Accueil > Accueil > Global Security Mag Online
http://www.globalsecuritymag.fr/
Articles
-
Multiples vulnérabilités dans Mattermost Desktop App (18 août 2026)
18 août, par CERT-FRDe multiples vulnérabilités ont été découvertes dans Mattermost Desktop App. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un problème de sécurité non spécifié par l'éditeur.
Voir en ligne : https://www.cert.ssi.gouv.fr/avis/C... -
Multiples vulnérabilités dans Typo3 (18 août 2026)
18 août, par CERT-FRDe multiples vulnérabilités ont été découvertes dans Typo3. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.
Voir en ligne : https://www.cert.ssi.gouv.fr/avis/C... -
ETSI advances cybersecurity standards supporting Cyber Resilience Act – Expert Comments
17 août, par Valentin Jangwa, Global Security Mag — afficheETSI (European Telecommunications Standards Institute) has moved 17 cybersecurity standards into the formal approval process as part of Europe's implementation of the Cyber Resilience Act (CRA).
The standards address specific categories of network and edge devices, security solutions and internet-of-things (IoT) appliances, including routers, operating systems, browsers, password managers, smart home devices and security software, and are designed to translate the CRA's broader legal obligations into technical requirements manufacturers can follow.
The proposed standards establish baseline security requirements that manufacturers will need to meet for CRA compliance and to sell covered products in the EU beginning in December 2027.Requirements include modern encryption, secure default configurations, a machine-readable software bill of materials (SBOM) documenting software dependencies, and mechanisms for delivering security updates after products are sold.
Doc McConnell, Head of Policy and Compliance, Finite State:
“The release of final draft standards from ETSI is great news for product manufacturers in these 17 verticals that cover many of the “important” products with digital elements defined in the Cyber Resilience Act. Seeing these documents makes it easier to concretely evaluate existing products to see where they align with the CRA requirements, and where manufacturers will need to do additional work prior to the December 2027 deadline.
“I expect we'll see manufacturers looking for help in the immediate future to evaluate their existing products to get a baseline of their compliance status, as well as looking for partners who can help them engineer future products in ways that are CRA-compliant before they ever hit the market.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“The CRA's Article 14 vulnerability reporting obligation starts September 11. Manufacturers will have 24 hours to submit an early warning for actively exploited vulnerabilities. Meeting that window in practice means knowing what components ship in every product, which versions are affected, and who owns remediation. I've watched that question consume most of the response time during live incidents, where teams dig through repositories and old release manifests while the clock runs.
“SBOMs built for incident response are produced automatically during builds, tied to specific product versions, retained across releases, and queryable when a new CVE drops. A document generated once for an auditor can't answer those questions under a 24-hour clock. SBOMs are becoming incident-response infrastructure.
“AI-accelerated vulnerability discovery compounds the pressure. AI systems are already demonstrating the ability to discover previously unknown vulnerabilities in production software. As researchers run vulnerability-discovery agents in parallel, finding potential vulnerabilities can scale faster than the engineering processes required to triage and remediate them. When discovery outpaces your ability to identify affected products, component visibility becomes the bottleneck.
“The 17 ETSI draft standards now entering formal approval begin translating the CRA's SBOM obligations into technical requirements. They don't yet carry the presumption of conformity under Article 27, which requires publication in the Official Journal. Treat them as a gap analysis baseline.”
John Strand, Owner, Black Hills Information Security, Inc.:
“In so many ways, it seems like Europe is getting this a little bit faster than we are in the United States. This is exactly the type of guidance and requirements we need for companies building Internet of Things devices, appliances, routers, and all of the other technology that ends up connected to our networks.
“There need to be baseline security requirements built into these products from the very beginning. And hopefully, this continues to expand so manufacturers aren't just responsible for security when a product ships. They need to maintain responsibility for the security of those devices throughout the lifespan of the product.”
Seemant Sehgal, Founder & CEO, BreachLock:
"Europe is doing something manufacturers have resisted for decades, which is making security a condition of market access. The seventeen standards moving through ETSI are essentially a translation layer, converting a legal obligation into something an engineering team can actually act on. What strikes me about the CRA requirements is how foundational they are.
“Encrypted communications, secure defaults, a documented software bill of materials, a defined path for delivering updates. These are not ambitious asks. They are baseline hygiene that the industry has been slow to standardize because there was no hard deadline and no real consequence for skipping it. December 2027 creates both of these.
“The question manufacturers should be considering now is how much of their existing product architecture was built with the assumption that they never would have to meet specific security requirements."
-
Attaque DGFIP : le défi de la détection post-authentification
17 août, par Valentin Jangwa, Global Security Mag — afficheSuite de l'attaque revendiquée contre la DGFIP.
L'attaquant affirme avoir contourné le MFA et conservé un accès authentifié pendant une période prolongée. Si ces déclarations restent à confirmer, ce scénario pose une question clé pour les équipes IT : comment détecter une exfiltration de données lorsque l'activité provient d'une session considérée comme légitime par les systèmes ?
Jeff Wichman, Director of Incident Response, Semperis, détaille les mesures à prendre (au-delà d'un simple changement de mot de passe) : révoquer les sessions et les tokens, reconstituer précisément l'activité du compte et vérifier si l'attaquant a modifié des permissions, créé de nouveaux accès ou installé un mécanisme de persistance.
Jeff WichmanDirector of Incident Response, Semperis
« On peut changer un mot de passe, mais on ne peut pas remplacer son identité ni effacer les données qui la relient à son patrimoine. C'est ce qui rend l'attaque contre la DGFiP particulièrement sensible. Le pirate affirme avoir contourné le MFA (authentification multifacteur), puis conservé pendant une période prolongée un accès authentifié au service cadastral. Cela reste, à ce stade, sa version des faits. Si elle est exacte, il aurait pu extraire progressivement des données tout en apparaissant, aux yeux du système, comme un utilisateur légitime.
Couper cet accès était la bonne première mesure. Dans le cadre de l'enquête, il faut maintenant révoquer toutes les sessions et tous les jetons d'authentification encore actifs, examiner précisément ce que le compte a consulté et vérifier si l'attaquant a modifié des droits, créé de nouveaux comptes ou laissé une autre porte d'entrée dans le système. Réinitialiser le mot de passe ne suffira peut-être pas.
Selon l'attaquant, l'extraction partielle pourrait concerner deux millions de personnes. Si les données décrites ont bien été extraites, les conséquences peuvent être graves et durables. Il ne s'agit pas seulement de noms et d'adresses : les dates et lieux de naissance, les identifiants fonciers et les liens avec des biens précis permettent de reconstituer un profil très détaillé de chaque personne. Pour un fraudeur, ces données constituent une base presque prête à l'emploi pour usurper une identité, fabriquer un faux avis d'imposition ou préparer un email ou un appel suffisamment crédible pour tromper même une personne vigilante.
Le MFA reste indispensable, mais il ne peut pas être la dernière ligne de défense. Les organisations doivent aussi surveiller ce qui se passe après la connexion. Dans ce type d'attaque, le danger ne vient pas d'un compte inconnu, mais d'un compte parfaitement légitime tombé entre de mauvaises mains. »
-
Vigilance.fr - Dolibarr : code execution via db_name, analyzed on 17/06/2026
17 août, par Vigilance.frAn attacker can use a vulnerability of Dolibarr, via db_name, in order to run code.
View online : https://vigilance.fr/vulnerability/...
GS Days