This Week in Security: BYOVD, Spectre Vx, More Octal Headaches, and ExifTool

I learned a new acronym while reading about a set of flaws in the Dell BIOS update system. Because Dell has patched their driver, but hasn’t yet revoked the signing …read more Continue reading This Week in Security: BYOVD, Spectre Vx, More Octal Headaches, and ExifTool

This Week in Security: Dan Kaminsky, Banned from Kernel Development, Ransomware, And The Pentagon’s IPv4 Addresses

This week we’re starting off with a somber note, as Dan Kaminsky passed at only 42, of diabetic ketoacidosis. Dan made a name for himself by noticing a weakness in …read more Continue reading This Week in Security: Dan Kaminsky, Banned from Kernel Development, Ransomware, And The Pentagon’s IPv4 Addresses

This Week in Security: NAME:WRECK, Signal Hacks Back, Updates, and More

NAME:WRECK is a collection of vulnerabilities in DNS implementations, discovered by Forescout and JSOF Research. This body of research can be seen as a continuation of Ripple20 and AMNESIA:33, as …read more Continue reading This Week in Security: NAME:WRECK, Signal Hacks Back, Updates, and More

This Week in Security: Pwn2own, Zoom Zero Day, Clubhouse Data, and an FBI Hacking Spree

Our first story this week comes courtesy of the Pwn2own contest. For anyone not familiar with it, this event is held twice a year, and features live demonstrations of exploits …read more Continue reading This Week in Security: Pwn2own, Zoom Zero Day, Clubhouse Data, and an FBI Hacking Spree

This Week in Security: The Facebook Leak, The YouTube Leak, and File Type Confusion

Facebook had a problem, way back in the simpler times that was 2019. Something like 533 million accounts had the cell phone number associated with the account leaked. It’s making …read more Continue reading This Week in Security: The Facebook Leak, The YouTube Leak, and File Type Confusion