to accounts with elevated privileges, to detect anomalous directory enumeration or session hijacking.
Given that Azure tenant attributes, active domains, and service account details were exfiltrated, affected companies should immediately rotate credential stores, reset application registration secrets, audit service principal permissions, and review federated domain trust relationships. Security leaders must mandate phishing-resistant multi-factor authentication, restrict tenant export rights, and monitor endpoint infostealer logs to stop credential theft before attackers map internal cloud architecture.
Critical Takeaways:
• Identity perimeter failure: The exposure stems from compromised credentials and infostealer malware, not a zero-day flaw in Microsoft Azure infrastructure.
• Tenant remediation: Affected organizations must reset application secrets, audit service principal privileges, and review federated trust relationships immediately.
• Privileged account auditing: Security teams must enforce strict conditional access and audit user accounts with elevated privileges to intercept active session abuse.Blaming the cloud provider for stolen credentials is like blaming the lock manufacturer when you leave your house key under the doormat.”
-
Vigilance.fr - Notepad++ : exécution de code via WinGUp, analysé le 18/11/2025
18 août, par Vigilance.frUn attaquant peut utiliser une vulnérabilité de Notepad++, via WinGUp, afin d'exécuter du code.
Voir en ligne : https://vigilance.fr/vulnerabilite/...
GS Days