FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

New "GoFetch" Vulnerability in Apple M-Series Chips Leaks Secret Encryption Keys

By: Newsroom β€” March 25th 2024 at 09:02
A new security shortcoming discovered in Apple M-series chips could be exploited to extract secret keys used during cryptographic operations. Dubbed GoFetch, the vulnerability relates to a microarchitectural side-channel attack that takes advantage of a feature known as data memory-dependent prefetcher (DMP) to target constant-time cryptographic implementations and capture sensitive data
☐ β˜† βœ‡ The Hacker News

GhostRace – New Data Leak Vulnerability Affects Modern CPUs

By: Newsroom β€” March 15th 2024 at 17:46
A group of researchers has discovered a new data leakage attack impacting modern CPU architectures supporting speculative execution. Dubbed GhostRace (CVE-2024-2193), it is a variation of the transient execution CPU vulnerability known as Spectre v1 (CVE-2017-5753). The approach combines speculative execution and race conditions. "All the common synchronization primitives implemented
☐ β˜† βœ‡ The Hacker News

Third-Party ChatGPT Plugins Could Lead to Account Takeovers

By: Newsroom β€” March 15th 2024 at 11:34
Cybersecurity researchers have found that third-party plugins available for OpenAI ChatGPT could act as a new attack surface for threat actors looking to gain unauthorized access to sensitive data. According to new research published by Salt Labs, security flaws found directly in ChatGPT and within the ecosystem could allow attackers to install malicious plugins without users' consent
☐ β˜† βœ‡ The Hacker News

Researchers Uncover New GPU Side-Channel Vulnerability Leaking Sensitive Data

By: THN β€” September 27th 2023 at 12:55
A novel side-channel attack calledΒ GPU.zipΒ renders virtually all modern graphics processing units (GPU) vulnerable to information leakage. "This channel exploits an optimization that is data dependent, software transparent, and present in nearly all modern GPUs: graphical data compression," a group of academics from the University of Texas at Austin, Carnegie Mellon University, University of
☐ β˜† βœ‡ The Hacker News

Collide+Power, Downfall, and Inception: New Side-Channel Attacks Affecting Modern CPUs

By: THN β€” August 9th 2023 at 15:39
Cybersecurity researchers have disclosed details of a trio of side-channel attacks that could be exploited to leak sensitive data from modern CPUs. CalledΒ Collide+PowerΒ (CVE-2023-20583),Β DownfallΒ (CVE-2022-40982), andΒ InceptionΒ (CVE-2023-20569), the novel methods follow the disclosure of another newly discovered security vulnerability affecting AMD's Zen 2 architecture-based processors known asΒ 
☐ β˜† βœ‡ The Hacker News

New 'Deep Learning Attack' Deciphers Laptop Keystrokes with 95% Accuracy

By: THN β€” August 7th 2023 at 10:14
A group of academics has devised a "deep learning-based acoustic side-channel attack" that can be used to classify laptop keystrokes that are recorded using a nearby phone with 95% accuracy. "When trained on keystrokes recorded using the video conferencing software Zoom, an accuracy of 93% was achieved, a new best for the medium," researchers Joshua Harrison, Ehsan Toreini, and Maryam Mehrnezhad
☐ β˜† βœ‡ The Hacker News

Researchers Find Way to Recover Cryptographic Keys by Analyzing LED Flickers

By: Ravie Lakshmanan β€” June 26th 2023 at 16:46
In what's an ingeniousΒ side-channel attack, a group of academics has found that it's possible to recover secret keys from a device by analyzing video footage of its power LED. "Cryptographic computations performed by the CPU change the power consumption of the device which affects the brightness of the device's power LED," researchers from the Ben-Gurion University of the Negev and Cornell
❌