[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 04:00

> #BHUSA: Windows Hello Passwordless Bypass Revealed
Using a pic of the cartoon character SpongeBob SquarePants, a researcher figures out an approach to bypass Windows Hello facial-recognition security
> #BHUSA: CISA Director Advocates for New Partnership to Improve Cybersecurity
CISA head wants to encourage public–private operational collaboration and information sharing with new initiatives
> CVE-2021-22388: Huawei NPU Kernel Driver Function Pointer Overwrite
Summary The NPU device’s kernel driver implements a set of ioctl handlers one of which uses unsanitized user data as an index into a function pointer array. The user provided values can exceed the boundaries of the legitimate array and might cause user controlled values to be called as function poin...
> #BHUSA: Looking for Vulnerabilities in Hospital Pneumatic Tubes
While the internet itself might not actually be a series of tubes, hospitals that connect to the internet do use pneumatic tubes that could potentially be at risk
> US Teams Up with Companies to Defend Critical Infrastructure
Joint Cyber Defense Collaborative will see US government working with tech’s key players
> CVE-2021-22389: Huawei NPU Kernel Driver Exposes Kernel Structures in Shared Memory
Summary The NPU device’s kernel driver implements a custom mmap handler that exposes trusted kernel data to user space. These exposed structures contain sensitive data, including kernel pointers, which can be controlled by a user process. The content of these structures is inherently trusted by the...
> Aussie Rapper Shares Cyber-Stalking Ordeal
Illy speaks out after enduring almost two years of “malicious abuse” from cyber-stalker
> FTC Warns of Phishing Text Scam
Cyber-criminals target Americans in receipt of unemployment insurance benefits
> CVE-2021-22390: Huawei NPU Kernel Driver Use-After-Free
Summary Due to a bug in the way mappings are closed it is possible to free a kmallocated memory chunk arbitrary times. This vulnerability can be used to craft a use after free scenario against any kernel structure that is allocated from the kmalloc-64 cache. There is rich public literature on how su...
> #BHUSA: The Serious Disinformation Threat Posed by GPT-3
Research by CSET reveals worrying potential for GPT-3 to spread disinformation
> Cybercrime Ransomware 'Ban' is No Match for Threat Actors
Users of popular underground forums are finding ways to bend the rules
> CVE-2021-22412: Huawei NPU Kernel Driver Shared Memory Out of Bounds Write
Summary The NPU device’s kernel driver implements a set of ioctl handlers one of which uses unsanitized user data as an offset to retrieve a kernel structure. Fields of the structure are written with user provided values. A malicious actor can use this vulnerability to overwrite kernel memory with c...
> Decade-Old Router Bug Could Affect Millions of Devices
Tenable discovery highlights continued software supply chain risk
> Web Shells and Digital Extortion Drive Triple-Digit Growth in Cyber-Intrusions
US bears the brunt of most malicious activity in H1 2021, says Accenture
> CVE-2021-22415: Huawei NPU Kernel Driver Use-After-Free
Summary In a previous advisory we disclosed multiple vulnerabilities within the NPU device’s mmap handler and discussed how it exposes sensitive kernel data. This advisory focuses on the implementation errors in the same handler. The mapping function ignores the requested size parameter and fails to...
> #BHUSA: The 9 Lives of the Charming Kitten Nation-State Attacker
IBM X-Force researchers claim that Iranian nation-state attacker continues to be successful using the same tactics, year after year
> #BHUSA: What is the Future of Security Advisories?
With the volume of security advisories set to grow, it's important to know what assets are not at risk from vulnerability
> [BugTales] Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver
Samsung’s neural processing framework has received a lot of attention from the security community since its introduction. Hardware isolation vulnerabilities have been demonstrated, both on the NPU and DSP cores (1, 2), that could be used to compromise the kernel. The surrounding kernel code was also...
> #BHUSA: Researchers Criticize Apple Bug Bounty Program
While Apple pays well, researchers at Black Hat argue there is a clear lack of transparency on when, or even if, reported vulnerabilities will be fixed
> #BHUSA: Hacking a Capsule Hotel to Silence a Noisy Neighbor
With lights and beds controlled by Wi-Fi, what could go wrong? Apparently, a lot.