Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tips to Protect Family on Telegram Messenger

https://cdn-images-1.medium.com/max/600/1*23HIsj05lBu2m-OGRWj4PA.png
In the ever-evolving world of technology, messaging apps like Telegram have become increasingly popular for their secure and versatile…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Discover Hidden Web Directories with Dirhunt v0.6.0 — No Bruteforce Required!

Are you tired of brute forcing web directories to find hidden content? Look no further! In this video, we introduce Dirhunt v0.6.0, a…

Continue reading on Medium »
How I was able to takeover 4000+ users account

How I was able to takeover 4000+ users accountContinue reading on Medium »
Read more...
How Hackers Are Stealing Millions Using CHATGPT

hackers discovered how to use chat GPT for their own selfish purposes using it as a tool to steal confidential data and extort millions of…Continue reading on Medium »
Read more...
SECRET Chat Leak EXPOSED Russian Hackers | Conti Explained

Welcome to Cybernews. Today, we bring you a thrilling cybercrime story surrounding the infamous Conti ransomware gang. This sophisticated…Continue reading on Medium »
Read more...
Ethical Hacker in The World Explains The Dark Web

I understand your intention to educate people about the dark web and its potential dangers. It’s important to raise awareness about these…Continue reading on Medium »
Read more...
hackers discovered how to use chat GPT for their own selfish purposes using it as a tool to steal confidential data and extort millions of…Continue reading on Medium » (https://medium.com/@stylishcollection666/how-hackers-are-stealing-millions-using-chatgpt-e7cf889ffb85?source=rss------bug_bounty-5)
Welcome to Cybernews. Today, we bring you a thrilling cybercrime story surrounding the infamous Conti ransomware gang. This sophisticated…Continue reading on Medium » (https://medium.com/@stylishcollection666/secret-chat-leak-exposed-russian-hackers-conti-explained-7f4da6f4c0e?source=rss------bug_bounty-5)
I understand your intention to educate people about the dark web and its potential dangers. It’s important to raise awareness about these…Continue reading on Medium » (https://medium.com/@stylishcollection666/ethical-hacker-in-the-world-explains-the-dark-web-d8c11a42d48c?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data

Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive DataPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Google’s renowned security researcher Tavis Ormandy has uncovered a significant vulnerability called Zenbleed affecting AMD Zen2 CPUs, posing a serious risk of data theft. The flaw, tracked as CVE-2023-20593, allows malicious actors to pilfer sensitive information, including passwords and encryption keys, at an alarming rate of 30KB/sec from each CPU core.

The root cause of this vulnerability lies in the improper handling of the ‘vzeroupper’ instruction during speculative execution, a widely-used performance-enhancing technique employed in modern processors.

Ormandy employed fuzzing and performance counters to identify specific hardware events, validating his findings using the “Oracle Serialization” approach. This method enabled the detection of inconsistencies between the execution of a randomly generated program and its serialized oracle, leading to the discovery of CVE-2023-20593 in Zen2 CPUs.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Zenbleed PoCWith an optimized exploit for the flaw, the researcher successfully demonstrated how sensitive data from various system operations, including those within virtual machines, isolated sandboxes, and containers, could be leaked.

“I found a variant that can leak about 30 kb per core, per second. This is fast enough to monitor encryption keys and passwords as users login!,” elaborated Ormandy in a technical write-up.

After notifying AMD about the flaw on May 15, 2023, the researcher has now published a proof-of-concept (PoC) exploit for CVE-2023-20593, impacting all operating systems running on Zen 2 CPUs.
First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! https://t.co/NVPWFpVopz pic.twitter.com/HgKwu9w8Av

— Tavis Ormandy (@taviso) July 24, 2023
The vulnerability affects numerous AMD CPUs built on the Zen 2 architecture, including Ryzen 3000 (“Matisse”), Ryzen 4000U/H (“Renoir”), Ryzen 5000U (“Lucienne”), Ryzen 7020, and high-end ThreadRipper 3000 and Epyc server (“Rome”) processors.

AMD has released an updated microcode to address the issue, and users are strongly advised to apply the fix or await BIOS upgrades from their computer vendors.

Trending: Unlocking Windows System Resource Utilization for Digital Forensics Analysis with SRUM Dump Trending: Digital Forensics Tool: ScrapPy
Ormandy suggests an alternative mitigation method involving setting the “chicken bit” to DE_CFG[9], though this may lead to a drop in CPU performance.

Detection of exploitation is challenging, as the improper usage of ‘vzeroupper’ does not require elevated privileges or special system calls, making the Zenbleed exploit stealthy and potentially hard to trace.

For regular users, the practical impact of Zenbleed is relatively low, as exploiting it requires local access to the target system and a high level of expertise. Nonetheless, maintaining up-to-date systems with the latest security patches and BIOS updates is crucial to mitigate potential risks.
Trending: WormGPT: Unleashing the Dark Side of Generative AI for Cybercrime
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sh[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive DataPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-c…
aring?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Copy-of-Images-for-the-News-posts-300x150.png HotRat Malware -The Sneaky Trojan Lurking in Cracked SoftwareJuly 24, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-12-300x150.png New P2PInfect Malware, Self-Spreading Worm Targets Redis Instances on Internet-Exposed SystemsJuly 21, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-11-300x150.png DeliveryCheck: Turla’s New Cyberweapon Strikes Microsoft Exchange Servers and Defense SectorJuly 20, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/07/Images-for-the-News-posts-10-300x150.png WormGPT: Unleashing the Dark Side of Generative AI for CybercrimeJuly 19, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Zenbleed: Critical Flaw Found in AMD Zen2 CPUs That Could Leak Sensitive Data first appeared on Black Hat Ethical Hacking.