Toulouse
Météo 15°C forte pluie

Space & Security News

Enterprise applications often still use complex standards like SOAP for web services. The big advantage of SOAP is its tight and extensive standards, which enable interoperability across an enterprise governed by web services. The disadvantage of...

As part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the topic today. This is my...

An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher....

For a few days, my SANS ISC mailbox is flooded with emails that delivers SVG files. An SVG ("Scalable Vector Graphic") is a web-friendly vector file format used for graphics and icons. No URL in the body, just “an image”, that’s the perfect way...

New article: “Responsible Disclosure in the Age of AI: A Call for Urgent Action,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and remediation. Frontier AI models...

Establishing a successful purple team program requires more than tools and technology. Organizations need to devote time, attention, and resources to critical considerations such as program governance, leadership, and outcomes. Establishing a...

OSSOCDOCS is a project designed to fill a need for robust, freely available, SOC documentation including runbooks and governance. After a decade of building and running Security Operations Centers (SOCs) for dozens of companies, I have...

Traditional formulas of risk assessment applied to cybersecurity simply do not work due to the fundamentally different landscape of cybersecurity. Assessment based on capability breaks due to the proliferation of computation, internet connection,...

About

01/06/2026 16:40

Daddy geek blog… Some informations: No regular posting Sometimes french posts, sometimes franglais posts Code presented is probably only working on my computer Content is licensed under CC-BY-SA 4.0 All opinions or views presented here are mine...

Here is an overview of content I published in May: Blog posts: Update: search-for-compression.py Version 0.0.7 SANS ISC Diary entries: Wireshark 4.6.5 Released YARA-X 1.16.0 Release Wireshark 4.6.6 Released Microsoft Access VBA YARA-X 1.17.0 Release

Introduction This diary provides indicators from an unidentified RAT infection on Wednesday 2026-05-27 that was followed by a malicious NetSupport Manager RAT package. This originated from the SmartApeSG ClickFix campaign. I still don't know the...

Aucun article de sécurité disponible