📺 Watch the full video: s1.ai/PKfail
📺 Watch the full video: s1.ai/PKfail
and @pagabuc.bsky.social reveal their research into a firmware supply-chain security issue that affected major device vendors and hundreds of models, PKfail.
👉 Watch the full video: s1.ai/PKfail
and @pagabuc.bsky.social reveal their research into a firmware supply-chain security issue that affected major device vendors and hundreds of models, PKfail.
👉 Watch the full video: s1.ai/PKfail
- AT&T Breach
- CrowdStrike Outage
- RegreSSHion
- Intel Decay
- PKfail Secure Boot bypass
Man, this year is not a good year for CyberSecurity.
- AT&T Breach
- CrowdStrike Outage
- RegreSSHion
- Intel Decay
- PKfail Secure Boot bypass
Man, this year is not a good year for CyberSecurity.
https://gigazine.net/news/20240726-pkfail/
https://gigazine.net/news/20240726-pkfail/
- Reused cryptographic keys across multiple device vendors, exposing billions of devices to risk
- Private key leaks and poor cryptographic practices that have persisted for years
- The impact on critical systems like ATMs, voting machines, and enterprise servers
- Reused cryptographic keys across multiple device vendors, exposing billions of devices to risk
- Private key leaks and poor cryptographic practices that have persisted for years
- The impact on critical systems like ATMs, voting machines, and enterprise servers
They’re calling it #PKfail. In #SBBlogwatch, we scramble to rotate our keys. At #TechstrongGroup’s #SecurityBlvd
They’re calling it #PKfail. In #SBBlogwatch, we scramble to rotate our keys. At #TechstrongGroup’s #SecurityBlvd
by @beng3.bsky.social
See what Steve Gibson has to say about the latest security news.
by @beng3.bsky.social
See what Steve Gibson has to say about the latest security news.
- Reused cryptographic keys across multiple device vendors, exposing billions of devices to risk
- Private key leaks and poor cryptographic practices that have persisted for years
- The impact on critical systems like ATMs, voting machines, and enterprise servers
- Reused cryptographic keys across multiple device vendors, exposing billions of devices to risk
- Private key leaks and poor cryptographic practices that have persisted for years
- The impact on critical systems like ATMs, voting machines, and enterprise servers
Written Sept 17th
www.bleepingcomputer.com/news/securit...
Written Sept 17th
www.bleepingcomputer.com/news/securit...
Hands-on Firmware Extraction, Exploration, and Emulation of an EV Charger [4]
PKfail: Untrusted Secure Boot Platform Keys in Production [5]
Hands-on Firmware Extraction, Exploration, and Emulation of an EV Charger [4]
PKfail: Untrusted Secure Boot Platform Keys in Production [5]
www.darkreading.com/endpoint-sec...
www.darkreading.com/endpoint-sec...
[5] www.binarly.io/blog/pkfail-... by @binarly.bsky.social
[6] github.com/tomasz-lisow... by @nsinusr.bsky.social et al.
[7] security.googleblog.com/2024/09/depl... by @dmnk.bsky.social et al.
[5] www.binarly.io/blog/pkfail-... by @binarly.bsky.social
[6] github.com/tomasz-lisow... by @nsinusr.bsky.social et al.
[7] security.googleblog.com/2024/09/depl... by @dmnk.bsky.social et al.
https://gigazine.net/news/20240726-pkfail/
https://gigazine.net/news/20240726-pkfail/
対策:デバイスベンダーによるPKfail脆弱性に対処するセキュリティパッチを適用する
対象のデバイスリスト👉 22222483.fs1.hubspotusercontent-na1.net/hubfs/222224...
対策:デバイスベンダーによるPKfail脆弱性に対処するセキュリティパッチを適用する
対象のデバイスリスト👉 22222483.fs1.hubspotusercontent-na1.net/hubfs/222224...
https://gigazine.net/news/20240726-pkfail/
https://gigazine.net/news/20240726-pkfail/
暗号関係になると途端に理解する事を放棄してお粗末な仕事をするエンジニアが結構多いと思うのだけど、有名メーカーでも大差無いのかな……
簡単だとは言わないけど、腰を落ち着けて取り組めば出来ないエンジニアは居ないと思ってる。
gigazine.net/news/2024072...
暗号関係になると途端に理解する事を放棄してお粗末な仕事をするエンジニアが結構多いと思うのだけど、有名メーカーでも大差無いのかな……
簡単だとは言わないけど、腰を落ち着けて取り組めば出来ないエンジニアは居ないと思ってる。
gigazine.net/news/2024072...
https://yespress.io/binarly?utm_source=bluesky&utm_medium=social via Yespress
https://yespress.io/binarly?utm_source=bluesky&utm_medium=social via Yespress