Daily NCSC-FI news followup 2020-11-10

With Great Power comes Great Leakage

platypusattack.com/ With PLATYPUS, we present novel software-based power side-channel attacks on Intel server, desktop and laptop CPUs. We exploit the unprivileged access to the Intel RAPL interface exposing the processor’s power consumption to infer data and extract cryptographic keys. Lisäksi:

www.zdnet.com/article/new-platypus-attack-can-steal-data-from-intel-cpus. Lisäksi:

arstechnica.com/information-technology/2020/11/intel-sgx-defeated-yet-again-this-time-thanks-to-on-chip-power-meter/. Lisäksi:

www.theregister.com/2020/11/10/intel_sgx_side_channel/

Microsoft Releases November 2020 Security Updates

us-cert.cisa.gov/ncas/current-activity/2020/11/10/microsoft-releases-november-2020-security-updates Microsoft has released updates to address vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. Lisäksi:

msrc.microsoft.com/update-guide/releaseNote/2020-Nov. Lisäksi:

isc.sans.edu/diary/Microsoft+November+2020+Patch+Tuesday/26778. Lisäksi:

www.zdnet.com/article/microsoft-november-2020-patch-tuesday-arrives-with-fix-for-windows-zero-day/

Critical Vulnerability in Windows OS

blog.checkpoint.com/2020/11/09/critical-vulnerability-in-windows-os-check-point-customers-remain-protected/ Only five days after Google disclosed information about a critical vulnerability in the Microsoft Windows operating system (CVE-2020-17087), Check Point has officially released protection to keep its customers completely safe. Early protections against vulnerabilities that are under active attack are crucial.

New APT32 Malware Campaign Targets Cambodian Government

www.recordedfuture.com/apt32-malware-campaign/ Recorded Future’s Insikt Group has discovered a new malware campaign targeting the Cambodian government using an Association of Southeast Asian Nations (ASEAN)-themed spearphish.

New Slipstream NAT bypass attacks to be blocked by browsers

www.bleepingcomputer.com/news/security/new-slipstream-nat-bypass-attacks-to-be-blocked-by-browsers/ Web browser vendors are planning to block a new attack technique that would allow attackers to bypass a victim’s NAT, firewall, or router to gain access to any TCP/UDP service hosted on their devices

Google Chrome to block JavaScript redirects on web page URL clicks

www.bleepingcomputer.com/news/security/google-chrome-to-block-javascript-redirects-on-web-page-url-clicks/ Google Chrome is getting a new feature that increases security when clicking on web page links that open URLs in a new window or tab. Lisäksi:

www.zdnet.com/article/chrome-to-block-tab-nabbing-attacks

Europe is adopting stricter rules on surveillance tech

www.technologyreview.com/2020/11/09/1011837/europe-is-adopting-stricter-rules-on-surveillance-tech/ The European Union has agreed to stricter rules on the sale and export of cyber-surveillance technologies like facial recognition and spyware. After years of negotiations, the new regulation will be announced today in Brussels.

New Cybersecurity Threat Predictions for 2021

www.fortinet.com/blog/threat-research/new-cybersecurity-threat-predictions-for-2021 In FortiGuard Labs’ threat predictions for 2021, we’ve estimated the strategies that we anticipate cybercriminals will leverage in the coming year and beyond.

IQM raises $46 million to commercialize its quantum computers

venturebeat.com/2020/11/10/iqm-raises-46-million-to-commercialize-its-quantum-computers/ The race to develop quantum computers has attracted growing hype in recent years. While it’s hard to know just when this next-generation computing architecture will have a real impact, one European company is preparing to take another significant step forward.

You might be interested in …

Daily NCSC-FI news followup 2021-02-18

Microsoft Internal Solorigate Investigation Final Update msrc-blog.microsoft.com/2021/02/18/microsoft-internal-solorigate-investigation-final-update/ We have now completed our internal investigation into the activity of the actor and want to share our findings, which confirm that we found no evidence of access to production services or customer data. The investigation also found no indications that our systems at Microsoft were used to […]

Read More

Daily NCSC-FI news followup 2020-12-19

Tietoturva NYT! – SolarWinds Orion Platformin takaovi mahdollisti vakoilun ja tietomurtoja www.kyberturvallisuuskeskus.fi/fi/ajankohtaista/solarwinds-orion-platformin-takaovi-mahdollisti-vakoilun-ja-tietomurtoja SolarWinds Orion Platform -hallintatyökaluun lisätty takaovi on merkittävä tietoturvatapaus. Tietomurron ja vakoilun mahdollistanut takaovi onnistuttiin levittämään tuhansiin organisaatioihin. Työkalun haavoittuvaa versiota käyttävien organisaatioiden pyydetään olemaan yhteydessä Kyberturvallisuuskeskukseen. Lue myös: yle.fi/uutiset/3-11707606 Google OAuth incident – 14.12.2020 status.cloud.google.com/incident/zall/20013 On Monday 14 December, 2020, for a […]

Read More

Daily NCSC-FI news followup 2019-07-27

New York Passes Law to Update Data Breach Notification Requirements www.bleepingcomputer.com/news/security/new-york-passes-law-to-update-data-breach-notification-requirements/ New York Governor Andrew M. Cuomo signed the Stop Hacks and Improve Electronic Data Security (SHIELD) Act into law, with the new consumer privacy policy being designed to protect New Yorkers’ private data and strengthen the state’s data breach policies.. The signed legislation, sponsored […]

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.