Blog

L’ANSSI réunit son conseil scientifique le temps d’une journée (ANSSI – Actualités)

Actualités
L’ANSSI réunit son conseil scientifique le temps d’une journée anssiadm mar 04/11/2025 - 15:41 Le 4 novembre 2025 a eu lieu la journée du conseil scientifique de l’ANSSI qui a réuni membres du conseil et agents de l’ANSSI au sein du Campus cyber. Le conseil scientifique : un organe consultatif de réflexion et de proposition depuis 2019 En 2019, l’ANSSI a pris la décision de se doter d’un conseil scientifique pour toujours mieux anticiper les grands défis technologiques et socio-économiques de la sécurité numérique. Composé de personnalités scientifiques mais également de représentants étatiques, cette instance assure une mission de conseil auprès de l’Agence dans le cadre de ses activités de recherche. Il propose ainsi des thèmes de recherche, s’exprime sur le programme scientifique de l’Agence et peut être consulté dans le…
Read More

L’ANSSI vous donne rendez-vous à la ECW 2025 (ANSSI – Actualités)

Actualités
L’ANSSI vous donne rendez-vous à la ECW 2025 anssiadm lun 10/11/2025 - 08:57 Du 17 au 20 novembre 2025, l’ANSSI participera à la 10e édition de l’European Cyber Week (ECW) organisée par le Pôle d’Excellence Cyber avec le soutien du ministère des Armées, de la Région Bretagne et de la Métropole de Rennes. Cet événement de premier plan réunira plus de 120 partenaires et 6 000 visiteurs des secteurs publics et privés de la cybersécurité pendant trois jours et demi, au sein du centre de conférences Couvent des Jacobins, à Rennes. Les grands enjeux technologiques, industriels et sociétaux sont autant de thématiques qui seront au programme de cette 10e édition. Sur le stand 25, les agents de l’ANSSI se rendront disponibles pour vous rencontrer, vous présenter les dernières actualités de…
Read More

ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves

Actualités
This week has been crazy in the world of hacking and online security. From Thailand to London to the US, we've seen arrests, spies at work, and big power moves online. Hackers are getting caught. Spies are getting better at their jobs. Even simple things like browser add-ons and smart home gadgets are being used to attack people. Every day, there's a new story that shows how quickly things are
Read More

New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

Actualités
Cybersecurity researchers have disclosed details of a new Android banking trojan called Sturnus that enables credential theft and full device takeover to conduct financial fraud. "A key differentiator is its ability to bypass encrypted messaging," ThreatFabric said in a report shared with The Hacker News. "By capturing content directly from the device screen after decryption, Sturnus can monitor
Read More

CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat

Actualités
CTM360 has identified a rapidly expanding WhatsApp account-hacking campaign targeting users worldwide via a network of deceptive authentication portals and impersonation pages. The campaign, internally dubbed HackOnChat, abuses WhatsApp’s familiar web interface, using social engineering tactics to trick users into compromising their accounts. Investigators identified thousands of malicious URLs
Read More

Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt

Actualités
Threat actors with ties to Iran engaged in cyber warfare as part of efforts to facilitate and enhance physical, real-world attacks, a trend that Amazon has called cyber-enabled kinetic targeting. The development is a sign that the lines between state-sponsored cyber attacks and kinetic warfare are increasingly blurring, necessitating the need for a new category of warfare, the tech giant's
Read More

TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

Actualités
Threat actors are leveraging bogus installers masquerading as popular software to trick users into installing malware as part of a global malvertising campaign dubbed TamperedChef. The end goal of the attacks is to establish persistence and deliver JavaScript malware that facilitates remote access and control, per a new report from Acronis Threat Research Unit (TRU). The campaign, per the
Read More

The Cloudflare Outage May Be a Security Roadmap (Krebs on Security)

Actualités
An intermittent outage at Cloudflare on Tuesday briefly knocked many of the Internet’s top destinations offline. Some affected Cloudflare customers were able to pivot away from the platform temporarily so that visitors could still access their websites. But security experts say doing so may have also triggered an impromptu network penetration test for organizations that have come to rely on Cloudflare to block many types of abusive and malicious traffic. At around 6:30 EST/11:30 UTC on Nov. 18, Cloudflare’s status page acknowledged the company was experiencing “an internal service degradation.” After several hours of Cloudflare services coming back up and failing again, many websites behind Cloudflare found they could not migrate away from using the company’s services because the Cloudflare portal was unreachable and/or because they also were getting their…
Read More

Google Sues to Disrupt Chinese SMS Phishing Triad (Krebs on Security)

Sécurité
Google is suing more than two dozen unnamed individuals allegedly involved in peddling a popular China-based mobile phishing service that helps scammers impersonate hundreds of trusted brands, blast out text message lures, and convert phished payment card data into mobile wallets from Apple and Google. In a lawsuit filed in the Southern District of New York on November 12, Google sued to unmask and disrupt 25 “John Doe” defendants allegedly linked to the sale of Lighthouse, a sophisticated phishing kit that makes it simple for even novices to steal payment card data from mobile users. Google said Lighthouse has harmed more than a million victims across 120 countries. A component of the Chinese phishing kit Lighthouse made to target customers of The Toll Roads, which refers to several state routes…
Read More

Microsoft Patch Tuesday, November 2025 Edition (Krebs on Security)

Sécurité
Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being exploited. Microsoft also fixed a glitch that prevented some Windows 10 users from taking advantage of an extra year of security updates, which is nice because the zero-day flaw and other critical weaknesses affect all versions of Windows, including Windows 10. Affected products this month include the Windows OS, Office, SharePoint, SQL Server, Visual Studio, GitHub Copilot, and Azure Monitor Agent. The zero-day threat concerns a memory corruption bug deep in the Windows innards called CVE-2025-62215. Despite the flaw’s zero-day status, Microsoft has assigned it an “important” rating rather than critical, because exploiting it requires an attacker to already have…
Read More