ATTACK 2022 -  2024  2023  2022  2021  2020  Other

16.6.22

Hertzbleed Attack

Attack

Attack

Hertzbleed is a new family of side-channel attacks: frequency side channels. In the worst case, these attacks can allow an attacker to extract cryptographic keys from remote servers that were previously believed to be secure.

11.6.22

PACMAN: Attacking ARM Pointer Authentication with Speculative Execution

Attack

Attack

We demonstrate multiple proof-of-concept attacks of PACMAN on the Apple M1 SoC, the first desktop processor that supports ARM Pointer Authentication. We reverse engineer the TLB hierarchy on the Apple M1 SoC and expand micro-architectural side-channel attacks to Apple processors.

31.5.22

Microsoft Office RCE -

“Follina” MSDT Attack

Attack

Attack

Microsoft has now revealed the CVE identifier for this vulnerability is CVE-2022-30190, including a Security Update and article with guidance... but no patch looks to be available as of yet.

20.5.22

BLE Proximity Authentication Vulnerable to Relay Attacks

Attack

Bluetooth Attack

An attacker can falsely indicate the proximity of Bluetooth LE (BLE) devices to one another through the use of a relay attack. This may enable unauthorized access to devices in BLE-based proximity authentication systems.

4.5.22

Moshen Dragon’s

Attack

Attack Exploit

A Chinese-aligned cyberespionage group has been observed striking the telecommunication sector in Central Asia with versions of malware such as ShadowPad and PlugX.

30.4.22

15M rps HTTPS DDoS attack

Attack

HTTPS DDoS

Earlier this month, Cloudflare’s systems automatically detected and mitigated a 15.3 million request-per-second (rps) DDoS attack — one of the largest HTTPS DDoS attacks on record.

2.3.22

UDP-Based Amplification Attacks

Attack

UDP

 

2.3.22

TCP Middlebox Reflection

Attack

DDoS