Connect with us

Press Release

On the first day of Pwn2Own Toronto, the Samsung Galaxy S22 was compromised twice.

Published

on

On the first day of Pwn2Own Toronto, the Samsung Galaxy S22 was compromised twice.

On the first day of the 10th iteration of the consumer-focused Pwn2Own Toronto 2022 hacking competition, competitors successfully penetrated the Samsung Galaxy S22 smartphone twice.

The STAR Labs team executed their faulty input validation assault on their third attempt, becoming the first to effectively exploit a zero-day on a Samsung flagship mobile, earning them $50,000 and 5 Master of Pwn points.

The Samsung Galaxy S22 was the target of another contestant’s successful exploit, demonstrated by Chim, who also earned $25,000 (or 50% of the reward for the second round of targeting the same device) and 5 Master of Pwn points.

The competition’s organisers state, “The first winner on each objective will get the whole cash award and the equipment under test.

“All other winners will receive 50% of the prize package for the second and future rounds on each target, but they will still gain the full Master of Pwn points.”

The Galaxy S22 devices in both instances ran the most recent version of the Android operating system with all available updates installed, in accordance with the contest’s regulations.

On the competition’s opening day, competitors successfully demonstrated exploits that target zero-day flaws in printers and routers from a variety of manufacturers, including Canon, Mikrotik, NETGEAR, TP-Link, Lexmark, Synology, and HP.

ZDI awarded a total of $400,000 today for 26 original and effectively demonstrated zero-day vulnerabilities.

Four days were added to the contest.
Security researchers can hack mobile phones, home automation hubs, printers, wireless routers, network-attached storage, smart speakers, and other devices that are all current and set to their default configuration during the Pwn2Own Toronto 2022 hacking competition hosted by Trend Micro’s Zero Day Initiative (ZDI).

For breaking into the Google Pixel 6 and Apple iPhone 13 handsets, they can receive the largest payouts in the mobile phone category, with cash awards ranging up to $200,000.

The maximum reward for a single challenge is $250,000 for a complete exploit chain with kernel-level access. Hacking Google and Apple devices can additionally result in $50,000 bonuses if the exploits execute with kernel-level privilege.

The consumer-focused Pwn2Own Toronto competition has been extended to four days (December 6–12) after 26 teams and competitors signed up to exploit 66 targets in all categories.

The competitive contest’s full schedule is available here. Here is the whole agenda for the first day of Pwn2Own Toronto 2022 as well as the outcomes for each task.

The Samsung Galaxy S22 will once more be put to the test by hackers from vulnerability research company Interrupt Labs on the second day of the competition.

Continue Reading

Press Release

Review of Bleeping Computer

Published

on

Review of Bleeping Computer

ComboFix is a tool made by sUBs that checks your computer for known malware and tries to automatically remove infestations when it finds any. In addition to being able to get rid of a lot of the most popular and up-to-date malware, ComboFix also shows a report that skilled assistants may use to get rid of malware that isn’t already eradicated by the programme.

Please be aware that executing this programme without supervision may result in improper operation of your computer. Run this programme only at the direction of a knowledgeable assistant.

At the moment, Windows 8.1 is not compatible with this programme, just Windows 8!

The author is collecting PayPal donations from people who want to support his work. By selecting the following picture, you may contribute:

Continue Reading

Press Release

Microsoft provides a fix for persistent Outlook login issues.

Published

on

Microsoft provides a fix for persistent Outlook login issues.

Microsoft is attempting to resolve ongoing sign-in issues that are preventing certain users of Outlook for Microsoft 365 from accessing their accounts.

Users who attempt to enter into Outlook using their Outlook.com accounts or those who have already added the accounts to their Outlook profiles are affected by the login issues.

The users will get the following error messages instructing them to use a work or school account rather than signing in: “You are unable to log in using a personal account here. Use your account from work or school instead.”

Although Microsoft claims that the Outlook Team is working on a patch for this known problem, users can access their accounts using an official workaround until a fix is released.

“You can get around the problem by disabling Support Diagnostics, which disables the ability to contact support through the In App Help menu by choosing Contact Support. The fault is connected to how Outlook is authenticating for the diagnostics in some cases, “explained Microsoft.

You must enable the DisableSupportDiagnostics policy setting in Outlook to turn off support diagnostics and stop it from informing support services about client failure.

According to the Group Policy Administrative Templates Catalog, “This policy setting determines whether Outlook can communicate client information on failure to support services with the intent of diagnosing the issue or making the information available to support to help with the diagnosis/resolution of the issue and/or provide contextual error messaging to the user.”

A different flaw that can prohibit users from configuring Exchange Online mailboxes in Outlook for Windows is something Redmond claimed it was attempting to fix last week.

Early in October, the company started releasing a remedy for a different problem that has been causing Outlook for Microsoft 365 to freeze and crash after opening since August.

Continue Reading

Press Release

After discovering a credit card skimmer, Costco admits a data breach.

Published

on

After discovering a credit card skimmer, Costco admits a data breach.

Customers who recently made purchases at one of Costco Wholesale Corporation’s stores have received notification letters informing them that their credit card information may have been stolen.

According to Fortune 500 rankings, the retail giant—also known as Costco Wholesale and Costco—is an American multinational that runs a sizable chain of membership-only retail locations. It is the fifth-largest retailer in the world and the tenth-largest firm in the US by total revenue.

It runs e-commerce websites with 737 warehouses across the world that cater to the Americas, Europe, and Asia, among other global regions.

planted skimmer in the Costco warehouse
During a regular check by Costco staff, a credit card skimming device was found in one of the company’s warehouses, leading to the discovery of the breach.

The business got rid of the gadget, let the authorities know, and is now assisting the police in their investigation.

In breach notification letters, Costco informed possibly impacted customers that they had recently visited a Costco facility where a payment card skimming device had been found.

“Our member records show that throughout the possible operational period of the device, you swiped your payment card to make a purchase at the impacted terminal.”

probable theft of customer financial information
Costco said that if those who placed the card theft device had been successful in accessing the data prior to the skimmer being discovered and taken out, then consumers affected by the incident may have had their payment information stolen.

The magnetic stripe of your credit card, which contains your name, card number, card expiration date, and CVV, may have been obtained by unauthorised individuals if they were able to remove information from the device before it was identified, according to Costco.

Customers were given advice by the retailer to check their bank and credit card statements for fraudulent payments and alert the appropriate financial institutions to any suspect activities.

The total number of customers who were impacted or the warehouse where the skimmer device was discovered were not disclosed in the data breach notification letters sent to affected consumers.

Although the business withheld details on the incident’s exact timing, Costco customers have been complaining about fraudulent charges on their credit cards at least since February.

Continue Reading

Trending