Firmware

U-Bootの新たな脆弱性により、検知されにくいファームウェア攻撃が可能になる恐れがある News

U-Bootの新たな脆弱性により、検知されにくいファームウェア攻撃が可能になる恐れがある

広く利用されているU-Bootブートローダーに6つの脆弱性が発見されました。これを利用すると、攻撃者がデバイスの起動中に悪意のあるコードを実行できるようになり、セキュリティ保護機能を無効化して永続的なマルウェアをインストールする、検知されに...
Tendaルーターのファームウェアに隠されたバックドアにより、管理者権限が取得可能に News

Tendaルーターのファームウェアに隠されたバックドアにより、管理者権限が取得可能に

Tenda社のルーターの複数のファームウェアバージョンに、隠された認証バックドアが発見されました。これにより、攻撃者がデバイスのWeb管理パネルへの管理者権限を取得できる可能性があります。 CERT Coordination Centerの...
Flipper Zero firmware development continues with community help News

Flipper Zero firmware development continues with community help

Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and gre...
Flaw in Grandstream VoIP phones allows stealthy eavesdropping News

Flaw in Grandstream VoIP phones allows stealthy eavesdropping

A critical vulnerability in Grandstream GXP1600 series VoIP phones allows a remote, unauthenticated attacker to gain roo...
New Keenadu backdoor found in Android firmware, Google Play apps News

New Keenadu backdoor found in Android firmware, Google Play apps

A newly discovered and sophisticated Android malware called Keenadu has been found embedded in firmware from multiple de...
TP-Link warns of critical command injection flaw in Omada gateways News

TP-Link warns of critical command injection flaw in Omada gateways

TP-Link is warning of two command injection vulnerabilities in Omada gateway devices that could be exploited to execute ...
ConnectWise fixes Automate bug allowing AiTM update attacks News

ConnectWise fixes Automate bug allowing AiTM update attacks

ConnectWise released a security update to address vulnerabilities, one of them with critical severity, in Automate produ...
セキュアブートバイパスの危険性により、約20万台のLinux FrameworkノートPCが脅威にさらされる News

セキュアブートバイパスの危険性により、約20万台のLinux FrameworkノートPCが脅威にさらされる

米国のコンピュータメーカーFramework社の約20万台のLinuxコンピュータシステムが、セキュアブート保護を回避するために悪用される可能性のある署名されたUEFIシェルコンポーネントとともに出荷されていた。 攻撃者は、OSレベルのセキ...
Microsoft Defender bug triggers erroneous BIOS update alerts News

Microsoft Defender bug triggers erroneous BIOS update alerts

​Microsoft is working to resolve a bug that causes Defender for Endpoint to incorrectly tag some devices' BIOS (Basic In...
New Supermicro BMC flaws can create persistent backdoors News

New Supermicro BMC flaws can create persistent backdoors

Two vulnerabilities affecting the firmware of Supermicro hardware, including Baseboard Management Controller (BMC) allow...