Threat actors have continued leveraging USB drives to spread the CoinMiner cryptocurrency mining malware as part of an ongoing attack campaign aimed at South Korean workstations, Cyber Security News reports.
Intel's Software Guard Extensions and Trust Domain Extensions, as well as AMD's Secure Encrypted Virtualization with Secure Nested Paging, which are DDR5 CPUs' trusted execution environments, could expose secrets through the new TEE.Fail side-channel attack, reports The Hacker News.
In the security news: When in doubt, blame DNS, you're almost always correct, How to Make Windows 11 great, or at least suck less, CSRF is the least of your problems, Shady exploits, Linux security table stakes (not steaks), The pill camera, Give AI access to your UART, Security products that actually try to be secure?, Firmware vulnerabilities, lo...
First up is a technical segment on UEFI shells: determining if they contain dangerous functionality that allows attackers to bypass Secure Boot. Then in the security news: Your vulnerability scanner is your weakest link, Scams that almost got me, The state of EDR is not good, You don't need to do that on a phone or Raspberry PI, Hash cracking and e...
This week we kick things off with a special interview: Kieran Human from ThreatLocker talks about EDR bypasses and other special projects. In the security news: Hacking TVs, Flushable wipes are not the only problem, People just want to spy on their pets, except the devices can be hacked, Linux EDR is for the birds, What does my hat say, we love exp...
SecurityWeek reports that Intel Software Guard Extensions, which is integrated into certain Intel CPUs to prevent data and code exposure even in the event of system hacking, could have its DCAP attestation mechanism compromised through the novel WireTap attack that harnesses a passive DIMM interposer.