> TODAY'S SUMMARY (1 articles)
Today's cybersecurity news highlights several key trends and threats. Ransomware attacks continue to rise, with a notable increase in targeted phishing campaigns exploiting current events. Zero-day vulnerabilities are being actively exploited across multiple platforms, emphasizing the need for timely patching. Additionally, increased attention is given to supply chain attacks, as threat actors seek to compromise third-party vendors. Organizations are urged to enhance their security posture through regular training and incident response planning. Lastly, the importance of multi-factor authentication (MFA) remains paramount in mitigating unauthorized access attempts.
|
// AI-powered summary generated at 04:00
Ministry of Defence teams up with HackerOne on first-of-its-kind initiative
Report finds little progress over the past decade
Summary The NPU device’s kernel driver implements a set of ioctl handlers one of which uses unsanitized user data as an index into a function pointer array. The user provided values can exceed the boundaries of the legitimate array and might cause user controlled values to be called as function poin...
Summary The NPU device’s kernel driver implements a custom mmap handler that exposes trusted kernel data to user space. These exposed structures contain sensitive data, including kernel pointers, which can be controlled by a user process. The content of these structures is inherently trusted by the...
Le Garante privacy italien a infligé des amendes totalisant 400 000 euros à LazioCrea, la Regione Lazio et l'Asl Roma 3 pour ne pas avoir mis en place des mesures de sécurité adéquates, permettant ainsi une attaque ransomware sur les systèmes informatiques de la région le 30 juillet 2021, en pleine...
Summary Due to a bug in the way mappings are closed it is possible to free a kmallocated memory chunk arbitrary times. This vulnerability can be used to craft a use after free scenario against any kernel structure that is allocated from the kmalloc-64 cache. There is rich public literature on how su...
Summary The NPU device’s kernel driver implements a set of ioctl handlers one of which uses unsanitized user data as an offset to retrieve a kernel structure. Fields of the structure are written with user provided values. A malicious actor can use this vulnerability to overwrite kernel memory with c...
In this very short post I wanna talk mention The Silver Searcher, which I just learned about a few weeks ago.
In the past I have written quite a bit about the importance of credential hunting for your organization and some cool built-in operating system indexing features that can be used as well.
Of...
Summary In a previous advisory we disclosed multiple vulnerabilities within the NPU device’s mmap handler and discussed how it exposes sensitive kernel data. This advisory focuses on the implementation errors in the same handler. The mapping function ignores the requested size parameter and fails to...
Samsung’s neural processing framework has received a lot of attention from the security community since its introduction. Hardware isolation vulnerabilities have been demonstrated, both on the NPU and DSP cores (1, 2), that could be used to compromise the kernel. The surrounding kernel code was also...
🇫🇷 L’ANSSI traite actuellement une vaste campagne de compromission touchant de nombreuses entités françaises. Cette dernière, toujours en cours et particulièrement virulente, est conduite par le mode opératoire APT31 (voir CERTFR-2021-CTI-012 pour plus d'informations). Les investigations montrent...
Summary During the regular boot sequence, Huawei’s BootROM initializes the UFS hardware and the crypto engine in order to load and verify the next stage bootloader image from flash. However, when run in download mode, which maybe used for factory flashing and repair purposes, a connected host can co...
Convert access to the AWS Console into IAM credentials.
Former US president takes legal action against companies over alleged illegal censorship
Black Widow malware masquerades as new movie to steal money and credentials
Each month we publish numerous new articles and known issues to the WatchGuard Knowledge Base. Here is the new content published in June:
Articles
False positive security scans for jQuery vulnerabilities in Dimension 2.2
Find Dimension Operating System version
How to manually reset TDR Host Sensor...
Security professionals say multi-cloud environments pose greater security challenges
Report finds 92% of UK organizations suffered a successful attack last year
Credits John
Github: https://github.com/johnjhacking
Jackson Henry [Helped simplify the payload]
Twitter: https://twitter.com/JacksonHHax
Wabaf3t [Provided post-code analysis/looked for escalation]
Twitter: https://twitter.com/wabafet1
Kelly Kaoudis [Reviewed the writeup]
Twitter: https://twitter.co...
648 cyber-attacks per minute occurred in the past year, costing organizations $1.79 million every minute