Menu

Blog

Archive for the ‘security’ category: Page 37

Jan 14, 2023

Critical zero day vulnerability in Linux Kernel Allows DoS Attack

Posted by in categories: computing, mobile phones, security, space

This flaw, which has been identified that affects the ksmbd NTLMv2 authentication in the Linux kernel, is known to quickly cause the operating system on Linux-based computers to crash. Namjae Jeon is the developer of KSMBD, which is an open-source In-kernel CIFS/SMB3 server designed for the Linux Kernel. It is an implementation of the SMB/CIFS protocol in the kernel space that allows for the sharing of IPC services and files over a network.

In order to take advantage of the vulnerability, you will need to transmit corrupted packets to the server, personal computer, tablet, or smartphone that you are targeting. The attack causes what is known as “a memory overflow flaw in ksmbd decodentlmssp auth blob,” which states that nt len may be less than CIFS ENCPWD SIZE in some circumstances. Because of this, the blen parameter that is sent to ksmbd authntlmv2, which runs memcpy using blen on memory that was allocated by kmalloc(blen + CIFS CRYPTO KEY SIZE), is now negative. It is important to take note that the CIFS ENCPWD SIZE value is 16, and the CIFS CRYPTO KEY SIZE value is 8. As the heap overflow happens when blen is in the range [-8,-1], we think that the only possible outcome of this problem is a remote denial of service and not a privilege escalation or a remote code execution.

Continue reading “Critical zero day vulnerability in Linux Kernel Allows DoS Attack” »

Jan 12, 2023

Generative AI, cloud computing and security top tech trends for 2023: Alibaba academy

Posted by in categories: robotics/AI, security

Alibaba Damo Academy, an in-house research initiative by Chinese technology giant Alibaba, has identified generative artificial intelligence, dual-engine decision intelligence, cloud computing and security as top technology trends for 2023.

Jan 11, 2023

Amazon introduces Ring car camera for vehicles

Posted by in categories: security, transportation

The dual-facing Ring Car Cam sits on the vehicle’s dashboard and is designed to record when your car is in motion and when it’s turned off. (Credit: Ring)

SANTA MONICA, Calif.Ring launched its first video doorbell 10 years ago — and now, its parent company Amazon is launching another security device: a camera for your car.

Josh Roth, Ring’s Chief Technology Officer, said last week that one of the products that Ring’s founder (Jamie Siminoff) has asked most about is one to protect the car.

Jan 11, 2023

Expert Analysis Reveals Cryptographic Weaknesses in Threema Messaging App

Posted by in categories: biotech/medical, encryption, security

A comprehensive analysis of the cryptographic protocols used in the Swiss encrypted messaging application Threema has revealed a number of loopholes that could be exploited to break authentication protections and even recover users’ private keys.

The seven attacks span three different threat models, according to ETH Zurich researchers Kenneth G. Paterson, Matteo Scarlata, and Kien Tuong Truong, who reported the issues to Threema on October 3, 2022. The weaknesses have since been addressed as part of updates released by the company on November 29, 2022.

Threema is an encrypted messaging app that’s used by more than 11 million users as of October 2022. “Security and privacy are deeply ingrained in Threema’s DNA,” the company claims on its website.

Jan 9, 2023

Microsoft acquires Fungible, a maker of data processing units, to bolster Azure

Posted by in categories: computing, security

In December, reports suggested that Microsoft had acquired Fungible, a startup fabricating a type of data center hardware known as a data processing unit (DPU), for around $190 million. Today, Microsoft confirmed the acquisition but not the purchase price, saying that it plans to use Fungible’s tech and team to deliver “multiple DPU solutions, network innovation and hardware systems advancements.”

“Fungible’s technologies help enable high-performance, scalable, disaggregated, scaled-out data center infrastructure with reliability and security,” Girish Bablani, the CVP of Microsoft’s Azure Core division, wrote in a blog post. “Today’s announcement further signals Microsoft’s commitment to long-term differentiated investments in our data center infrastructure, which enhances our broad range of technologies and offerings including offloading, improving latency, increasing data center server density, optimizing energy efficiency and reducing costs.”

A DPU is a dedicated piece of hardware designed to handle certain data processing tasks, including security and network routing for data traffic. The approach is intended to help reduce the load on CPUs and GPUs for core computing tasks related to a given workload.

Jan 9, 2023

Why IAM’s identity-first security is core to zero trust

Posted by in category: security

Check out all the on-demand sessions from the Intelligent Security Summit here.

The faster attackers can gain control over human or machine identities during a breach attempt, the easier it becomes to infiltrate core enterprise systems and take control. Attackers, cybercriminal gangs and advanced persistent threat (APT) groups share the goal of quickly seizing control of identity access management (IAM) systems.

Impersonating identities is how attackers move laterally across networks, undetected for months. IAM systems — in particular, older perimeter-based ones not protected with zero-trust security — are often the first or primary target.

Jan 8, 2023

We need to build better bias in AI

Posted by in categories: robotics/AI, security

Check out all the on-demand sessions from the Intelligent Security Summit here.

At their best, AI systems extend and augment the work we do, helping us to realize our goals. At their worst, they undermine them. We’ve all heard of high-profile instances of AI bias, like Amazon’s machine learning (ML) recruitment engine that discriminated against women or the racist results from Google Vision. These cases don’t just harm individuals; they work against their creators’ original intentions. Quite rightly, these examples attracted public outcry and, as a result, shaped perceptions of AI bias into something that is categorically bad and that we need to eliminate.

While most people agree on the need to build high-trust, fair AI systems, taking all bias out of AI is unrealistic. In fact, as the new wave of ML models go beyond the deterministic, they’re actively being designed with some level of subjectivity built in. Today’s most sophisticated systems are synthesizing inputs, contextualizing content and interpreting results. Rather than trying to eliminate bias entirely, organizations should seek to understand and measure subjectivity better.

Jan 5, 2023

How can artificial intelligence fuel the logistics industry?

Posted by in categories: blockchains, information science, robotics/AI, security, transportation

Artificial Intelligence is the buzzword of the year with many big giants in almost every industry trying to explore this cutting-edge technology. Right from self-checkout cash registers to AI-based applications to analyse large data in real-time to advanced security check-ins at the airport, AI is just about everywhere.

Currently, the logistics industry is bloated with a number of challenges related to cost, efficiency, security, bureaucracy, and reliability. So, according to the experts, new age technologies like AI, machine learning, the blockchain, and big data are the only fix for the logistics sector which can improve the supply chain ecosystem right from purchase to internal exchanges like storage, auditing, and delivery.

AI is an underlying technology which can enhance the supplier selection, boost supplier relationship management, and more. When combined with big data analytics AI also helps in analysing the supplier related data such as on-time delivery performance, credit scoring, audits, evaluations etc. This helps in making valuable decisions based on actionable real-time insights.

Jan 4, 2023

How the quantum realm will go beyond computing

Posted by in categories: biotech/medical, finance, quantum physics, robotics/AI, security

Check out all the on-demand sessions from the Intelligent Security Summit here.

Over the last half-decade, quantum computing has attracted tremendous media attention. Why?

After all, we have computers already, which have been around since the 1940s. Is the interest because of the use cases? Better AI? Faster and more accurate pricing for financial services firms and hedge funds? Better medicines once quantum computers get a thousand times bigger?

Jan 4, 2023

How deep learning will ignite the metaverse in 2023 and beyond

Posted by in categories: economics, education, robotics/AI, security

Check out all the on-demand sessions from the Intelligent Security Summit here.

The metaverse is becoming one of the hottest topics not only in technology but in the social and economic spheres. Tech giants and startups alike are already working on creating services for this new digital reality.

The metaverse is slowly evolving into a mainstream virtual world where you can work, learn, shop, be entertained and interact with others in ways never before possible. Gartner recently listed the metaverse as one of the top strategic technology trends for 2023, and predicts that by 2026, 25% of the population will spend at least one hour a day there for work, shopping, education, social activities and/or entertainment. That means organizations that use the metaverse effectively will be able to engage with both human and machine customers and create new revenue streams and markets.

Page 37 of 142First3435363738394041Last