First up is a technical segment on UEFI shells: determining if they contain dangerous functionality that allows attackers to bypass Secure Boot. Then in the security news: Your vulnerability scanner is your weakest link, Scams that almost got me, The state of EDR is not good, You don't need to do that on a phone or Raspberry PI, Hash cracking and e...
This week we kick things off with a special interview: Kieran Human from ThreatLocker talks about EDR bypasses and other special projects. In the security news: Hacking TVs, Flushable wipes are not the only problem, People just want to spy on their pets, except the devices can be hacked, Linux EDR is for the birds, What does my hat say, we love exp...
SecurityWeek reports that Intel Software Guard Extensions, which is integrated into certain Intel CPUs to prevent data and code exposure even in the event of system hacking, could have its DCAP attestation mechanism compromised through the novel WireTap attack that harnesses a passive DIMM interposer.
This week's technical segment is all about the T-Lora Pager from Lilygo, and really cool Meshtastic device that can also be used for some hacking tasks! In the security news: Your safe is not safe, Cisco ASA devices are under attack, VMScape, HybridPetya and UEFI attacks in the wild, Eveything is a Linux terminal, Hackers turns 30, Hosting websites...
BleepingComputer reports unmodified QEMU hypervisors underpinned by AMD Zen 1 to 5 processors and Intel Coffee Lake processors could have their cryptographic keys compromised with the new VMScape attack, which circumvents protections for Spectre vulnerabilities.
CyberScoop reports that intensified spyware attacks against iPhones have prompted Apple to introduce the new Memory Integrity Enforcement security system in its new iPhone 17 and iPhone Air devices with the A19 and A19 Pro chipsets.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.