Security News

BYO-Bug Tactic Attacks Windows Kernel with Outdated Driver
2020-02-10 21:07

Specifically, they're updating the Windows kernel in-memory with the Gigabyte driver, according to the research - and the kernel accepts it as a "Patch" thanks to the signed certificate. Once that's loaded, they can then exploit that driver using the known vulnerability in order to load their own, unsigned, malicious driver.

Dell, HP Memory-Access Bugs Open Attacker Path to Kernel Privileges
2020-01-30 11:00

Vulnerabilities in Dell and HP laptops could allow an attacker to access information and gain kernel privileges via the devices' Direct Memory Access capability. "This can allow an attacker to execute kernel code on the system, insert a wide variety of kernel implants and perform a host of additional activity such as spawning system shells or removing password requirements."

Google plans to take Android back to ‘mainline’ Linux kernel
2019-11-22 13:59

Android could be returning to its roots.

How the Linux kernel balances the risks of public bug disclosure
2019-11-15 13:27

A serious Wi-Fi flaw shows how Linux handles security in plain sight.

Don't miss this patch: Bad Intel drivers give hackers a backdoor to the Windows kernel
2019-11-12 18:00

Alarm raised over more holes in third-party low-level code Nearly three months after infosec biz Eclypsium highlighted widespread security weaknesses in third-party Windows hardware drivers, you...

Running on Intel? If you want security, disable hyper-threading, says Linux kernel maintainer
2019-10-29 15:17

Speculative execution bugs will be with us for a very long time Linux kernel dev Greg Kroah-Hartman reckons Intel Simultaneous Multithreading (SMT) - also known as hyper-threading - should be...

Linux Crypto-Miner Uses Kernel-Mode Rootkits for Evasion
2019-09-17 15:13

A recently discovered cryptocurrency mining malware targeting Linux machines is employing kernel-mode rootkits in an attempt to make detection more difficult, Trend Micro reveals. read more

Linux Kernel Bug Knocks PCs, IoT Gadgets and More Offline
2019-06-18 18:43

Four vulnerabilities could "SACK" connected devices with denial-of-service exploits.

Serious Vulnerabilities in Linux Kernel Allow Remote DoS Attacks
2019-06-18 10:17

A security researcher working for Netflix has discovered that the Linux kernel is affected by potentially serious vulnerabilities that can be exploited by a remote, unauthenticated attacker to...

Linux Kernel Privilege Escalation Vulnerability Found in RDS Over TCP
2019-05-20 16:42

A memory corruption vulnerability recently found in Linux Kernel’s implementation of RDS over TCP could lead to privilege escalation.  Tracked as CVE-2019-11815 and featuring a CVSS base score of...