Adding Variometer Functionality to a GPS

Flying a glider, or similarly piloting a paraglider or hang glider, can all be pathways into aviation with a lower barrier of entry than powered flight. Sacrificing one’s engine does …read more Continue reading Adding Variometer Functionality to a GPS

Chinese state-sponsored attack uses custom router implant to target European governments

Learn technical details about this cyberattack, as well as Check Point Research’s tips on how to detect and protect against this security threat.
The post Chinese state-sponsored attack uses custom router implant to target European governments appeared… Continue reading Chinese state-sponsored attack uses custom router implant to target European governments

83C0000B: The error code that means a dodgy software update bricked your HP printer

Since earlier this month some owners of HP OfficeJet printers have been reporting that they are faced with a blue screen error message, and a bricked device.

Read more in my article on the Hot for Security blog. Continue reading 83C0000B: The error code that means a dodgy software update bricked your HP printer

Vulnerability in Zyxel firewalls may soon be widely exploited (CVE-2023-28771)

A recently fixed command injection vulnerability (CVE-2023-28771) affecting a variety Zyxel firewalls may soon be exploited in the wild, Rapid7 researchers have warned, after publishing a technical analysis and a PoC script that triggers the vulnerabil… Continue reading Vulnerability in Zyxel firewalls may soon be widely exploited (CVE-2023-28771)

MSI’s firmware, Intel Boot Guard private keys leaked

The cybercriminals who breached Taiwanese multinational MSI last month have apparently leaked the company’s private code signing keys on their dark web site. The breach MSI (Micro-Star International) is a corporation that develops and sells compu… Continue reading MSI’s firmware, Intel Boot Guard private keys leaked

Critical RCE vulnerability in Cisco phone adapters, no update available (CVE-2023-20126)

Cisco has revealed the existence of a critical vulnerability (CVE-2023-20126) in the web-based management interface of Cisco SPA112 2-Port Phone Adapters. The adapters are widely used to integrate analog phones into VoIP networks without the need for a… Continue reading Critical RCE vulnerability in Cisco phone adapters, no update available (CVE-2023-20126)

How safe is sharing keyboard & mouse between work laptop & my personal laptop

What I need to know is if my work laptop (remotely managed by Org) installs or tags some hidden software on any devices being plugged in to the USB (obvious security hardening on their own part) which may make it to my personal laptop via … Continue reading How safe is sharing keyboard & mouse between work laptop & my personal laptop

Another Malware with Persistence

Here’s a piece of Chinese malware that infects SonicWall security appliances and survives firmware updates.

On Thursday, security firm Mandiant published a report that said threat actors with a suspected nexus to China were engaged in a campaign to maintain long-term persistence by running malware on unpatched SonicWall SMA appliances. The campaign was notable for the ability of the malware to remain on the devices even after its firmware received new firmware.

“The attackers put significant effort into the stability and persistence of their tooling,” Mandiant researchers Daniel Lee, Stephen Eckels, and Ben Read wrote. “This allows their access to the network to persist through firmware updates and maintain a foothold on the network through the SonicWall Device.”…

Continue reading Another Malware with Persistence