The attack exploits a time-of-neutralization to time-of-use (TONTOU) window in Spectre v2 defenses, where a gap exists between when the branch predictor is isolated and when it is used.
VulnCheck CTO Jacob Baines claims that Zbtlink routers are intentionally designed to communicate with command and control servers, a feature he calls a "phone-home trojan horse."
The lawsuit, filed in the U.S. District Court for the Northern District of Illinois, claims Walmart records calls to its stores, extracts vocal characteristics, and creates mathematical templates to identify callers.
The criminals leveraged ChatGPT for various fraudulent activities, including romance scams, fake investment schemes, bogus police impersonations, and potentially operations linked to human trafficking.
A spokesperson for Palo Alto Networks affirmed the company's commitment to high standards of business conduct and security, stating that the review has no impact on their ability to support customers or deliver services in the region.
Security researchers at Arctic Wolf have found that LightSpy, initially discovered in 2018 and linked to Chinese state-backed hackers, has evolved into a commercial spyware platform.
The Hacker News reports that North Korean threat actors have developed a new command-and-control (C2) technique called NullReceiver, an evolution of the EtherHiding method.
As reported by Security Affairs, a 13-year-old Linux kernel flaw named OVSwrap was disclosed, enabling local users to gain root privileges on many default-configured distributions utilizing Open vSwitch.