Tag: Security flaw

Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers
News

Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers

Researchers studying cybersecurity have discovered firmware security flaws in the Illumina iSeq 100 DNA sequencing technology that, if properly used, might allow hackers to brick or install persistent malware on vulnerable devices. According to Eclypsium's study, which was published with The Hacker News, the Illumina iSeq 100 had an extremely antiquated BIOS firmware implementation that used CSM [Compatibility Support Mode] mode and lacked Secure Boot and conventional firmware write safeguards. This would enable a system attacker to either install a firmware implant for continued attacker persistence or overwrite the system firmware to "brick" the device read more about Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers. Get up to date on the latest cyber...
Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers
News

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers

Cybersecurity experts have found serious cryptographic flaws in several end-to-end encrypted (E2EE) cloud storage systems that might be used to steal private information. Researchers at ETH Zurich Jonas Hofmann and Kien Tuong Truong stated that the vulnerabilities vary in severity. A malicious server can frequently insert files, alter file contents, and even obtain direct access to plaintext. Surprisingly, many of our attacks had identical effects on multiple providers, exposing similar failure patterns in separate cryptographic schemes. An investigation of five prominent providers, including Sync, pCloud, Icedrive, Seafile, and Tresorit, produced the discovered flaws. The attack methods that have been developed rely on a malicious server that an adversary controls and that might be...
Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation
News

Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation

Google has disclosed that a security vulnerability addressed in the Chrome browser's security update that was released last week is being actively exploited in the wild. The vulnerability, identified as CVE-2024-7965, is characterized as an improper implementation error in the WebAssembly and JavaScript engines of version 8. A summary of the bug in the NIST National Vulnerability Database (NVD) states that improper implementation in V8 in Google Chrome versions earlier than 128.0.6613.84 allows a remote attacker to possibly exploit heap corruption via a forged HTML page. It has been reported that a security researcher going by the online alias TheDog found and reported the vulnerability read more about Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation. ...
Anycubic 3D printers hacked worldwide to expose security flaw
News

Anycubic 3D printers hacked worldwide to expose security flaw

Customers of Anycubic have reported online that someone has hacked their 3D printers, alerting users to the possibility of assaults. The perpetrator of this issue informed the impacted users that their printer is compromised by a critical security flaw by uploading a hacked_machine_readme.gcode file to their devices. This file typically provides instructions for 3D printing. Using the company's MQTT service API, this vulnerability is said to allow potential attackers to take control of any Anycubic 3D printer that is impacted. Along with requesting Anycubic to open-source its 3D printers, the file that the affected devices got also claims that Anycubic's software "is lacking." There is a serious risk to your security from a severe vulnerability on your machine read more Anycub...
Exploits released for Linux flaw giving root on major distros
News

Exploits released for Linux flaw giving root on major distros

On the majority of Linux distributions, proof-of-concept attacks for a high-severity vulnerability in the dynamic loader of the GNU C Library have previously been made public online. This security flaw, dubbed "Looney Tunables," is listed as CVE-2023-4911 and affects Fedora 37 and 38, Ubuntu 22.04 and 23.04, and Debian 12 and 13. It is caused by a buffer overflow problem. Attackers can use it to start programs with SUID permission and get root privileges by exploiting the GLIBC_TUNABLES environment variable that is processed by the ld.so dynamic loader. Several security researchers have already released proof-of-concept (PoC) exploit code that is functional for various system configurations since Qualys read more Exploits released for Linux flaw giving root on major distros. ...
API Security Flaw Found in Booking.com Allowed Full Account Takeover
News

API Security Flaw Found in Booking.com Allowed Full Account Takeover

The Open Authorization (OAuth) social-login mechanism employed by the online travel service Booking.com has been revealed to have several security issues. The vulnerabilities found by Salt Security might have an impact on anyone using their Facebook accounts to get into the website. According to Salt Security security researcher Aviad Carmel, "The OAuth misconfigurations might have enabled both large-scale account takeover (ATO) on users' accounts and server intrusion. OAuth, according to the security expert, makes it easier for users to connect with websites read more API Security Flaw Found in Booking.com Allowed Full Account Takeover. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, ...