ATTACK 2022   2026(1)  2025(44)  2024(30)  2023(20)  2022(8) 2021(7)  2020(30)  Other(215)


DATE

NAME

INFO

CATEGORY

SUBCATEGORIES

16.6.22

Hertzbleed Attack

Hertzbleed is a new family of side-channel attacks: frequency side channels. In the worst case, these attacks can allow an attacker to extract cryptographic keys from remote servers that were previously believed to be secure.

ATTACK

Attack

11.6.22

PACMAN: Attacking ARM Pointer Authentication with Speculative Execution

We demonstrate multiple proof-of-concept attacks of PACMAN on the Apple M1 SoC, the first desktop processor that supports ARM Pointer Authentication. We reverse engineer the TLB hierarchy on the Apple M1 SoC and expand micro-architectural side-channel attacks to Apple processors.

ATTACK

Attack

31.5.22

Microsoft Office RCE -

“Follina” MSDT Attack

Microsoft has now revealed the CVE identifier for this vulnerability is CVE-2022-30190, including a Security Update and article with guidance... but no patch looks to be available as of yet.

ATTACK

Attack

20.5.22

BLE Proximity Authentication Vulnerable to Relay Attacks

An attacker can falsely indicate the proximity of Bluetooth LE (BLE) devices to one another through the use of a relay attack. This may enable unauthorized access to devices in BLE-based proximity authentication systems.

ATTACK

Bluetooth Attack

4.5.22

Moshen Dragon’s

A Chinese-aligned cyberespionage group has been observed striking the telecommunication sector in Central Asia with versions of malware such as ShadowPad and PlugX.

ATTACK

Attack Exploit

30.4.22

15M rps HTTPS DDoS attack

Earlier this month, Cloudflare’s systems automatically detected and mitigated a 15.3 million request-per-second (rps) DDoS attack — one of the largest HTTPS DDoS attacks on record.

ATTACK

HTTPS DDoS

2.3.22

UDP-Based Amplification Attacks

 

ATTACK

UDP

2.3.22

TCP Middlebox Reflection

  ATTACK

DDoS