Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Intel Plugs 29 Holes in CPUs, Bluetooth, Security https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Intel Plugs 29 Holes in CPUs, Bluetooth, SecurityPost Views: 61 Reading Time:…
S firmware, allowing escalation of privilege via local or physical access:

* CVE-2020-12357 Rating: High / CVSS 7.5* CVE-2020-8670 Rating: High / CVSS 7.5CVE-2020-8700 Rating: High / CVSS 7.5CVE-2020-12359 Rating: High / CVSS 7.5See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework The Bad Security Library BugIntel also patched a high-severity bug in Intel Security Library that affects iterations before version 3.3 and may allow escalation of privilege, denial of service or information disclosure. It’s caused by a key exchange without entity authentication that enables authenticated attackers to escalate privilege via network access. CVE-2021-0133 was issued a CVSS rating of 7.7.

Intel also patched 11 other high-severity security that affect Intel NUCs, Intel Driver and Support Assistant (DSA), Intel RealSense ID, Intel Field Programmable Gate Array (FPGA) Open Programmable Acceleration Engine (OPAE) driver for Linux, and Intel Thunderbolt controllers. Focus on Privilege EscalationImmersive Labs’ Kevin Breen, director of cyber threat research, noted that the theme for Intel’s June patch set seems to be privilege escalation. “The higher-rated vulnerabilities in this release seem to focus around resolving privilege escalation vulnerabilities,” he observed to Threatpost via email on Wednesday.

“Interestingly, it’s in the firmware that controls the CPUs, not in the host operating system,” he continued. “We’re used to automatically applying updates for operating systems and software products – and even then we still occasionally see updates that result in the dreaded blue screen of death.”

Applying firmware updates is not as well-managed as software updates, he noted, likely because they’re tougher to test … which means they pack more inherent risk. “As these have a lower level of interaction with your hardware, there’s no easy way to test them before deploying across your network,” Breen said. “This means there is more inherent risk with these kinds of patches and updates.” See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat While hardware exploitation is “a lot harder for attackers to weaponize,” Breen said, attackers know that firmware isn’t updated as frequently as operating systems. That makes firmware exploits a tempting target for threat groups with the technical savvy to create exploits, he predicted: “Creating these exploits would be high on their list for development.”

The regular “patch fast” advice applies, Breen said: “As always, understand your risk and apply patches in the shortest time possible,” he said. “If you have to delay patching to accommodate more testing, consider adding extra monitoring around the services and hosts that would be vulnerable to shorten response times.”

Dirk Schrader, global vice president of security research at New Net Technologies, agreed that focusing on privilege escalation is the key to Intel’s June 2021 security advisories release. He told Threatpost on Wednesday that these newly patched flaws might not be the most critical vulnerabilities an attacker would want to exploit, but “they are certainly of use in an attack script.”

Via email, Schrader pointed out that “any attack uses a couple of vulnerabilities, and those allowing for privilege escalation are sought after in the later stages of an attack after initial exploits or phishes have opened a door.”
He suggested that restricting user privileges is a central element of any security guideline, be it NIST, CIS, or any sector-specific one. “Having exploits in their arsenal to escape from these restrictions is vital to attackers, and companies are well-advised to follow up on the security advisories released by Intel today,” Schrader advised. “Any company should make it hard for attackers, as hard as possible all along the way into the infrastructure, and not just buil[...]
Hacking Articles Tips Tricks Videos Tutorials
S firmware, allowing escalation of privilege via local or physical access: * CVE-2020-12357 Rating: High / CVSS 7.5* CVE-2020-8670 Rating: High / CVSS 7.5CVE-2020-8700 Rating: High / CVSS 7.5CVE-2020-12359 Rating: High / CVSS 7.5See Also: Offensive Security…
d up a hard to crack perimeter (btw: there is no such thing as a hard to crack perimeter). Respect the cyber kill chain, follow through on those other controls in the guidelines, patch and control any change to your infrastructure.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-90x90.png Google PPC Ads Used to Deliver Infostealers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-90x90.png Researchers Uncover Hacking Operations Targeting Government Entities in South Korea1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ransomware-payment-90x90.jpg Cyber-Insurance Fuels Ransomware Payment Surge1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/banner-2021.2-release-90x90.png Kali Linux 2021.2 Release (Kaboxer, Kali-Tweaks, Bleeding-Edge & Privileged Ports)1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker-90x90.jpg Cyber attack hits JBS meat works in Australia, North America1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-1-90x90.jpg HPE Fixes Critical Zero-Day in Server Management Software1 week ago
The post Intel Plugs 29 Holes in CPUs, Bluetooth, Security first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
THE INFAMOUS DOS

https://cdn-images-1.medium.com/max/1691/1*_LVRil38cudCy6DzDTQNZA.png
Undoubtedly DOS (Denial of Service) is one of the most simplest and famous type of network attack, where instead of directly stealing the…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to reveal password from any browser

If you use auto fill for your passwords in your browser of choice then you know it’s easy to forget what your password is. As it turns out…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
SCAM SITE WITH PROOF

Long story short, my cat is dying so i need money for surgery and i thought i can really try my luck with this on... i was wrong, i bought 500$ paypal transfer for 70$ on "ALPHACARDS"

proof : https://imgur.com/a/PtsyNEi (there you have the order id, the mails i send him, and the transaction)

I really thought this site was "ok", but in my stupidity i lost all my money, my cat gonna die. DONT BUY FROM ALPHACARDS!!

submitted by /u/SkinnyWhitePimp420
[link] [comments]