Ticker Articles

Security Vulnerability Announced for Netgear Routers

Security Vulnerability Announced for Netgear Routers

Another week, another firmware vulnerability and POC attack, this time for Netgear routers. This stack-based overflow vulnerability was discovered by NCC Group and can be exploited on the LAN side of the router and does not need authentication. It allows an attacker to get remote code execution as the admin user (highest privileges) on the router if a printer is directly connected to the router via a USB port.

read more
Kapersky Discovers New UEFI Firmware Boot Kit for FinSpy Spyware

Kapersky Discovers New UEFI Firmware Boot Kit for FinSpy Spyware

Kaspersky has been tracking deployments of the spyware known as FinSpy (also known as FinFisher or Wingbird) since 2011. This infamous surveillance toolset has been historically implanted through a single-stage installer on Windows machines. Recently the Kapersky team reported several findings that focused on suspicious installers of legitimate applications that had been backdoored with a relatively small obfuscated downloader. Read more about their investigation and findings below.

read more
Firmware Security Goes Mainstream as Microsoft Acquires ReFirm Labs

Firmware Security Goes Mainstream as Microsoft Acquires ReFirm Labs

Firmware attacks and industry attention to this growing problem has taken a front stage today as industry giant Microsoft, Inc announced their acquisition of ReFirm Labs to enhance IoT security. Microsoft acknowledges the growth in recent attacks and in their own research has found that over 80% of organizations reported being attacked at the firmware level in the last two years. Read how their acquisition changes the firmware security landscape today.

read more
Looking Back at The RSA Hack 10 Years Later

Looking Back at The RSA Hack 10 Years Later

The RSA breach rocked the cyber security world 10 years ago, but most people are just now coming to understand its significance. In addition to spawning 10 years of rampant state-sponsored attacks and supply chain hacks, only now can we see how this breach was both a lesson to security pros and the start of what is now the modern era of digital insecurity.

read more