[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> Using procdump on Linux to dump credentials
I like using procdump on Windows. It’s quite handy for software development when systems have memory leaks or performance issues, procdump allows to set thresholds to trigger creation of a core dump. BUT, it’s also super useful to search processes for secrets and other information. For instance, thi...
> New Android Trojan Hijacks Social Media
FlyTrap malware hits over 140 countries to claim more than 10,000 victims
> Virtual Vaccination Card Prompts Cybersecurity Fears
Poll shows Americans and Brits doubt the cyber-safety of possible digital COVID-19 vaccination card
> CVE-2021-22388: Huawei NPU Kernel Driver Function Pointer Overwrite
Summary The NPU device’s kernel driver implements a set of ioctl handlers one of which uses unsanitized user data as an index into a function pointer array. The user provided values can exceed the boundaries of the legitimate array and might cause user controlled values to be called as function poin...
> Average Ransomware Demands Surge by 518% in 2021
Payments also climb by 82% in the same period
> May 2021 Saw a 440% Increase in Phishing
Around half of businesses and consumers saw at least one sustained additional infection in May 2021, according to a new Webroot report
> CVE-2021-22389: Huawei NPU Kernel Driver Exposes Kernel Structures in Shared Memory
Summary The NPU device’s kernel driver implements a custom mmap handler that exposes trusted kernel data to user space. These exposed structures contain sensitive data, including kernel pointers, which can be controlled by a user process. The content of these structures is inherently trusted by the...
> House of Commons Beefs up Cyber Training Following Matt Hancock CCTV Leak Scandal
2,658 HoC staff members were put through a cybersecurity training course during the 2020/21 financial year
> NCSC Sticks by 'Three Random Words' Strategy for Passwords
Using random words is more effective than using complex combinations for passwords, says the National Cyber Security Council (NCSC)
> CVE-2021-22390: Huawei NPU Kernel Driver Use-After-Free
Summary Due to a bug in the way mappings are closed it is possible to free a kmallocated memory chunk arbitrary times. This vulnerability can be used to craft a use after free scenario against any kernel structure that is allocated from the kmalloc-64 cache. There is rich public literature on how su...
> #DEFCON: Exploiting Vulnerabilities in the Global Food Supply Chain
A security researcher reveals how it was possible to exploit the command center for global farming equipment, which could have had disastrous consequences
> #DEFCON: Exploiting Physical Shopping Carts for Denial of Shopping
Physical shopping carts used by retailers can potentially be locked or unlocked by hacker, though the actual risk is small
> CVE-2021-22412: Huawei NPU Kernel Driver Shared Memory Out of Bounds Write
Summary The NPU device’s kernel driver implements a set of ioctl handlers one of which uses unsanitized user data as an offset to retrieve a kernel structure. Fields of the structure are written with user provided values. A malicious actor can use this vulnerability to overwrite kernel memory with c...
> #DEFCON: Why Social Media Security is Election Security
Though the big social media platforms claim to have made progress, researcher alleges little has been achieved, and it's still possible to disseminate false information
> #DEFCON: Hacking RFID Attendance Systems with a Time Turner
Student researcher reveals how it could be possible to hack an attendance system remotely and also change the responses that other students provide
> CVE-2021-22415: Huawei NPU Kernel Driver Use-After-Free
Summary In a previous advisory we disclosed multiple vulnerabilities within the NPU device’s mmap handler and discussed how it exposes sensitive kernel data. This advisory focuses on the implementation errors in the same handler. The mapping function ignores the requested size parameter and fails to...
> #DEFCON: Ransomware Moves from Nuisance to Scourge
A panel of experts debate what needs to be done to combat the increasing growth and impact of ransomware
> #DEFCON: A Bad eBook Can Take Over Your Kindle (or Worse)
Reading isn't always good for you, as a hacker reveals that a malicious eBook could potentially lead to a very bad day for a victim
> [BugTales] Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver
Samsung’s neural processing framework has received a lot of attention from the security community since its introduction. Hardware isolation vulnerabilities have been demonstrated, both on the NPU and DSP cores (1, 2), that could be used to compromise the kernel. The surrounding kernel code was also...
> Disney Employees Among Those Arrested in Child Abuse Sting
Three Disney workers were among 17 suspects arrested in Florida’s Operation Child Protector