Security News

Helping researchers with IoT firmware vulnerability discovery
2018-11-19 07:20

John Toterhi, a security researcher with IoT security company Finite State, believes that many of the security problems plaguing IoT devices are solvable problems through transparency....

Researchers Disclose 7 New Meltdown, Spectre Attacks
2018-11-14 17:59

A team of researchers has described seven new variants of the notorious Meltdown and Spectre attacks, and they claim some of these methods are not mitigated by existing patches, but Intel...

Researchers discover seven new Meltdown and Spectre attacks
2018-11-14 17:54

Experiments showed that processors from AMD, ARM, and Intel are affected.

HITB Armory: Independent security researchers to showcase their tools
2018-11-14 06:55

Organized in collaboration with Maximiliano Soler from ToolsWatch and Matteo Beccaro from Opposing Force, the HITB Armory is a brand new area of HITB2018DXB where independent researchers will get...

Spectre, Meltdown researchers unveil 7 more speculative execution attacks
2018-11-14 01:50

Systemic analysis reveals a range of new issues, and a need for new mitigations.

Researcher Bypasses Windows UAC by Spoofing Trusted Directory
2018-11-12 19:34

A security researcher from Tenable, Inc. recently discovered that it is possible to bypass Windows’ User Account Control (UAC) by spoofing the execution path of a file in a trusted directory.  read more

Ranting researcher publishes VM-busting zero-day without warning
2018-11-08 13:57

A security researcher has published a zero-day flaw in a commonly-used virtual machine management system without notifying the vendor, justifying it with a scathing critique of the infosecurity industry.

Researcher Drops Oracle VirtualBox Zero-Day
2018-11-07 10:31

A researcher has disclosed the details of a zero-day vulnerability affecting Oracle’s VirtualBox virtualization software. The flaw appears serious as exploitation can allow a guest-to-host escape....

Researchers Break Full-Disk Encryption of Popular SSDs
2018-11-06 17:14

The encryption mechanism used by several types of solid state drives contains vulnerabilities that an attacker could exploit to access encrypted data without knowing a password. read more

ICS Devices Vulnerable to Side-Channel Attacks: Researcher
2018-11-05 10:35

Side-channel attacks can pose a serious threat to industrial control systems (ICS), a researcher warned last month at SecurityWeek’s ICS Cyber Security Conference in Atlanta, GA. read more