This Week in Security: Printing Shellz, ms-officecmd, And AI Security

Researchers at f-secure have developed an impressive new attack, leveraging HP printers as an unexpected attack surface. Printing Shellz (PDF) is a one-click attack, where simply visiting a malicious webpage …read more Continue reading This Week in Security: Printing Shellz, ms-officecmd, And AI Security

This Week in Security: Intel Atoms Spill Secrets, ICMP Poisons DNS, and The Blacksmith

Intel has announced CVE-2021-0146, a vulnerability in certain processors based on the Atom architecture, and the Trusted Platform Module (TPM) is at the center of the problem. The goal of …read more Continue reading This Week in Security: Intel Atoms Spill Secrets, ICMP Poisons DNS, and The Blacksmith

This Week in Security:Use-After-Free For Dummies, WiFi cracking, and PHP-FPM

In a brilliant write-up, [Stephen Tong] brings us his “Use-After-Free for Dummies“. It’s a surprising tale of a vulnerability that really shouldn’t exist, and a walkthrough of how to complete …read more Continue reading This Week in Security:Use-After-Free For Dummies, WiFi cracking, and PHP-FPM

This Week in Security: The Apache Fix Miss, Github (Malicious) Actions, and Shooting the Messenger

Apache 2.4.50 included a fix for CVE-2021-41773. It has since been discovered that this fix was incomplete, and this version is vulnerable to a permutation of the same vulnerability. 2.4.51 …read more Continue reading This Week in Security: The Apache Fix Miss, Github (Malicious) Actions, and Shooting the Messenger