Summary There is a vulnerability in the Huawei Kirin SoC’s DDR Controller (DMSS) Access Permission system which allows the baseband to bypass the Baseband’s MPU memory protections and circumvent RO and NX protections. The vulnerability was fixed in February 2022.
Vulnerability Details CVE-2021-22430...
Summary Last year we published research at Black Hat in which we disclosed multiple vulnerabilities in Huawei Kirin SoC’s DDR Controller (DMSS) Access Permission system which allowed some SoC cores or DMA-capable peripherals to directly access secure world memory and completely compromise the entire...
Ransomware impacted certain internal systems
Summary Last year we published research at Black Hat in which we disclosed multiple vulnerabilities in Huawei Kirin SoC’s DDR Controller (DMSS) Access Permission system which allowed some SoC cores or DMA-capable peripherals to directly access secure world memory and completely compromise the entire...
Summary Last year we published research at Black Hat in which we disclosed multiple vulnerabilities in Huawei Kirin SoC’s DDR Controller (DMSS) Access Permission system which allowed some SoC cores or DMA-capable peripherals to directly access secure world memory and completely compromise the entire...
North Korean IT workers are attempting to generate revenue for DPRK and conduct cyber intrusions
Summary There is a vulnerability in the Huawei Kirin SoC’s DDR Controller (DMSS) Access Permission system which allows the Linux kernel to bypass memory access restrictions and directly compromise multiple privileged subsystems of the SoC. As demonstrated by CVE-2021-3710, CVE-2021-39991, CVE-2021-3...
Summary In this advisory we are disclosing a signature verification bypass vulnerability in the Huawei recovery mode. The vulnerability can be used not only to apply unauthentic firmware updates but also to achieve arbitrary code execution in the recovery mode. Combining this advisory with the vulne...
Rellic is a framework for analyzing and decompiling LLVM modules into C code, implementing the concepts described in the original paper presenting the Dream decompiler and its successor, Dream++. It recently made an appearance on this blog when I presented rellic-headergen, a tool for extracting deb...
Summary In this advisory we are disclosing a vulnerability in the Huawei Over-The-Air (OTA) update implementation that allows bypassing SSL protections and execute a Man-In-The-Middle attack. The vulnerability was fixed in March 2022.
Vulnerability Details Huawei devices - both those running Android...
The 100K in the UK scheme is aimed at recent graduates and career changers seeking to work in cyber
Attacks surge 12% in 2021, according to leading insurer
How to work with stolen IAM credentials and things to consider.
Venezuelan linked to Jigsaw and Thanos variants
Range of initiatives will push back against Russia and China
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in April:
Known Issues
10G SFP+ interfaces (eth8/eth9) on Firebox M590/M690 do not respond to traffic
After upgrade to Fireware 12.8, IKEv2 BOVPNs that use VPN failover a...
The company announced that employees’ personally identifiable information was exposed in the breach
Microsoft advised organizations running Windows or Linux on internet-facing systems to take action
Last week, over 500 cryptographers from around the world gathered in Amsterdam for Real World Crypto 2022, meeting in person for the first time in over two years. As in previous years, we dispatched a handful of our researchers and engineers to attend the conference, listen to talks, and schmooze ob...
Radcliffe will be officially inducted into the Hall of Fame during a keynote session at this year’s Infosecurity Europe 2022