Philippe Vialle

3.7K posts

Philippe Vialle banner
Philippe Vialle

Philippe Vialle

@ph_V

Cyber security engineer working in SecOps, and teacher in Master's degree. Please note that those publications are my own view.

Se unió Nisan 2010
798 Siguiendo458 Seguidores
Tweet fijado
Philippe Vialle
Philippe Vialle@ph_V·
CheckPoint anime son "secure", en FR (partiellement), et fait venir le Pr JULIA qui démontre que l'I.A. n'existe pas. Merci... Du ménage à faire niveau marketing. La présentation qui suit celle du Pr parle d'"AI engines", incohérent! Lien de l'événement: virtual-france.checkpoint.com
Philippe Vialle tweet media
Français
0
0
0
0
Philippe Vialle retuiteado
CNIL
CNIL@CNIL·
🎂 Aujourd'hui marque le 10e anniversaire de l'adoption du RGPD ! Qu'est-ce qui a changé depuis ? 👇
EDPB@EU_EDPB

Today marks the 10th anniversary of the #GDPR’s adoption, the 1st comprehensive data protection framework spanning an entire continent. Have you ever wondered what the data protection landscape looked like before the GDPR? Watch the video to find out more!

Français
173
11
28
204.5K
Philippe Vialle retuiteado
Cyber Security News
Cyber Security News@The_Cyber_News·
🔐 Hackers Can Abuse Entra Agent ID Admin Role to Hijack Service Principals Source: cybersecuritynews.com/entra-agent-id… A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and escalate privileges across the entire tenant. New research found that actions like updating agent identity owners allowed administrators to modify the ownership of any service principal in the tenant. A user with the Agent ID Administrator role could assign themselves as the owner of a completely unrelated, high-privileged service principal. #cybersecuritynews
Cyber Security News tweet media
English
4
81
343
29.8K
Philippe Vialle retuiteado
Microsoft Threat Intelligence
Microsoft Threat Intelligence@MsftSecIntel·
Attackers are using cross-tenant helpdesk impersonation to trick users into granting remote access. Read this Microsoft Defender Research blog to learn how these attacks work and how layered defenses and user awareness reduce risk: msft.it/6013v6SnH
English
15
51
187
35.1K
Philippe Vialle retuiteado
Seb
Seb@seblatombe·
🔴 L'application européenne de vérification d'âge hackée en 2 minutes : de simples modifications dans les fichiers locaux permettent de contourner le PIN, le biométrique et les limites de tentative, exposant potentiellement des données d’identité sensibles.
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

Français
29
518
1.1K
85.7K
Philippe Vialle retuiteado
Philippe Vialle retuiteado
The Hacker News
The Hacker News@TheHackersNews·
🚨 APT37 used Facebook to run a targeted malware campaign. Fake profiles built trust, moved chats to Telegram, then pushed a trojanized PDF app that installs RokRAT via a JPG payload, using compromised sites and Zoho WorkDrive for control. 🔗 Read → thehackernews.com/2026/04/north-…
English
4
65
169
16.2K
Philippe Vialle retuiteado
CERT-FR
CERT-FR@CERT_FR·
Les assistants personnels autonomes par IA (OpenClaw, Claude Cowork, etc.) présentent des risques importants de sécurité pour le SI (fuite de données, compromission des postes, Shadow IT). Découvrez l’analyse et les recommandations du CERT-FR. cert.ssi.gouv.fr/actualite/CERT…
Français
9
86
215
30.6K
Philippe Vialle retuiteado
Cert-IST
Cert-IST@cert_ist·
Une erreur vient d’exposer 4,5 millions d’adresses e-mail appartenant à de grandes entreprises françaises et à des institutions du gouvernement. Laissée en accès libre sur Internet, une base de données a divulgué une montagne de données sensibles. tinyurl.com/3y7cahs6
Français
0
3
2
219