Artwork

Conteúdo fornecido por Paul Torgersen. Todo o conteúdo do podcast, incluindo episódios, gráficos e descrições de podcast, é carregado e fornecido diretamente por Paul Torgersen ou por seu parceiro de plataforma de podcast. Se você acredita que alguém está usando seu trabalho protegido por direitos autorais sem sua permissão, siga o processo descrito aqui https://pt.player.fm/legal.
Player FM - Aplicativo de podcast
Fique off-line com o app Player FM !

HP broken BIOS, New Nerbian, Konica cure, and more.

2:41
 
Compartilhar
 

Série arquivada ("Feed inativo " status)

When? This feed was archived on May 25, 2023 16:09 (11M ago). Last successful fetch was on July 29, 2022 18:35 (1+ y ago)

Why? Feed inativo status. Nossos servidores foram incapazes de recuperar um feed de podcast válido por um período razoável.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 328278259 series 2478053
Conteúdo fornecido por Paul Torgersen. Todo o conteúdo do podcast, incluindo episódios, gráficos e descrições de podcast, é carregado e fornecido diretamente por Paul Torgersen ou por seu parceiro de plataforma de podcast. Se você acredita que alguém está usando seu trabalho protegido por direitos autorais sem sua permissão, siga o processo descrito aqui https://pt.player.fm/legal.
A daily look at the relevant information security news from overnight.
Episode 237 - 12 May 2022
HP broken BIOS - https://www.bleepingcomputer.com/news/security/hp-fixes-bug-letting-attackers-overwrite-firmware-in-over-200-models/
New Nerbian -
https://threatpost.com/nerbian-rat-advanced-trick/179600/
Bitter at Bangladesh - https://www.bleepingcomputer.com/news/security/bitter-cyberspies-target-south-asian-govts-with-new-malware/
Fake Vanity - https://portswigger.net/daily-swig/box-zoom-google-docs-offer-phishing-boost-with-vanity-url-flaws
Konica cure- https://www.securityweek.com/konica-minolta-printers-vulnerable-hacking-physical-access
Hi, I’m Paul Torgersen. It’s Thursday May 12th, 2022, and this is a look at the information security news from overnight.
From BleepingComputer.com:
HP has released BIOS updates to fix two 8.8 severity vulnerabilities that would allow code to run with Kernel privileges, and affects over 200 PC and notebook products. The problem appears to be that an SMI handler can be triggered from the OS environment. You can see the details and a couple important links in the article.
From ThreatPost.com:
A newly discovered and complex remote access trojan dubbed Nerbian RAT, is spreading via malicious email campaigns using COVID-19 as a lure. This multi-feature baddie, including the ability to evade analysis or detection by researchers. The majority of the attacks have been centered in Spain and the United Kingdom.
From BleepingComputer.com:
APT cyberespionage group Bitter has been found targeting the government of Bangladesh with a new malware with remote file execution capabilities. These messages are sent via spoofed email addresses that appear to come from Pakistani government organizations. This was likely possible by exploiting a flaw in the Zimbra mail server that allows attackers to send messages from a non-existent mail domain. Full details from the Talos research in the article.
From PortSwigger.net:
Threat actors are enhancing their phishing campaigns by exploiting a failure to validate subdomains within so-called ‘vanity URLs’ used in SaaS applications. Apps such as Box, Zoom, and Google Docs validate vanity URLs’ URI (the unique sequence of characters at the end of the link), but not its descriptive subdomain, which is the portion preceding the URI.
And last today, from SecurityWeek.com:
Hundreds of thousands of Konica printers are vulnerable to hacking via ​​physical access. The vendor produced firmware and operating system patches in early 2020, but details are only being disclosed now because in many cases the patches need to be manually installed by a service technician. That was a bit tough in the midst of the Covid shutdowns.
That’s all for me today. Remember to LIKE and SUBSCRIBE. And as always, until next time, be safe out there.
  continue reading

221 episódios

Artwork
iconCompartilhar
 

Série arquivada ("Feed inativo " status)

When? This feed was archived on May 25, 2023 16:09 (11M ago). Last successful fetch was on July 29, 2022 18:35 (1+ y ago)

Why? Feed inativo status. Nossos servidores foram incapazes de recuperar um feed de podcast válido por um período razoável.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 328278259 series 2478053
Conteúdo fornecido por Paul Torgersen. Todo o conteúdo do podcast, incluindo episódios, gráficos e descrições de podcast, é carregado e fornecido diretamente por Paul Torgersen ou por seu parceiro de plataforma de podcast. Se você acredita que alguém está usando seu trabalho protegido por direitos autorais sem sua permissão, siga o processo descrito aqui https://pt.player.fm/legal.
A daily look at the relevant information security news from overnight.
Episode 237 - 12 May 2022
HP broken BIOS - https://www.bleepingcomputer.com/news/security/hp-fixes-bug-letting-attackers-overwrite-firmware-in-over-200-models/
New Nerbian -
https://threatpost.com/nerbian-rat-advanced-trick/179600/
Bitter at Bangladesh - https://www.bleepingcomputer.com/news/security/bitter-cyberspies-target-south-asian-govts-with-new-malware/
Fake Vanity - https://portswigger.net/daily-swig/box-zoom-google-docs-offer-phishing-boost-with-vanity-url-flaws
Konica cure- https://www.securityweek.com/konica-minolta-printers-vulnerable-hacking-physical-access
Hi, I’m Paul Torgersen. It’s Thursday May 12th, 2022, and this is a look at the information security news from overnight.
From BleepingComputer.com:
HP has released BIOS updates to fix two 8.8 severity vulnerabilities that would allow code to run with Kernel privileges, and affects over 200 PC and notebook products. The problem appears to be that an SMI handler can be triggered from the OS environment. You can see the details and a couple important links in the article.
From ThreatPost.com:
A newly discovered and complex remote access trojan dubbed Nerbian RAT, is spreading via malicious email campaigns using COVID-19 as a lure. This multi-feature baddie, including the ability to evade analysis or detection by researchers. The majority of the attacks have been centered in Spain and the United Kingdom.
From BleepingComputer.com:
APT cyberespionage group Bitter has been found targeting the government of Bangladesh with a new malware with remote file execution capabilities. These messages are sent via spoofed email addresses that appear to come from Pakistani government organizations. This was likely possible by exploiting a flaw in the Zimbra mail server that allows attackers to send messages from a non-existent mail domain. Full details from the Talos research in the article.
From PortSwigger.net:
Threat actors are enhancing their phishing campaigns by exploiting a failure to validate subdomains within so-called ‘vanity URLs’ used in SaaS applications. Apps such as Box, Zoom, and Google Docs validate vanity URLs’ URI (the unique sequence of characters at the end of the link), but not its descriptive subdomain, which is the portion preceding the URI.
And last today, from SecurityWeek.com:
Hundreds of thousands of Konica printers are vulnerable to hacking via ​​physical access. The vendor produced firmware and operating system patches in early 2020, but details are only being disclosed now because in many cases the patches need to be manually installed by a service technician. That was a bit tough in the midst of the Covid shutdowns.
That’s all for me today. Remember to LIKE and SUBSCRIBE. And as always, until next time, be safe out there.
  continue reading

221 episódios

Alle episoder

×
 
Loading …

Bem vindo ao Player FM!

O Player FM procura na web por podcasts de alta qualidade para você curtir agora mesmo. É o melhor app de podcast e funciona no Android, iPhone e web. Inscreva-se para sincronizar as assinaturas entre os dispositivos.

 

Guia rápido de referências