This Week in Security: QueueJumper, JS VM2 Escape, and CAN Hacking

You may not be familiar with the Microsoft Message Queuing (MSMQ) service, a store and forward sort of inter-process and inter-system communication service. MSMQ has become something of a legacy …read more Continue reading This Week in Security: QueueJumper, JS VM2 Escape, and CAN Hacking

This Week in Security: Cookie Monster, CyberGhost, NEXX, and Dead Angles

“Operation Cookie Monster” ranks as one of the best code names in recent memory. And it’s apropo, given what exactly went down. Genesis Market was one of those marketplaces where …read more Continue reading This Week in Security: Cookie Monster, CyberGhost, NEXX, and Dead Angles

Arbitrary Code Execution Over Radio

Computers connected to networks are constantly threatened by attackers who seek to exploit vulnerabilities wherever they can find them. This risk is particularly high for machines connected to the Internet, …read more Continue reading Arbitrary Code Execution Over Radio

Xiaomi Scooter Firmware Hacking Gets Hands-On

A Xiaomi 3 Lite dashboard with the panel taken off and the PCB visible, four wires connected to the SWD header.

Scooter hacking is wonderful – you get to create a better scooter from a pre-made scooter platform, and sometimes you can do that purely through firmware modifications. Typically, hackers have …read more Continue reading Xiaomi Scooter Firmware Hacking Gets Hands-On