Encryption

Cryptographer Announces $12K Bounty to Find the Lost Seeds to 5 NIST Elliptic Curves (filippo.io) 43

Long-time Slashdot reader mejustme writes: The NIST elliptic curves that power much of modern cryptography were generated in the late '90s by hashing seeds provided by the NSA. Rumor has it that they are in turn hashes of English sentences, but the person who picked them, Dr. Jerry Solinas, passed away in early 2023 leaving behind a cryptographic mystery."

That's from the blog of Filippo Valsorda, who was in charge of cryptography and security on the Go team at Google until 2022, (and was on the Cryptography team at Cloudflare until 2017). But more importantly, he adds that "I'm announcing a $12,288 bounty for cracking these five hashes, tripled to $36,864 if the recipient chooses to donate it to a 501(c)(3) charity of their choice."

There are hints to which phrase was used as the seed. [Before his death] Dr. Jerry Solinas said he thought he'd used something similar to "Jerry deserves a raise.

Security

For 'Cybersecurity Awareness Month' America's Cybersecurity Agency Shares Four Online Safety Tips (cisa.gov) 34

Since 2004 October has been designated "Cybersecurity Awareness Month" in America, "a collaborative effort between government and industry to enhance cybersecurity awareness, encourage actions by the public to reduce online risk and generate discussion on cyber threats on a national and global scale."

That's according to America's Cybersecurity and Infrastructure Security Agency (or CISA), the operational lead for federal cybersecurity and national coordinator for critical infrastructure security and resilience (specifically designed for collaboration and partnership). It's why the NSA is publicizing the ten most common cybersecurity misconfigurations in large organizations.

But in addition, for consumers CISA is introducing a new program this year that "promotes behavioral change across the Nation, with a particular focus on how individuals, families and small to medium-sized businesses can Secure Our World by focusing on the four critical actions..." In a video the director of America's cyberdefense agency calls them steps "that everyone can take to stay safe online."
  • Use Strong Passwords, "meaning long, random, and unique to each account. And use a password manager to generate and to save them."
  • Turn on Multi-Factor Authentication on All Accounts That Offer It. "You need more than a password on your most important accounts, like email, social media, and financial accounts."
  • Recognize and Report Phishing. "Be cautious of unsolicited emails, texts, or calls asking you for personal information, and don't click on links or open attachments from unknown sources.
  • Update Your Software. "In fact, enable automatic updates on your software, so the latest security patches just keep your devices continuously up-to-date."

The video ends by noting CISA is asking tech companies and software developers to create products that are "secure by design."

"And let's secure our families by ensuring that our loved ones know what to look for and how to stay safe online."


Android

Android Devices With Backdoored Firmware Found In US Schools (securityweek.com) 36

An anonymous reader quotes a report from SecurityWeek: Tens of thousands of Android devices have been shipped to end-users with backdoored firmware, according to a warning from cybersecurity vendor Human Security. As part of the global cybercriminal operation called BadBox (PDF), Human Security found a threat actor relied on supply chain compromise to infect the firmware of more than 70,000 Android smartphones, CTV boxes, and tablet devices with the Triada malware. The infected devices come from at least one Chinese manufacturer but, before they are delivered to resellers, physical retail stores, and e-commerce warehouses, a backdoor was injected into their firmware. "Products known to contain the backdoor have been found on public school networks throughout the United States," Human says.

Discovered in 2016, Triada is a modular trojan residing in a device's RAM, relying on the Zygote process to hook all applications on Android, actively using root privileges to substitute system files. Over time, the malware went through various iterations and was found pre-installed on low-cost Android devices on at least two occasions. As part of the BadBox operation that Human Security discovered, the infected low-cost Android devices allow threat actors to carry out various ad-fraud schemes, including one named PeachPit, which at its peak relied on 121,000 Android and 159,000 iOS devices infected with malware, and on 39 Android, iOS, and CTV-centric apps designed to connect to a fake supply-side platform (SSP).

One of the modules delivered to the infected devices from the command-and-control (C&C) server allows the creation of WebViews that are fully hidden from the user, but which "are used to request, render, and click on ads, spoofing the ad requests to look like they're coming from certain apps, referred by certain websites, and rendered" on specific devices. BadBox, Human Security notes, also includes a residential proxy module that allows the threat actors to sell access to the victim's network. Furthermore, they can create WhatsApp messaging accounts and Gmail accounts they can then use for other malicious activities. "Finally, because of the backdoor's connection to C2 servers on BadBox-infected smartphones, tablets, and CTV boxes, new apps or code can be remotely installed by the threat actors without the device owner's permission. The threat actors behind BadBox could develop entirely new schemes and deploy them on BadBox-infected devices without any interaction from the devices' owners," Human notes.

Privacy

23andMe Scraping Incident Leaked Data On 1.3 Million Users (therecord.media) 25

Jonathan Greig writes via The Record: Genetic testing giant 23andMe confirmed that a data scraping incident resulted in hackers gaining access to sensitive user information and selling it on the dark web. The information of nearly 7 million 23andMe users was offered for sale on a cybercriminal forum this week. The information included origin estimation, phenotype, health information, photos, identification data and more. 23andMe processes saliva samples submitted by customers to determine their ancestry.

When asked about the post, the company initially denied that the information was legitimate, calling it a "misleading claim" in a statement to Recorded Future News. The company later said it was aware that certain 23andMe customer profile information was compiled through unauthorized access to individual accounts that were signed up for the DNA Relative feature -- which allows users to opt in for the company to show them potential matches for relatives. [...] When pressed on how compromising a handful of user accounts would give someone access to millions of users, the spokesperson said the company does not believe the threat actor had access to all of the accounts but rather gained unauthorized entry to a much smaller number of 23andMe accounts and scraped data from their DNA Relative matches.

A researcher approached Recorded Future News after examining the leaked database and found that much of it looked real. [...] The researcher downloaded two files from the BreachForums post and found that one had information on 1 million 23andMe users of Ashkenazi heritage. The other file included data on more than 300,000 users of Chinese heritage. The data included profile and account ID numbers, names, gender, birth year, maternal and paternal genetic markers, ancestral heritage results, and data on whether or not each user has opted into 23andme's health data. The researcher added that he discovered another issue where someone could enter a 23andme profile ID, like the ones included in the leaked data set, into their URL and see someone's profile. The data available through this only includes profile photos, names, birth years and location but does not include test results.

Businesses

All Slack Employees Forced To Spend a Week Getting Salesforce Certifications (fortune.com) 57

Kylie Robison writes via Fortune: Beginning on Monday, Slack employees will be expected to set aside their regular work duties and to instead plug away at various modules on Salesforce's Trailhead online learning platform, Fortune has learned. The goal is for Slack's employees to reach Trailhead's Ranger level, a feat that requires roughly 40 hours on the learning platform, whose modules include topics like "Learn about the Fourth Industrial Revolution" and "Healthy Eating." A large percent of Slack's roughly 3,000 staff have neglected to hit the target, according to sources inside the company. And since Salesforce provides Trailhead to other businesses as a way to "upskill" employees, some speculate that the slackers at Slack make for bad optics.

In a message to employees in mid-September, Slack CEO Lidiane Jones wrote that the one week shutdown, dubbed "Ranger Week," is intended to give everyone "dedicated time to make a lot of progress towards the goal." Jones wrote in her message that the product development engineering (PDE), customer experience (CE), Biz Ops, and communication departments are expected to participate in Ranger Week. "It's important that we all reach Ranger status this year, and I want to ensure that everyone has focus time to upskill on Trailhead," Jones wrote in the message to staff. "I know this will disrupt and slow V2MOM progress for many of us -- we are making this a priority now so we can quickly get back to work on our roadmaps," she said, referring to the company's annual forward-looking strategy planning document which stands for vision, values, methods, obstacles, and measures. [...]

"We really are canceling all meetings next week to facilitate this heads-down time, even 1:1s," Slack's chief of staff to the CTO wrote to employees on Wednesday. "We don't know yet what will happen to people who haven't hit Ranger by Jan. 31. At a minimum, it will make Slack look bad compared to the other clouds. Please do use the time next week to make as much progress as you can!" [...] Still, the work stoppage is somewhat porous. Slack's CTO noted that "deploys, on-call rotations, and interviews" will still happen as normal, and while no executive has used the word "mandatory," it's considered strongly encouraged.
According to Insider, some workers at Slack are "gaming" the platform to speed through the sessions.
Security

NSA Shares Top Ten Cybersecurity Misconfigurations (cisa.gov) 31

The National Security Agency (NSA), in partnership with the Cybersecurity and Infrastructure Security Agency (CISA), have highlighted the ten most common cybersecurity misconfigurations in large organizations. In their join cybersecurity advisory (CSA), they also detail the tactics, techniques, and procedures (TTPs) actors use to exploit these misconfigurations. From the report: Through NSA and CISA Red and Blue team assessments, as well as through the activities of NSA and CISA Hunt and Incident Response teams, the agencies identified the following 10 most common network misconfigurations:

1. Default configurations of software and applications
2. Improper separation of user/administrator privilege
3. Insufficient internal network monitoring
4. Lack of network segmentation
5. Poor patch management
6. Bypass of system access controls
7. Weak or misconfigured multifactor authentication (MFA) methods
8. Insufficient access control lists (ACLs) on network shares and services
9. Poor credential hygiene
10. Unrestricted code execution

NSA and CISA encourage network defenders to implement the recommendations found within the Mitigations section of this advisory -- including the following -- to reduce the risk of malicious actors exploiting the identified misconfigurations: Remove default credentials and harden configurations; Disable unused services and implement access controls; Update regularly and automate patching, prioritizing patching of known exploited vulnerabilities; and Reduce, restrict, audit, and monitor administrative accounts and privileges.

NSA and CISA urge software manufacturers to take ownership of improving security outcomes of their customers by embracing secure-by-design and-default tactics, including: Embedding security controls into product architecture from the start of development and throughout the entire software development lifecycle (SDLC); Eliminating default passwords; Providing high-quality audit logs to customers at no extra charge; and Mandating MFA, ideally phishing-resistant, for privileged users and making MFA a default rather than opt-in feature.
A PDF version of the report can be downloaded here (PDF).
Microsoft

Microsoft Launches New Web App Store for Windows 21

Microsoft has launched a new web version of its app store for Windows. From a report: It's designed as a replacement for the existing way to find Windows apps on the web, with links from the site opening in the Microsoft Store client on Windows 10 or Windows 11. The software giant has ditched its old React codebase from its previous web version of the Microsoft Store and replaced it with a modern web version that uses Shoelace, Lit, Vite, and a C# ASPNET backend. "The old site was a React codebase built on an obsoleted UI framework," explains Microsoft engineer Judah Gabriel in a post on X (formerly Twitter). "We created a fresh user experience with a thoughtfully designed interface, easier ways to discover new apps, modern web tech stack. I hope folks will find it useful."
Google

Google Open-Sourced a Hat Shaped Like a Giant Keycap - and It Actually Types (arstechnica.com) 20

Google Japan's latest DIY project is for people who can't get keyboards off their heads. From a report: Google isn't making this product. Instead, the Gboard CAPS project is another of Google Japan's joke keyboard ideas, like the 5.25-foot-long, single-row Gboard Stick Version keyboard shown off last year, used to promote Google's Gboard app. However, Google Japan seemingly prototyped the keyboard in real life. Everything you need to make this typing topper, including the firmware and hardware, is open source and available on GitHub. How do you type with the hat? It has a 6-axis sensor that reads its position. Turn the hat to select a character and press its top to enter. It pairs via Bluetooth, runs on a 3.7V, 120mAh battery, and charges via USB-C.
Businesses

MGM Says Computer Hack Will Cost It $100 Million In Lost Profit (reuters.com) 59

An anonymous reader quotes a report from Reuters: MGM Resorts International said on Thursday a cyberattack last month that disrupted its operations would cause a $100 million hit to its third-quarter results, as it works to restore its systems. One of the world's largest gambling firms, MGM shut down its systems after detecting the attack to contain damage, it said. It expects to also incur less than $10 million as a related one-time cost in the quarter ended on Sept. 30. After the attack last month, customers posted social media images showing slot machines with error messages and queues at hotels in Las Vegas.

A hacking group named AlphV claimed it was involved in the breach. Sources earlier told Reuters AlphV worked with another outfit named Scattered Spider to break into MGM systems and steal data to hold for extortion. MGM has declined to comment on whether it was asked for or paid any ransom. The private data of customers who used MGM services before March 2019, including contact information, gender, date of birth and driver's license numbers, was breached, the company said. "We also believe a more limited number of Social Security numbers and passport numbers were obtained," it said. "We have no evidence that the criminal actors have used this data to commit identity theft or account fraud." [...]

The company expects the breach will have a negative impact of about $100 million to its adjusted property core profit for its Las Vegas Strip division, and expects total occupancy of 93% this October versus 94% in the same month a year ago. "Virtually all of the Company's guest-facing systems have been restored," it said, adding that it expects no impact on its full-year results from the breach. MGM said it is "well-positioned" to have a strong fourth quarter with record results in November, driven mainly by a Formula One racing event slated to take place in Las Vegas.

Microsoft

Microsoft Won't Say If Its Products Were Exploited By Spyware Zero-Days (techcrunch.com) 13

Microsoft has released patches to fix zero-day vulnerabilities in two popular open source libraries that affect several Microsoft products, including Skype, Teams and its Edge browser. But Microsoft won't say if those zero-days were exploited to target its products, or if the company knows either way. From a report: The two vulnerabilities -- known as zero-days because developers had no advance notice to fix the bugs -- were discovered last month, and both bugs have been actively exploited to target individuals with spyware, according to researchers at Google and Citizen Lab. The bugs were discovered in two common open source libraries, webp and libvpx, which are widely integrated into browsers, apps and phones to process images and videos. The ubiquity of these libraries coupled with a warning from security researchers that the bugs were abused to plant spyware prompted a rush by tech companies, phone makers and app developers to update the vulnerable libraries in their products.

In a brief statement Monday, Microsoft said it had rolled out fixes addressing the two vulnerabilities in the webp and libvpx libraries which it had integrated into its products, and acknowledged that exploits exist for both vulnerabilities. When reached for comment, a Microsoft spokesperson declined to say if its products had been exploited in the wild, or if the company has the ability to know. Security researchers at Citizen Lab said in early September that they had discovered evidence that NSO Group customers, using the company's Pegasus spyware, had exploited a vulnerability found in the software of an up-to-date and fully patched iPhone.

Networking

Linux Tries To Dump Windows' Notoriously Insecure RNDIS Protocol (zdnet.com) 35

An anonymous reader quotes a report from ZDNet: Microsoft's proprietary protocol, Remote Network Driver Interface Specification (RNDIS), started with a good idea. It would enable hardware vendors to add networking support to USB devices without having to build them from scratch. There was only one little problem. RNDIS has no security to speak of. As Greg Kroah-Hartman, the Linux Foundation fellow responsible for stable Linux kernel releases, wrote in November 2022 on the Linux Kernel Mailing List (LKML), "The Microsoft RNDIS protocol is, as designed, insecure and vulnerable on any system that uses it with untrusted hosts or devices. Because the protocol is impossible to make secure, just disable all RNDIS drivers to prevent anyone from using them again."

He added, in another message, "The protocol was never designed to be used with untrusted devices. It was created, and we implemented support for it, when we trusted USB devices that we plugged into our systems, AND we trusted the systems we plugged our USB devices into." That's no longer the case. Kroah-Hartman concluded, "Today, with untrusted hosts and devices, it's time just to retire this protocol. As I mentioned in the patch comments, Android disabled this many years ago in their devices, with no loss of functionality."

[...] But now, sick and tired of having a built-in Windows security exploit in Linux, Kroah-Hartman has decided that enough was enough. He's disabled all the RNDIS protocol drivers in Linux's Git repository. That means that while the RNDIS code is still in the Linux kernel, if you try to build Linux using this new patch, all your RNDIS drivers will be broken and won't build. This is one step short of purging RNDIS from Linux.

IT

Russia Plans To Block VPN In March 2024 (reuters.com) 150

Russia's communications watchdog plans to block VPNs from March 1 next year, a Russian senator for the ruling United Russia party said on Tuesday. From a report: Demand for VPN services soared after Russia restricted access to some Western social media after President Vladimir Putin ordered troops into Ukraine in February 2022. Senator Artem Sheikin said an order from the Roskomnadzor watchdog would come into force on March 1 that would block VPNs. "From March 1, 2024, an order will come into force to block VPN services providing access to sites banned in Russia," Sheikin was quoted as saying by state news agency RIA.
Security

Clorox Security Breach Linked to Group Behind Casino Hacks (bloomberg.com) 23

A notorious group of hackers blamed for recent breaches on major casino companies is also suspected of being behind a recent cyberattack against Clorox that has led to a nationwide shortage of its cleaning products. Bloomberg News: Officials suspect that "Scattered Spider" is responsible for a breach that Clorox first disclosed in August, according to four people familiar with the situation, who asked not to be identified because the information isn't public. The same group, known for its so-called social engineering tactics, was tied to attacks on Caesars Entertainment and MGM Resorts International in recent weeks, Bloomberg News previously reported.

Scattered Spider hackers specialize in targeting call centers and IT help desks, impersonating employees to trick support staff into coughing up information to gain access to accounts. The fallout from their recent attacks has been profound. At MGM properties, guests couldn't charge purchases to their rooms, slot machines were shut down and reservation websites weren't working. The impact on Clorox was arguably much worse. The company didn't immediately respond to requests for comment. On Friday, Clorox indicated that it was still working to recover from the disruption. "We are ramping up production and working to restock trade inventories," the company said in a statement. "We are focusing on maximizing shipments and restocking trade inventories."

Iphone

Apple Releases iPhone Software Update To Fix Overheating Issue (bloomberg.com) 36

Apple rolled out a software update Wednesday to address an overheating issue that plagued some early buyers of the iPhone 15 Pro line. From a report: The update, called iOS 17.0.3, is available as an over-the-air fix in the software update section of the iPhone settings app. The release notes say the update "provides important bug fixes, security updates, and addresses an issue that may cause iPhone to run warmer than expected." The update was also released for older iPhones as well as iPads. Some early iPhone 15 Pro owners reported that their iPhone could get hotter than normal. Apple on Saturday blamed bad code in apps including Uber, Instagram and the Asphalt 9 racing game, in addition to a bug in the device's software. The company said the new device set-up could overwork the processor and lead to overheating.
Google

The Google Pixel 8 is Official With 7 Years of Updates (arstechnica.com) 77

Google's newest flagship phone is finally official. The Pixel 8 and Pixel 8 Pro were both unveiled today, with the headline changes being a whopping seven years of updates, flat screens across the board, new CPUs, and a $100 price increase. The Pixel 8 Pro is officially $999, while the Pixel 8 is $699. ArsTechnica: As for specs, the Pro display is a 6.7-inch, 120 Hz, 2992x1344 OLED. Google is branding this display "Super Actua" because it's one of the brightest phone displays on the market at 1600 nits for HDR content and 2400 nits in sunlight mode. That beats the sunlight modes on the S23 Ultra (1750 nits) and iPhone 15 Pro Max (2000 nits) but not the Xiaomi 13T Pro (2600 nits). The storage situation here isn't great. The Pixel 8 Pro has 12GB of RAM and storage tiers of 128GB, 256GB, 512GB, and 1TB. Most other phones in this price range start at 256GB, and the 8 Pro uses slower UFS 3.1 storage instead of the speedy UFS 4.0 a lot of phones ship with now. The 8 Pro battery is 5050 mAh, and there's 30 W wired charging. Wireless charging will hit 23 W on the Pixel charging stand, while Qi chargers will only hit 12 W (it would be great if Qi2 would get its act together). Both phones have IP68 dust and water resistance. On the software update support lifecycle: This year, there is finally something tangible to point to -- 7 years of OS updates. Unlike with previous models, there are no games being played here, as Google says there are "7 years of OS, security, and Feature Drop updates." That's more major OS updates than even iPhone owners are getting, with the iPhone X getting iOS versions 11-16.
Security

FBI Most-Wanted Russian Hacker Reveals Why He Burned His Passport 124

An anonymous reader shares a report: Russian hacker Mikhail Matveev, also known on the internet as "Wazawaka" and "Boriselcin," is wanted by the FBI, which is offering a $10 million reward for information that could lead to his arrest, and has been put on a U.S. sanctions list. But, according to Matveev, his life hasn't changed much since he was outed as an alleged cybercriminal and put on the FBI's most wanted list. "We are Russian people, we are not afraid of the American government," Matveev told TechCrunch in an online interview. "My life has changed for the better after the sanctions, I don't feel them on me, as well as sanctions are a plus for my security, so sanctions help us."

In an interview where he answered both in English and in Russian, Matveev said that being sanctioned means Russia will not deport him. And to avoid getting caught outside of Russia, he won't travel anymore, and said he has "burned" his passport. His last trip, he said, was to Thailand in 2014, where he ate scorpion, which he said was "delicious." Earlier this year, the U.S. government accused Matveev of participating in "a global ransomware campaign" against victims all over the world. Prosecutors claim Matveev is "a prolific ransomware affiliate," who worked with the Hive, LockBit and Babuk ransomware gangs to carry out "significant attacks" against corporations and critical infrastructure in the U.S. and elsewhere, including hospitals and government agencies.
Encryption

New Group Attacking iPhone Encryption Backed By US Political Dark-Money Network (theintercept.com) 52

Long-time Slashdot reader schwit1 shares a report from The Intercept: The Heat Initiative, a nonprofit child safety advocacy group, was formed earlier this year to campaign against some of the strong privacy protections Apple provides customers. The group says these protections help enable child exploitation, objecting to the fact that pedophiles can encrypt their personal data just like everyone else. When Apple launched its new iPhone this September, the Heat Initiative seized on the occasion, taking out a full-page New York Times ad, using digital billboard trucks, and even hiring a plane to fly over Apple headquarters with a banner message. The message on the banner appeared simple: 'Dear Apple, Detect Child Sexual Abuse in iCloud' -- Apple's cloud storage system, which today employs a range of powerful encryption technologies aimed at preventing hackers, spies, and Tim Cook from knowing anything about your private files.

Something the Heat Initiative has not placed on giant airborne banners is who's behind it: a controversial billionaire philanthropy network whose influence and tactics have drawn unfavorable comparisons to the right-wing Koch network. Though it does not publicize this fact, the Heat Initiative is a project of the Hopewell Fund, an organization that helps privately and often secretly direct the largesse -- and political will -- of billionaires. Hopewell is part of a giant, tightly connected web of largely anonymous, Democratic Party-aligned dark-money groups, in an ironic turn, campaigning to undermine the privacy of ordinary people.

For an organization demanding that Apple scour the private information of its customers, the Heat Initiative discloses extremely little about itself. According to a report in the New York Times, the Heat Initiative is armed with $2 million from donors including the Children's Investment Fund Foundation, an organization founded by British billionaire hedge fund manager and Google activist investor Chris Cohn, and the Oak Foundation, also founded by a British billionaire. The Oak Foundation previously provided $250,000 to a group attempting to weaken end-to-end encryption protections in EU legislation, according to a 2020 annual report. The Heat Initiative is helmed by Sarah Gardner, who joined from Thorn, an anti-child trafficking organization founded by actor Ashton Kutcher. [...] Critics say these technologies aren't just uncovering trafficked children, but ensnaring adults engaging in consensual sex work.
"My goal is for child sexual abuse images to not be freely shared on the internet, and I'm here to advocate for the children who cannot make the case for themselves," Gardner said, declining to name the Heat Initiative's funders. "I think data privacy is vital. I think there's a conflation between user privacy and known illegal content."
Google

Google Mandates Unsubscribe Button in Emails For Those Sending Over 5,000 Daily Messages (cnbc.com) 91

Google plans to make it harder for spammers to send messages to Gmail users. From a report: The company said it will require emailers who send more than 5,000 messages per day to Gmail users to offer a one-click unsubscribe button in their messages. It will also require them to authenticate their email address, configuring their systems so they prove they own their domain name and aren't spoofing IP addresses. Alphabet-owned Google says it may not deliver messages from senders whose emails are frequently marked as spam and fall under a "clear spam rate threshold" of 0.3% of messages sent, as measured by Google's Postmaster Tools.

Google says it has signed up Yahoo to make the same changes, and they'll come into effect in February 2024. The moves highlight the ongoing fight between big tech companies and spammers who use open systems such as email to send fraudulent messages and annoy users. For years, machine learning techniques have been used to fight spam, but it remains a back-and-forth battle as spammers discover new techniques to get past filters.

Microsoft

Microsoft Kills Its Classic Azure DaaS, Because It Isn't Really Azure (theregister.com) 14

Microsoft will deprecate the classic edition of its Azure Virtual Desktop desktop-as-a-service (DaaS) and has given customers three years to keep using the service before they'll need to find an alternative. From a report: The software giant seems to have spent years trying to confuse cloudy DaaS users, as it has offered two products called Azure Virtual Desktop, with varying degrees of integration with Azure.

The "classic" service has a management GUI that's not part of the Azure Portal and isn't addressable with the Azure Resource Manager (ARM), Microsoft's main deployment and management service for its cloud. The successor to Azure Virtual Desktop (AVD) classic is called -- wait for it -- "Azure Virtual Desktop." This from the innovative minds that suddenly and inexplicably renamed Azure Active Directory as "Entra" and kept the name "Active Directory" for on-prem directories.

Security

Vulnerable Arm GPU Drivers Under Active Exploitation, Patches May Not Be Available (arstechnica.com) 30

An anonymous reader quotes a report from Ars Technica: Arm warned on Monday of active ongoing attacks targeting a vulnerability in device drivers for its Mali line of GPUs, which run on a host of devices, including Google Pixels and other Android handsets, Chromebooks, and hardware running Linux. "A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory," Arm officials wrote in an advisory. "This issue is fixed in Bifrost, Valhall and Arm 5th Gen GPU Architecture Kernel Driver r43p0. There is evidence that this vulnerability may be under limited, targeted exploitation. Users are recommended to upgrade if they are impacted by this issue."

The advisory continued: "A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system's memory is carefully prepared by the user, then this in turn could give them access to already freed memory." [...] Getting access to system memory that's no longer in use is a common mechanism for loading malicious code into a location an attacker can then execute. This code often allows them to exploit other vulnerabilities or to install malicious payloads for spying on the phone user. Attackers often gain local access to a mobile device by tricking users into downloading malicious applications from unofficial repositories. The advisory mentions drivers for the affected GPUs being vulnerable but makes no mention of microcode that runs inside the chips themselves.

The most prevalent platform affected by the vulnerability is Google's line of Pixels, which are one of the only Android models to receive security updates on a timely basis. Google patched Pixels in its September update against the vulnerability, which is tracked as CVE-2023-4211. Google has also patched Chromebooks that use the vulnerable GPUs. Any device that shows a patch level of 2023-09-01 or later is immune to attacks that exploit the vulnerability. The device driver on patched devices will show as version r44p1 or r45p0. CVE-2023-4211 is present in a range of Arm GPUs released over the past decade. The Arm chips affected are:

- Midgard GPU Kernel Driver: All versions from r12p0 - r32p0
- Bifrost GPU Kernel Driver: All versions from r0p0 - r42p0
- Valhall GPU Kernel Driver: All versions from r19p0 - r42p0
- Arm 5th Gen GPU Architecture Kernel Driver: All versions from r41p0 - r42p0

Slashdot Top Deals