Shadowhammer, WPA3, and Alexa is Listening: This Week in Computer Security

Let’s get caught up on computer security news! The big news is Shadowhammer — The Asus Live Update Utility prompted users to download an update that lacked any description or changelog. People thought it was odd, but the update was properly signed by Asus, and antivirus scans reported it as …read more

Continue reading Shadowhammer, WPA3, and Alexa is Listening: This Week in Computer Security

ASUS ShadowHammer Episode – A Custom Made Supply Chain Attack

This Hammer does not work on all nails – Read more on the targeted supply chain attack that evaded major corporations’ security “defenses”
The post ASUS ShadowHammer Episode – A Custom Made Supply Chain Attack appeared first on Security Boulevard.
Continue reading ASUS ShadowHammer Episode – A Custom Made Supply Chain Attack

Smashing Security #121: Hijacked motel rooms, ASUS PCs, and leaky apps

An app leaking private conversations and intimate photographs is ignoring requests to fix the problem, hackers poison a security update sent to ASUS PCs, and how to protect your privacy in motel rooms.
All this and much more is discussed in the latest … Continue reading Smashing Security #121: Hijacked motel rooms, ASUS PCs, and leaky apps

Asus pushes out urgent security update after its own automatic Live Update tool was hacked

Taiwan-based technology giant Asus is advising concerned customers to run a newly-created diagnostic tool on their Windows computers after hackers pushed out malware to what some security researchers have estimated to be as many as one million PCs usin… Continue reading Asus pushes out urgent security update after its own automatic Live Update tool was hacked

ASUS pushes out urgent security update after attackers hacked its automatic Live Update tool

Taiwan-based technology giant ASUS is advising concerned customers to run a newly-created diagnostic tool on their Windows computers after hackers pushed out malware to what some security researchers have estimated to be as many as one million PCs usin… Continue reading ASUS pushes out urgent security update after attackers hacked its automatic Live Update tool

ASUS issues patch, downplays scope of APT hack of its supply chain

Taiwanese hardware manufacturer ASUS on Tuesday announced a software update in response to a nation-state-linked hack and downplayed the scale of the compromise of its supply chain. “Only a very small number of [a] specific user group were found to have been targeted by this attack and as such it is extremely unlikely that your device has been targeted,” ASUS said in a press release. The statement contrasted with the findings of Kaspersky Lab researchers, who described the breach as perhaps “one of the biggest supply-chain incidents ever.” The attackers compromised an ASUS server to send malicious updates that affected about 1 million computer users between June and November 2018, according to the researchers, though only 600 appeared to be targeted for attack. ASUS accounted for 6 percent of global PC shipments in the third quarter of 2018, according to Gartner. The company also makes mobile phones, smart home devices, and other […]

The post ASUS issues patch, downplays scope of APT hack of its supply chain appeared first on CyberScoop.

Continue reading ASUS issues patch, downplays scope of APT hack of its supply chain