Daily NCSC-FI news followup 2020-11-10

With Great Power comes Great Leakage

platypusattack.com/ With PLATYPUS, we present novel software-based power side-channel attacks on Intel server, desktop and laptop CPUs. We exploit the unprivileged access to the Intel RAPL interface exposing the processor’s power consumption to infer data and extract cryptographic keys. Lisäksi:

www.zdnet.com/article/new-platypus-attack-can-steal-data-from-intel-cpus. Lisäksi:

arstechnica.com/information-technology/2020/11/intel-sgx-defeated-yet-again-this-time-thanks-to-on-chip-power-meter/. Lisäksi:


Microsoft Releases November 2020 Security Updates

us-cert.cisa.gov/ncas/current-activity/2020/11/10/microsoft-releases-november-2020-security-updates Microsoft has released updates to address vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. Lisäksi:

msrc.microsoft.com/update-guide/releaseNote/2020-Nov. Lisäksi:

isc.sans.edu/diary/Microsoft+November+2020+Patch+Tuesday/26778. Lisäksi:


Critical Vulnerability in Windows OS

blog.checkpoint.com/2020/11/09/critical-vulnerability-in-windows-os-check-point-customers-remain-protected/ Only five days after Google disclosed information about a critical vulnerability in the Microsoft Windows operating system (CVE-2020-17087), Check Point has officially released protection to keep its customers completely safe. Early protections against vulnerabilities that are under active attack are crucial.

New APT32 Malware Campaign Targets Cambodian Government

www.recordedfuture.com/apt32-malware-campaign/ Recorded Future’s Insikt Group has discovered a new malware campaign targeting the Cambodian government using an Association of Southeast Asian Nations (ASEAN)-themed spearphish.

New Slipstream NAT bypass attacks to be blocked by browsers

www.bleepingcomputer.com/news/security/new-slipstream-nat-bypass-attacks-to-be-blocked-by-browsers/ Web browser vendors are planning to block a new attack technique that would allow attackers to bypass a victim’s NAT, firewall, or router to gain access to any TCP/UDP service hosted on their devices

Google Chrome to block JavaScript redirects on web page URL clicks

www.bleepingcomputer.com/news/security/google-chrome-to-block-javascript-redirects-on-web-page-url-clicks/ Google Chrome is getting a new feature that increases security when clicking on web page links that open URLs in a new window or tab. Lisäksi:


Europe is adopting stricter rules on surveillance tech

www.technologyreview.com/2020/11/09/1011837/europe-is-adopting-stricter-rules-on-surveillance-tech/ The European Union has agreed to stricter rules on the sale and export of cyber-surveillance technologies like facial recognition and spyware. After years of negotiations, the new regulation will be announced today in Brussels.

New Cybersecurity Threat Predictions for 2021

www.fortinet.com/blog/threat-research/new-cybersecurity-threat-predictions-for-2021 In FortiGuard Labs’ threat predictions for 2021, we’ve estimated the strategies that we anticipate cybercriminals will leverage in the coming year and beyond.

IQM raises $46 million to commercialize its quantum computers

venturebeat.com/2020/11/10/iqm-raises-46-million-to-commercialize-its-quantum-computers/ The race to develop quantum computers has attracted growing hype in recent years. While it’s hard to know just when this next-generation computing architecture will have a real impact, one European company is preparing to take another significant step forward.

You might be interested in …

Daily NCSC-FI news followup 2020-07-03

New Apple macOS Big Sur feature to hamper adware operations www.zdnet.com/article/new-apple-macos-big-sur-feature-to-hamper-adware-operations/#ftag=RSSbaffb68 Apple has disabled the ability to silently install macOS profiles from the CLI in macOS 11, a measure that was widely employed by adware and malware gangs. Windows 10: Microsoft Defender ATP now rates your security configurations www.zdnet.com/article/windows-10-microsoft-defender-atp-now-rates-your-security-configurations/#ftag=RSSbaffb68 New Microsoft Defender ATP service will […]

Read More

Daily NCSC-FI news followup 2021-10-12

Farm equipment security at DEF CON 29 www.kaspersky.com/blog/hacking-agriculture-defcon29/42402/ One of the most unusual presentations at the DEF CON 29 conference, held in early August, covered farm equipment vulnerabilities found by an Australian researcher who goes by the alias Sick Codes. Vulnerabilities affecting the major manufacturers John Deere and Case IH were found not in tractors […]

Read More

Daily NCSC-FI news followup 2020-01-07

Potential for Iranian Cyber Response to U.S. Military Strike in Baghdad www.us-cert.gov/ncas/alerts/aa20-006a The Cybersecurity and Infrastructure Security Agency (CISA) is sharing the following information with the cybersecurity community as a primer for assisting in the protection of our Nations critical infrastructure in light of the current tensions between the Islamic Republic of Iran and the […]

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.