{"id":23361,"date":"2022-03-08T15:51:13","date_gmt":"2022-03-08T17:51:13","guid":{"rendered":"https:\/\/teknomers.com\/fr\/samsung-confirme-une-violation-de-donnees-apres-que-des-pirates-ont-divulgue-le-code-source-de-galaxy\/"},"modified":"2022-03-08T15:51:28","modified_gmt":"2022-03-08T17:51:28","slug":"samsung-confirme-une-violation-de-donnees-apres-que-des-pirates-ont-divulgue-le-code-source-de-galaxy","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/samsung-confirme-une-violation-de-donnees-apres-que-des-pirates-ont-divulgue-le-code-source-de-galaxy\/","title":{"rendered":"Samsung confirme une violation de donn\u00e9es apr\u00e8s que des pirates ont divulgu\u00e9 le code source de Galaxy"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Samsung a confirm\u00e9 lundi une faille de s\u00e9curit\u00e9 qui a entra\u00een\u00e9 l&#8217;exposition de donn\u00e9es internes \u00e0 l&#8217;entreprise, y compris le code source li\u00e9 \u00e0 ses smartphones Galaxy.<\/p>\n<p>&#8220;Selon notre analyse initiale, la violation implique du code source relatif au fonctionnement des appareils Galaxy, mais n&#8217;inclut pas les informations personnelles de nos consommateurs ou employ\u00e9s&#8221;, a d\u00e9clar\u00e9 le g\u00e9ant de l&#8217;\u00e9lectronique. <a rel=\"nofollow noopener\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2022-03-07\/samsung-says-hackers-breached-company-data-galaxy-source-code\" target=\"_blank\">Racont\u00e9<\/a> Bloomberg.<\/p>\n<p>Le chaebol sud-cor\u00e9en a \u00e9galement confirm\u00e9 qu&#8217;il ne pr\u00e9voyait aucun impact sur son activit\u00e9 ou ses clients \u00e0 la suite de l&#8217;incident et qu&#8217;il avait mis en place de nouvelles mesures de s\u00e9curit\u00e9 pour emp\u00eacher de telles violations \u00e0 l&#8217;avenir.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset2\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Alertes-CISA-sur-les-failles-activement-exploitees-dans-la-plate-forme.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>La confirmation intervient apr\u00e8s que le groupe de piratage LAPSUS$ a vid\u00e9 190 Go de donn\u00e9es Samsung sur sa cha\u00eene Telegram vers la fin de la semaine derni\u00e8re, exposant pr\u00e9tendument le code source des applets de confiance install\u00e9s dans TrustZone, des algorithmes d&#8217;authentification biom\u00e9trique, des chargeurs de d\u00e9marrage pour les appareils r\u00e9cents et m\u00eame confidentiels. donn\u00e9es de son fournisseur de puces Qualcomm.<\/p>\n<p>La nouvelle de la fuite a \u00e9t\u00e9 la premi\u00e8re <a rel=\"nofollow noopener\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-leak-190gb-of-alleged-samsung-data-source-code\/\" target=\"_blank\">signal\u00e9<\/a> par Bleeping Computer le 4 mars 2022.<\/p>\n<p>Si le nom LAPSUS$ sonne familier, c&#8217;est le m\u00eame gang d&#8217;extorqueurs qui a vol\u00e9 1 To de donn\u00e9es propri\u00e9taires de NVIDIA le mois dernier, \u00e0 savoir les informations d&#8217;identification des employ\u00e9s, les sch\u00e9mas, le code source du pilote et les informations relatives aux nouvelles puces graphiques.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"Code source Samsung Galaxy\" border=\"0\" data-original-height=\"482\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646761873_518_Samsung-confirme-une-violation-de-donnees-apres-que-des-pirates.jpeg\" title=\"Code source Samsung Galaxy\" \/><\/div>\n<p>Le groupe, qui est apparu pour la premi\u00e8re fois fin d\u00e9cembre 2021, a \u00e9galement lanc\u00e9 une demande inhabituelle exhortant la soci\u00e9t\u00e9 \u00e0 ouvrir ses pilotes GPU pour toujours et \u00e0 supprimer son plafond d&#8217;extraction de crypto-monnaie Ethereum de tous les GPU NVIDIA de la s\u00e9rie 30 pour \u00e9viter davantage de fuites.<\/p>\n<p>Il n&#8217;est pas imm\u00e9diatement clair si LAPSUS$ a fait des demandes similaires \u00e0 Samsung avant de publier les informations.<\/p>\n<p>Les retomb\u00e9es des fuites de NVIDIA ont \u00e9galement conduit \u00e0 la <a rel=\"nofollow noopener\" href=\"https:\/\/haveibeenpwned.com\/PwnedWebsites#NVIDIA\" target=\"_blank\">Lib\u00e9ration<\/a> de &#8220;plus de 70 000 adresses e-mail d&#8217;employ\u00e9s et hachages de mots de passe NTLM, dont beaucoup ont ensuite \u00e9t\u00e9 craqu\u00e9s et diffus\u00e9s au sein de la communaut\u00e9 des pirates&#8221;.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646326908_645_Correctifs-critiques-publies-pour-la-gamme-Cisco-Expressway-les-produits.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Ce n&#8217;est pas tout.  Deux certificats de signature de code <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/BillDemirkapi\/status\/1499437244830175236\" target=\"_blank\">inclus<\/a> dans le vidage du cache de NVIDIA ont \u00e9t\u00e9 utilis\u00e9s pour signer des pilotes Windows malveillants et <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/cyb3rops\/status\/1499514240008437762\" target=\"_blank\">autre<\/a> <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/cyb3rops\/status\/1500091665595387909\" target=\"_blank\">outils<\/a> souvent utilis\u00e9 par les \u00e9quipes de piratage, \u00e0 savoir les balises Cobalt Strike, Mimikatz et d&#8217;autres chevaux de Troie d&#8217;acc\u00e8s \u00e0 distance.<\/p>\n<p>&#8220;Les acteurs de la menace ont commenc\u00e9 le 1er mars, un jour apr\u00e8s torrent [was] post\u00e9&#8221;, le chercheur en s\u00e9curit\u00e9 Kevin Beaumont <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1499781976835993600\" target=\"_blank\">mentionn\u00e9<\/a> dans un tweet la semaine derni\u00e8re.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/samsung-confirms-data-breach-after.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Samsung a confirm\u00e9 lundi une faille de s\u00e9curit\u00e9 qui a entra\u00een\u00e9 l&#8217;exposition de donn\u00e9es internes \u00e0 l&#8217;entreprise, y compris le code source li\u00e9 \u00e0 ses smartphones Galaxy. &#8220;Selon notre analyse initiale, la violation implique du code source relatif au fonctionnement des appareils Galaxy, mais n&#8217;inclut pas les informations personnelles de nos consommateurs ou employ\u00e9s&#8221;, a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":23362,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[271,5597,4168,845,4158,4165,4161,133,6905,1343,10778,4157,4159,4171,4170,4167,4160,4163,4162,249,4394,7850,4172,4169,11137,196,899,4166,4164],"class_list":["post-23361","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-apres","tag-code","tag-comment-pirater","tag-confirme","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-divulgue","tag-donnees","tag-galaxy","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-ont","tag-pirates","tag-samsung","tag-securite-informatique","tag-securite-internet","tag-source","tag-une","tag-violation","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/23361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=23361"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/23361\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/23362"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=23361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=23361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=23361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}