Security News

Knockoff semiconductor chips flood the enterprise market
2021-08-19 12:00

The need for chips spiked as well-given how central they became for more devices for people staying home. One way grifters are operating is they've turned to purchasing ads for chips on search engines to bait buyers, as the Wall Street Journal recently reported.

65 vendors affected by severe vulnerabilities in Realtek chips
2021-08-16 10:36

A vulnerability within the Realtek RTL819xD module allows attackers to gain complete access to the device, installed operating systems and other network devices. The chips supplied by Realtek are used by almost all well-known manufacturers and can be found in VoIP and wireless routers, repeaters, IP cameras, and smart lighting controls - just to name a few.

Voltage Glitching Attack on AMD Chips Poses Risk to Cloud Environments
2021-08-13 12:57

Researchers have described a voltage glitching attack that shows AMD's Secure Encrypted Virtualization technology may not provide proper protection for confidential data in cloud environments. The TU Berlin researchers showed that an attacker who has physical access to the targeted system can gain access to SEV-protected VM memory content by launching a voltage fault injection attack on SP. In order to work as intended, integrated circuits need to operate within specific temperature, clock stability, electromagnetic field, and supply voltage ranges.

Secure Identity Alliance encourages authorities to ensure the supply of chips for identity documents
2021-07-13 22:35

The Secure Identity Alliance believes that a trusted legal identity is essential to protecting people's rights, fostering social inclusion and supporting economic growth. Embedded in national electronic identity cards and electronic passports, this identity provides access to essential public and private services for billions of people around the world.

Impinj RAIN RFID reader chips address increasing demand for item connectivity
2021-06-16 01:15

Impinj introduced three next-generation RAIN RFID reader chips that enable IoT device makers to meet the increasing demand for item connectivity in retail, supply chain and logistics, consumer electronics, and many other markets. The new Impinj E710, E510, and E310 RAIN RFID reader chips are high-performance, low-power systems-on-chips that extend the item connectivity opportunity to hundreds of billions of things worldwide.

Samsung introduces 8nm RF chip architecture to strengthen 5G communications
2021-06-09 23:30

This foundry technology is expected to provide a 'one chip solution,' specifically for 5G communications with support for multi-channel and multi-antenna chip designs. Samsung's 8nm RF platform extension is expected to expand the company's leadership in the 5G semiconductor market from sub-6GHz to mmWave applications.

S3 Ep35: Apple chip flaw, Have I Been Pwned, and Covid tracker trouble [Podcast]
2021-06-03 18:34

The fascinating tale of a bug that's baked into Apple's latest chip. Why the Aussie data breach warning site HIBP is partnering with the FBI. A coronavirus tracking toolkit that fell foul of privacy rules.

Security Vulnerability in Apple’s Silicon “M1” Chip
2021-06-01 11:26

The website for the M1racles security vulnerability is an excellent demonstration that not all vulnerabilities are exploitable. Be sure to read the FAQ through to the end. EDITED TO ADD: Wired article.

“Unpatchable” vuln in Apple’s new Mac chip – what you need to know
2021-05-27 18:59

Apple's brand new Mac has a security hole, right inside the processor itself! The vulnerability is baked into Apple Silicon chips, and cannot be fixed without a new silicon revision.

Unfixable Apple M1 chip bug enables cross-process chatter, breaking OS security model
2021-05-27 01:38

Apple's Arm-based M1 chip, much ballyhooed for its performance, contains a design flaw that can be exploited to allow different processes to quietly communicate with one another, in violation of operating system security principles. Martin has published a proof-of-concept script to demonstrate how to read and write data to the overly talkative system register and a proof-of-concept script for setting up a covert channel on an M1 system.