Security News

OpenSSH Now Encrypts Secret Keys in Memory Against Side-Channel Attacks
2019-06-22 16:33

In recent years, several groups of cybersecurity researchers have disclosed dozens of memory side-channel vulnerabilities in modern processors and DRAMs, like Rowhammer, RAMBleed, Spectre, and...

RAMBleed Side-Channel Attack Exposes Privileged Memory
2019-06-12 15:51

An attacker can use Rowhammer attacker to induce bit flips, thereby leaking the victim's secret data via a side channel.

JavaScript tells all, which turns out not to be so great for privacy: Side-channel leaks can be exploited to follow you around the interweb
2019-06-11 08:58

And using browser privacy extensions may just make matters worse Boffins from Graz University of Technology in Austria have devised an automated system for browser profiling using two new side...

ZombieLoad: How Intel’s Latest Side Channel Bug Was Discovered and Disclosed
2019-05-20 13:42

Daniel Gruss, the researcher behind Spectre, Meltdown - and most recently, ZombieLoad - Intel CPU side channel attacks, gives an inside look into how he discovered the flaws.

Intel ZombieLoad Side-Channel Attack: 10 Takeaways
2019-05-15 16:48

Here are 10 top takeaways from Intel's most recent class of Spectre-like speculative execution vulnerabilities, disclosed this week.

Microsoft plugs wormable RDP flaw, new speculative execution side channel vulnerabilities
2019-05-15 09:33

For May 2019 Patch Tuesday, Microsoft has released fixes for 79 vulnerabilities, 22 of which are deemed critical. Among the fixes is that for CVE-2019-0708, a “wormable” RDP flaw that is expected...

Apple Patches Intel Side-Channel Bugs; Updates iOS, macOS and More
2019-05-14 20:31

A massive update addresses the breadth of the computing giant's product portfolio.

New Side-Channel Attack Targets OS Page Cache
2019-01-08 16:34

A team of researchers, including experts involved in the discovery of the Meltdown and Spectre vulnerabilities, have disclosed a new type of side-channel attack that targets the operating system...

New side-channel leak: Boffins bash operating system page caches until they spill secrets
2019-01-05 01:30

Novel data-siphoning attack is hardware agnostic Some of the computer security boffins who revealed last year's data-leaking speculative-execution holes have identified yet another side-channel...

Week in review: VirtualBox 0day, GPU side channel attacks, vulnerable self-encrypting SSDs
2018-11-11 18:41

Here’s an overview of some of last week’s most interesting news and articles: Five key considerations when developing a Security Operations Center Organizations should start with the following...