This Week in Security: Asterisk, TikTok, Gitlab, And Finally a Spam Solution

There’s an ongoing campaign that’s compromising FreePBX systems around the world. It seems to be aimed specifically at Elastix systems, using CVE-2021-45461, a really nasty Remote Code Execution (RCE) from …read more Continue reading This Week in Security: Asterisk, TikTok, Gitlab, And Finally a Spam Solution

Hacker Liberates Hyundai Head Unit, Writes Custom Apps

Photo of the head unit , with "Hacked by greenluigi1" in the center of the UI

[greenluigi1] bought a Hyundai Ioniq car, and then, to our astonishment, absolutely demolished the Linux-based head unit firmware. By that, we mean that he bypassed all of the firmware update …read more Continue reading Hacker Liberates Hyundai Head Unit, Writes Custom Apps

This Week in Security: Retbleed, Post-Quantum, Python-atomicwrites, and the Mysterious Cuteboi

Yet another entry in the “why we can’t have nice things” category, Retbleed was announced this week, as yet another speculative execution vulnerability. This one is mitigated in hardware for …read more Continue reading This Week in Security: Retbleed, Post-Quantum, Python-atomicwrites, and the Mysterious Cuteboi

This Week in Security:Breaking CACs to Fix NTLM, The Biggest Leak Ever, and Fixing Firefox by Breaking It

To start with, Microsoft’s June Security Patch has a fix for CVE-2022-26925, a Man-In-The-Middle attack against NTLM. According to NIST, this attack is actively being exploited in the wild, so …read more Continue reading This Week in Security:Breaking CACs to Fix NTLM, The Biggest Leak Ever, and Fixing Firefox by Breaking It