{"id":414309,"date":"2023-05-25T19:45:57","date_gmt":"2023-05-25T18:45:57","guid":{"rendered":"https:\/\/www.stormshield.com\/?p=414309"},"modified":"2024-05-29T08:59:19","modified_gmt":"2024-05-29T07:59:19","slug":"alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield","status":"publish","type":"post","link":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/","title":{"rendered":"Alerte s\u00e9curit\u00e9 Volt Typhoon : la r\u00e9ponse des produits Stormshield"},"content":{"rendered":"<p><strong>Une attaque persistante (APT) de grande envergure r\u00e9alis\u00e9e par le groupe de cyber-criminels chinois nomm\u00e9 Volt Typhoon vient d\u2019\u00eatre signal\u00e9e par le gouvernement am\u00e9ricain, conjointement avec plusieurs entit\u00e9s priv\u00e9es dans la cybers\u00e9curit\u00e9. Cette cyberattaque a cibl\u00e9 des infrastructures am\u00e9ricaines critiques et semble \u00eatre infiltr\u00e9e depuis 2021.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h2>Le contexte de l'attaque Volt Typhoon<\/h2>\n<p>La NSA a publi\u00e9 le 24 mai 2023 <a href=\"https:\/\/media.defense.gov\/2023\/May\/24\/2003229517\/-1\/-1\/0\/CSA_Living_off_the_Land.PDF\" target=\"_blank\" rel=\"noopener\">l'analyse d\u2019une APT chinoise<\/a> ciblant les infrastructures am\u00e9ricaines critiques dans les secteurs de la communication, le transport, la construction, la marine ou encore l\u2019\u00e9ducation. Une attaque attribu\u00e9e au groupe Volt Typhoon. Un groupe qui n\u2019en serait pas \u00e0 son premier coup, puisqu\u2019il serait connu aussi sous le nom de <a href=\"https:\/\/www.secureworks.com\/blog\/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations\" target=\"_blank\" rel=\"noopener\">Bronze Silhouette<\/a> (une analyse de l'entreprise SecureWork).<\/p>\n<p>Ce document relate <strong>une cyberattaque dont l\u2019objectif principal est l\u2019espionnage et l\u2019exfiltration de donn\u00e9es par des moyens les plus discrets possibles<\/strong>.<\/p>\n<p>La collecte d\u2019informations <a href=\"https:\/\/lolbas-project.github.io\" target=\"_blank\" rel=\"noopener\">exploite massivement l\u2019usage de LOLBin<\/a>\u00a0dans le but de contourner les restrictions d\u2019ex\u00e9cutions potentiellement effectives sur les postes de travail et limiter au maximum de d\u00e9clencher des alertes de s\u00e9curit\u00e9.<\/p>\n<p>Pour exfiltrer les donn\u00e9es vers son C&amp;C, le groupe Volt Typhoon a utilis\u00e9 des relais cr\u00e9\u00e9s suite \u00e0 compromission pr\u00e9alable d\u2019\u00e9quipements SoHo (<em>Small Office \/ Home Office<\/em>), notamment des routeurs, firewall ou VPN de diff\u00e9rentes marques et gammes (ASUS, Cisco RV, Draytek Vigor, D-Link, FatPipe IPVPN \/ MPVPN \/ WARP, Netgear Prosafe, ou encore Zyxel USG). Ce principe permet de masquer au maximum ces communications.<\/p>\n<p>&nbsp;<\/p>\n<h2>Le vecteur initial de l'attaque Volt Typhoon<\/h2>\n<p>L\u2019acc\u00e8s initial de cette cyberattaque a \u00e9t\u00e9 conduit sur des \u00e9quipements Fortigate de Fortinet qui auraient permis ensuite aux cyber-criminels de collecter des donn\u00e9es d\u2019authentification aupr\u00e8s de l\u2019AD auquel ils seraient rattach\u00e9s. Ils auraient ensuite tent\u00e9 d\u2019utiliser ces informations de connexion sur d\u2019autres \u00e9quipements du r\u00e9seau.<\/p>\n<p>Aucune information n\u2019est donn\u00e9e concernant les vuln\u00e9rabilit\u00e9s exploit\u00e9es sur les \u00e9quipements Fortigate ou sur les \u00e9quipements r\u00e9seaux utilis\u00e9s comme relais de communication vers le serveur de contr\u00f4le.<\/p>\n<p>&nbsp;<\/p>\n<h2>Les d\u00e9tails techniques de l'attaque Volt Typhoon<\/h2>\n<p>Une fois les acc\u00e8s au r\u00e9seau obtenus, le groupe Volt Typhoon \/ Bronze Silhouette a ensuite lourdement exploit\u00e9 les fameux <a href=\"https:\/\/www.stormshield.com\/fr\/actus\/fileless-malware-comment-ca-marche\/\">LOLBins<\/a> afin de contourner les politiques de restriction d\u2019ex\u00e9cution des postes de travail ainsi que pour maximiser la discr\u00e9tion.<\/p>\n<p>On retrouve notamment l\u2019usage des binaires \/ commandes suivants (liste non exhaustive)\u00a0:<\/p>\n<ul>\n<li>wmic process call create [\u2026]<\/li>\n<li>netsh interface portproxy [\u2026]<\/li>\n<li>netsh interface firewall [\u2026]<\/li>\n<li>net group [\u2026]<\/li>\n<li>net localgroup [\u2026]<\/li>\n<li>dnscmd \/enumrecords<\/li>\n<li>ipconfig<\/li>\n<li>Get-EventLog security -instanceid 4624<\/li>\n<li>reg query<\/li>\n<li>reg save<\/li>\n<li>certutil<\/li>\n<li>makecab<\/li>\n<li>etc.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Attaque Volt Typhoon et moyens de protection Stormshield<\/h2>\n<h3>Stormshield Network Security<\/h3>\n<p>La signature IPS suivante permet de d\u00e9tecter l\u2019usage d\u2019exploitation de la vuln\u00e9rabilit\u00e9 <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-40539\" target=\"_blank\" rel=\"noopener\">CVE-2021-40539<\/a> impactant ManageEngine utilis\u00e9e par le groupe Volt Typhoon :<\/p>\n<ul>\n<li><strong>http:79 <\/strong>-&gt; Directory self reference contre la vuln\u00e9rabilit\u00e9 CVE-2021-40539<\/li>\n<\/ul>\n<table class=\" aligncenter\" width=\"623\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" width=\"312\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-227874\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p><em>Indice de confiance de la protection propos\u00e9e par Stormshield<\/em><\/td>\n<td width=\"312\">\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-227874\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p style=\"text-align: center;\"><em>Indice de confiance de l\u2019absence de faux positif<\/em><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Une autre signature permet de bloquer une tentative de reconnaissance effectu\u00e9e par le groupe. Le d\u00e9chiffrement SSL au pr\u00e9alable est n\u00e9cessaire.<\/p>\n<ul>\n<li><strong>http:client:header:useragent.110 <\/strong>-&gt; Threat actor recon activity<\/li>\n<\/ul>\n<table class=\" aligncenter\" width=\"623\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" width=\"312\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-232004 size-full\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice-2.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p><em>Indice de confiance de la protection propos\u00e9e par Stormshield<\/em><\/td>\n<td width=\"312\">\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-227874\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p style=\"text-align: center;\"><em>Indice de confiance de l\u2019absence de faux positif<\/em><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Les IPs utilis\u00e9es par les serveurs de contr\u00f4le de Bronze Silhouette, qui est tr\u00e8s probablement Volt Typhoon, ont \u00e9t\u00e9 ajout\u00e9es au moteur de r\u00e9putation dans la cat\u00e9gorie \u00ab\u00a0malware\u00a0\u00bb.<\/p>\n<p>Enfin, les \u00e9chantillons des binaires impliqu\u00e9s dans l\u2019attaque sont d\u00e9tect\u00e9s par la solution de d\u00e9tonation <a href=\"https:\/\/www.stormshield.com\/fr\/produits-et-services\/produits\/protection-des-reseaux\/nos-produits\/sandbox-breach-fighter\/\">Breach Fighter<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h3>Stormshield Endpoint Security Evolution<\/h3>\n<p>Les jeux de r\u00e8gles suivants de la politique par d\u00e9faut en version 2304a ou 2211b sont d\u00e9j\u00e0 capables de d\u00e9tecter de nombreuses ex\u00e9cutions de processus employ\u00e9es durant l\u2019attaque par l\u2019acteur malveillant\u00a0:<\/p>\n<ul>\n<li>Stormshield - Socle de protections<\/li>\n<li>Stormshield - Pr\u00e9vention des fuites d'informations<\/li>\n<li>Stormshield - Protection contre l'utilisation malveillante des LOLBIN<\/li>\n<li>Stormshield - Blocage des applications malveillantes connues<\/li>\n<li>Stormshield - Protections avanc\u00e9es<\/li>\n<\/ul>\n<p>Il est donc important de confirmer que ces jeux de r\u00e8gles sont bien actifs et dans leur version la plus r\u00e9cente dans les politiques appliqu\u00e9es par les agents du parc.<\/p>\n<table class=\" aligncenter\" width=\"623\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" width=\"312\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-227874\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p><em>Indice de confiance de la protection propos\u00e9e par Stormshield<\/em><\/td>\n<td width=\"312\">\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-227874\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p style=\"text-align: center;\"><em>Indice de confiance de l\u2019absence de faux positif<\/em><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Une unit\u00e9 d\u2019analyse YARA, nomm\u00e9e \u00ab APT \u2013 Volt Typhoon \u00bb, est aussi disponible d\u00e8s \u00e0 pr\u00e9sent sur le serveur de mise \u00e0 jour de SES et permet de rechercher des traces de l\u2019attaque.<\/p>\n<table class=\" aligncenter\" width=\"623\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\" width=\"312\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-233125\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice-3.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p><em>Indice de confiance de la protection propos\u00e9e par Stormshield<\/em><\/td>\n<td width=\"312\">\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-233125\" src=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/indice-3.png\" alt=\"\" width=\"135\" height=\"101\" \/><\/p>\n<p style=\"text-align: center;\"><em>Indice de confiance de l\u2019absence de faux positif<\/em><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3>Recommandations<\/h3>\n<p>Il est fortement recommand\u00e9 de surveiller l\u2019ex\u00e9cution des commandes utilis\u00e9es dans l\u2019attaque ainsi que de limiter l\u2019usage de proxy de port au maximum.<\/p>\n<p>&nbsp;<\/p>\n<h2>Attaque Volt Typhoon &amp; IOC<\/h2>\n<p>IOCs Volt Typhoon : retrouvez ici les indicateurs de compromission relatifs \u00e0 l\u2019attaque.<\/p>\n<h3>Hashes<\/h3>\n<p>SHA256 : f4dd44bc19c19056794d29151a5b1bb76afd502388622e24c863a8494af147dd<\/p>\n<p>SHA256 : ef09b8ff86c276e9b475a6ae6b54f08ed77e09e169f7fc0872eb1d427ee27d31<\/p>\n<p>SHA256 : d6ebde42457fe4b2a927ce53fc36f465f0000da931cfab9b79a36083e914ceca<\/p>\n<p>SHA256 : 472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d<\/p>\n<p>SHA256 : 66a19f7d2547a8a85cee7a62d0b6114fd31afdee090bd43f36b89470238393d7<\/p>\n<p>SHA256 : 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71<\/p>\n<p>SHA256 : 41e5181b9553bbe33d91ee204fe1d2ca321ac123f9147bb475c0ed32f9488597<\/p>\n<p>SHA256 : c7fee7a3ffaf0732f42d89c4399cbff219459ae04a81fc6eff7050d53bd69b99<\/p>\n<p>SHA256 : 3a9d8bb85fbcfe92bae79d5ab18e4bca9eaf36cea70086e8d1ab85336c83945f<\/p>\n<p>SHA256 : fe95a382b4f879830e2666473d662a24b34fccf34b6b3505ee1b62b32adafa15<\/p>\n<p>SHA256 : ee8df354503a56c62719656fae71b3502acf9f87951c55ffd955feec90a11484<\/p>\n<h3>IPs<\/h3>\n<p>104.161.54.203 : C&amp;C Volt Typhoon \/ Bronze Silhouette<\/p>\n<p>23.227.198.247 : C&amp;C Volt Typhoon \/ Bronze Silhouette<\/p>\n<p>109.166.39.139 : C&amp;C Volt Typhoon \/ Bronze Silhouette<\/p>\n<h3>User agent<\/h3>\n<p>Mozilla\/5.0 (Windows NT 6.1; WOW64; rv:68.0)\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Gecko\/20100101 Firefox\/68.0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Une attaque persistante (APT) de grande envergure r\u00e9alis\u00e9e par le groupe de cyber-criminels chinois nomm\u00e9 Volt Typhoon vient d\u2019\u00eatre signal\u00e9e par le gouvernement am\u00e9ricain, conjointement avec plusieurs entit\u00e9s priv\u00e9es dans la cybers\u00e9curit\u00e9. Cette cyberattaque a cibl\u00e9 des infrastructures am\u00e9ricaines critiques et semble \u00eatre infiltr\u00e9e depuis&#8230;<\/p>\n","protected":false},"author":72,"featured_media":190179,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1503],"tags":[4368],"business_size":[],"industry":[],"help_mefind":[],"features":[],"type_security":[],"maintenance":[],"offer":[],"administration_tools":[],"cloud_offers":[],"listing_product":[1565,1530],"class_list":["post-414309","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alertes","tag-la-cybersecurite-par-stormshield","listing_product-ses-fr","listing_product-sns-fr"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Volt Typhoon : quelles protections avec les produits Stormshield ?<\/title>\n<meta name=\"description\" content=\"Alerte de s\u00e9curit\u00e9 du groupe APT chinois Volt Typhoon sur les infrastructures militaires am\u00e9ricaines. La r\u00e9ponse des produits Stormshield.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Volt Typhoon : quelles protections avec les produits Stormshield ?\" \/>\n<meta property=\"og:description\" content=\"Alerte de s\u00e9curit\u00e9 du groupe APT chinois Volt Typhoon sur les infrastructures militaires am\u00e9ricaines. La r\u00e9ponse des produits Stormshield.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/\" \/>\n<meta property=\"og:site_name\" content=\"Stormshield\" \/>\n<meta property=\"article:published_time\" content=\"2023-05-25T18:45:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-29T07:59:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock_1534485395-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1422\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Edouard Simpere\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Stormshield\" \/>\n<meta name=\"twitter:site\" content=\"@Stormshield\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Edouard Simpere\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/\"},\"author\":{\"name\":\"Edouard Simpere\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#\\\/schema\\\/person\\\/f2b09771507d722f3084b11a9b22aa53\"},\"headline\":\"Alerte s\u00e9curit\u00e9 Volt Typhoon : la r\u00e9ponse des produits Stormshield\",\"datePublished\":\"2023-05-25T18:45:57+00:00\",\"dateModified\":\"2024-05-29T07:59:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/\"},\"wordCount\":1085,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock_1534485395-scaled.jpg\",\"keywords\":[\"La cybers\u00e9curit\u00e9 - par Stormshield\"],\"articleSection\":[\"Alertes\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/\",\"url\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/\",\"name\":\"Volt Typhoon : quelles protections avec les produits Stormshield ?\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock_1534485395-scaled.jpg\",\"datePublished\":\"2023-05-25T18:45:57+00:00\",\"dateModified\":\"2024-05-29T07:59:19+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#\\\/schema\\\/person\\\/f2b09771507d722f3084b11a9b22aa53\"},\"description\":\"Alerte de s\u00e9curit\u00e9 du groupe APT chinois Volt Typhoon sur les infrastructures militaires am\u00e9ricaines. La r\u00e9ponse des produits Stormshield.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock_1534485395-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock_1534485395-scaled.jpg\",\"width\":2560,\"height\":1422},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Alerte s\u00e9curit\u00e9 Volt Typhoon : la r\u00e9ponse des produits Stormshield\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#website\",\"url\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/\",\"name\":\"Stormshield\",\"description\":\"Stormshield\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#\\\/schema\\\/person\\\/f2b09771507d722f3084b11a9b22aa53\",\"name\":\"Edouard Simpere\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d21e23df04a1d5fa2e7754ae2fc9c80a1a78001781fe235cfcd44db1f16003e5?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d21e23df04a1d5fa2e7754ae2fc9c80a1a78001781fe235cfcd44db1f16003e5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d21e23df04a1d5fa2e7754ae2fc9c80a1a78001781fe235cfcd44db1f16003e5?s=96&d=mm&r=g\",\"caption\":\"Edouard Simpere\"},\"description\":\"With a strong appetite for dark humor, starred chefs' pastries and the Windows environment, Edouard is a cybersecurity buff, a real one. A living standard of internal mobility at Stormshield, he made his first, second and third steps around the Stormshield Endpoint Security Evolution product, as a developer, architect and technical leader. He then became head of the company's Threat Intelligence team, in charge of researching and maintaining the level of protection of all the company's products.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Volt Typhoon : quelles protections avec les produits Stormshield ?","description":"Alerte de s\u00e9curit\u00e9 du groupe APT chinois Volt Typhoon sur les infrastructures militaires am\u00e9ricaines. La r\u00e9ponse des produits Stormshield.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/","og_locale":"fr_FR","og_type":"article","og_title":"Volt Typhoon : quelles protections avec les produits Stormshield ?","og_description":"Alerte de s\u00e9curit\u00e9 du groupe APT chinois Volt Typhoon sur les infrastructures militaires am\u00e9ricaines. La r\u00e9ponse des produits Stormshield.","og_url":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/","og_site_name":"Stormshield","article_published_time":"2023-05-25T18:45:57+00:00","article_modified_time":"2024-05-29T07:59:19+00:00","og_image":[{"width":2560,"height":1422,"url":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock_1534485395-scaled.jpg","type":"image\/jpeg"}],"author":"Edouard Simpere","twitter_card":"summary_large_image","twitter_creator":"@Stormshield","twitter_site":"@Stormshield","twitter_misc":{"\u00c9crit par":"Edouard Simpere","Dur\u00e9e de lecture estim\u00e9e":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/#article","isPartOf":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/"},"author":{"name":"Edouard Simpere","@id":"https:\/\/www.stormshield.com\/fr\/#\/schema\/person\/f2b09771507d722f3084b11a9b22aa53"},"headline":"Alerte s\u00e9curit\u00e9 Volt Typhoon : la r\u00e9ponse des produits Stormshield","datePublished":"2023-05-25T18:45:57+00:00","dateModified":"2024-05-29T07:59:19+00:00","mainEntityOfPage":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/"},"wordCount":1085,"commentCount":0,"image":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/#primaryimage"},"thumbnailUrl":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock_1534485395-scaled.jpg","keywords":["La cybers\u00e9curit\u00e9 - par Stormshield"],"articleSection":["Alertes"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/","url":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/","name":"Volt Typhoon : quelles protections avec les produits Stormshield ?","isPartOf":{"@id":"https:\/\/www.stormshield.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/#primaryimage"},"image":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/#primaryimage"},"thumbnailUrl":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock_1534485395-scaled.jpg","datePublished":"2023-05-25T18:45:57+00:00","dateModified":"2024-05-29T07:59:19+00:00","author":{"@id":"https:\/\/www.stormshield.com\/fr\/#\/schema\/person\/f2b09771507d722f3084b11a9b22aa53"},"description":"Alerte de s\u00e9curit\u00e9 du groupe APT chinois Volt Typhoon sur les infrastructures militaires am\u00e9ricaines. La r\u00e9ponse des produits Stormshield.","breadcrumb":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/#primaryimage","url":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock_1534485395-scaled.jpg","contentUrl":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock_1534485395-scaled.jpg","width":2560,"height":1422},{"@type":"BreadcrumbList","@id":"https:\/\/www.stormshield.com\/fr\/actus\/alerte-securite-volt-typhoon-la-reponse-des-produits-stormshield\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.stormshield.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Alerte s\u00e9curit\u00e9 Volt Typhoon : la r\u00e9ponse des produits Stormshield"}]},{"@type":"WebSite","@id":"https:\/\/www.stormshield.com\/fr\/#website","url":"https:\/\/www.stormshield.com\/fr\/","name":"Stormshield","description":"Stormshield","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.stormshield.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/www.stormshield.com\/fr\/#\/schema\/person\/f2b09771507d722f3084b11a9b22aa53","name":"Edouard Simpere","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/d21e23df04a1d5fa2e7754ae2fc9c80a1a78001781fe235cfcd44db1f16003e5?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d21e23df04a1d5fa2e7754ae2fc9c80a1a78001781fe235cfcd44db1f16003e5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d21e23df04a1d5fa2e7754ae2fc9c80a1a78001781fe235cfcd44db1f16003e5?s=96&d=mm&r=g","caption":"Edouard Simpere"},"description":"With a strong appetite for dark humor, starred chefs' pastries and the Windows environment, Edouard is a cybersecurity buff, a real one. A living standard of internal mobility at Stormshield, he made his first, second and third steps around the Stormshield Endpoint Security Evolution product, as a developer, architect and technical leader. He then became head of the company's Threat Intelligence team, in charge of researching and maintaining the level of protection of all the company's products."}]}},"_links":{"self":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts\/414309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/users\/72"}],"replies":[{"embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/comments?post=414309"}],"version-history":[{"count":8,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts\/414309\/revisions"}],"predecessor-version":[{"id":414334,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts\/414309\/revisions\/414334"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/media\/190179"}],"wp:attachment":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/media?parent=414309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/categories?post=414309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/tags?post=414309"},{"taxonomy":"business_size","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/business_size?post=414309"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/industry?post=414309"},{"taxonomy":"help_mefind","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/help_mefind?post=414309"},{"taxonomy":"features","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/features?post=414309"},{"taxonomy":"type_security","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/type_security?post=414309"},{"taxonomy":"maintenance","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/maintenance?post=414309"},{"taxonomy":"offer","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/offer?post=414309"},{"taxonomy":"administration_tools","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/administration_tools?post=414309"},{"taxonomy":"cloud_offers","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/cloud_offers?post=414309"},{"taxonomy":"listing_product","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/listing_product?post=414309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}