pouet.chapril.org est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Chapril https://www.chapril.org est un projet de l'April https://www.april.org

Administré par :

Statistiques du serveur :

1,1K
comptes actifs

#office

15 messages14 participants3 messages aujourd’hui

Atomic and Exodus crypto wallets targeted in malicious npm campaign

A malicious npm package named pdf-to-office was discovered targeting cryptocurrency wallets. The package, posing as a PDF to Office converter, injects malicious code into locally installed Atomic and Exodus wallets. This attack modifies legitimate files to redirect crypto funds to the attacker's wallet. The campaign shows persistence, as removing the malicious package doesn't remove the injected code from the wallets. Multiple versions of both wallets were targeted, with the attackers adapting their code accordingly. This incident highlights the growing scope of software supply chain risks, particularly in the cryptocurrency industry, and emphasizes the need for improved monitoring of both source code repositories and locally deployed applications.

Pulse ID: 67fd41f7af4b02a0fd75fb69
Pulse Link: otx.alienvault.com/pulse/67fd4
Pulse Author: AlienVault
Created: 2025-04-14 17:12:23

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.
Suite du fil

Microsoft Office 2016 and Office 2019 will no longer receive software updates, technical support, or bug and security fixes after 14.10.2025.

Consider migrating to LibreOffice.

400 million downloads.
Used by businesses, governments, and individuals.

SOURCE
blog.documentfoundation.org/bl
libreoffice.org/discover/who-u
blog.documentfoundation.org/bl

Website: libreoffice.org
Mastodon: @libreoffice

2/4

Atomic and Exodus crypto wallets targeted in malicious npm campaign

Threat actors are employing new techniques to target the cryptocurrency community by uploading packages to popular open source repositories that apply malicious 'patches' to local versions of legitimate libraries. A recent campaign launched on April 1 published a package called 'pdf-to-office' on npm, which injected malicious code into locally installed Atomic Wallet and Exodus crypto wallet software. This attack overwrote existing files, allowing attackers to swap out intended wallet destination addresses with their own. The malicious package was designed to target specific versions of the wallets and included persistence mechanisms. This campaign is part of a larger trend of sophisticated software supply chain attacks targeting the cryptocurrency industry, highlighting the need for improved monitoring and security measures in both commercial and open-source software.

Pulse ID: 67f80a491ab75c1a71050453
Pulse Link: otx.alienvault.com/pulse/67f80
Pulse Author: AlienVault
Created: 2025-04-10 18:13:29

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

Pick your Poison - A Double-Edged Email Attack

A sophisticated cyber-attack has been identified by the Cofense Phishing Defense Center, combining phishing techniques targeting Office365 credentials with malware delivery. The campaign uses a file deletion reminder as bait, exploiting a legitimate file-sharing service to increase credibility. Users are led to a fake Microsoft login page or prompted to download malware disguised as a OneDrive installer. The attack employs ConnectWise RAT, a legitimate remote administration tool exploited for malicious purposes. The malware establishes persistence through system services and registry modifications, highlighting the need for enhanced user awareness and education to combat such dual-threat approaches.

Pulse ID: 67f59820a8fab9815ec86721
Pulse Link: otx.alienvault.com/pulse/67f59
Pulse Author: AlienVault
Created: 2025-04-08 21:41:51

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.
A répondu dans un fil de discussion

@timnitGebru Boycott, divest, sanction Microsoft → bdsmovement.net/microsoft

"The Palestinian-led BDS movement, supported by Microsoft workers, calls on people of conscious to pressure Microsoft to end its complicity in Israeli apartheid and AI-powered genocide. To pressure Microsoft, boycott Microsoft’s consumer products whenever possible"

BDS MovementMicrosoftMicrosoft is perhaps the most complicit tech company in Israel’s illegal apartheid regime and ongoing genocide against 2.3 million Palestinians in Gaza.
A répondu dans un fil de discussion

@heiseonlineenglish Microsoft are right about MS Office being "impractical and too expensive" (and that is not even the worst part about it). They got the solution wrong though. The practical and free and Free (as in freedom and opensource and privacy respecting) is something like LibreOffice → libreoffice.org/

@libreoffice

www.libreoffice.orgHome | LibreOffice - Free and private office suite - Based on OpenOffice - Compatible with MicrosoftFree office suite – the evolution of OpenOffice. Compatible with Microsoft .doc, .docx, .xls, .xlsx, .ppt, .pptx. Updated regularly, community powered.
A répondu dans un fil de discussion

@ulrichkelber Finde ich prinzipiell eine sehr gute Entscheidung!
Aber über #Office und #Kollaboration hinaus: Welche Alternativen zu #Microsoft #CoPilot plant @zendis im Bereich Generative #KI aufzubauen, zu betreiben und anzubieten und wie schnell? Mit einem kleinen Entwickler-Team wird das kaum zu schaffen sein.
Um bei unserer schleppenden Digitalisierung, sehr hohem bürokratischen Aufwand und viel zu geringer Personalstärke die notwendige Fahrt aufzunehmen wird eine reine Office- und Kollaborationsplattform nicht ausreichen. So kritisch ich die #KI Entwicklung derzeit sehe - ohne KI- und Agenten-Systeme bleiben wir in Deutschland bei der #Digitalisierung weiter im Hintertreffen - und somit international im Nachteil - zusätzlich zu unserem Föderalismusproblem. Daher müssen wir uns auch bei KI souverän aufstellen - aber dürfen natürlich auch hier keinesfalls auf Lösungen von US-Unternehmen setzen.
#GenerativeAI #OpenDesk #Zendis