Press Release
Samsung Galaxy S22 hacked again on second day of Pwn2Own
Contestants hacked the Samsung Galaxy S22 again during the second day of the consumer-focused Pwn2Own 2022 competition in Toronto, Canada.
They also demoed exploits targeting zero-day vulnerabilities in routers, printers, smart speakers, and Network Attached Storage (NAS) devices from HP, NETGEAR, Synology, Sonos, TP-Link, Canon, Lexmark, and Western Digital.
Security researchers representing the vulnerability research company Interrupt Labs were the ones to demonstrate a successful exploit against Samsung’s flagship device on Wednesday.
They executed an improper input validation attack and earned $25,000, 50% of the total cash award, because this was the third time the Galaxy S22 was hacked during the competition.
On the first day of Pwn2Own Toronto, the STAR Labs team and a contestant known as Chim demoed two other zero-day exploits as part of successful improper input validation attacks against the Galaxy S22.
In all three cases, according to the contest rules, the devices ran the latest version of the Android operating system with all available updates installed.
The second day of Pwn2Own Toronto wrapped up with Trend Micro’s Zero Day Initiative awarding $281,500 for 17 unique bugs across multiple categories.
This brings the first two days of Pwn2Own total to $681,250 awarded for 46 unique zero-days, as ZDI’s Head of Threat Awareness Dustin Childs revealed.
Competition extended to four days
At Pwn2Own Toronto 2022, security researchers target consumer devices in multiple categories, including mobile phones, home automation hubs, printers, wireless routers, network-attached storage, and smart speakers, all running the latest software and in their default configuration.
The mobile phone category comes with the highest cash prizes, with researchers earning up to $200,000 for hacking Apple iPhone 13 and Google Pixel 6 smartphones.
Hacked Google and Apple devices also come with $50,000 bonuses if the exploits execute with kernel-level privilege, with the maximum reward for a single challenge going up to $250,000 for a full exploit chain with kernel-level access.
This year’s Pwn2Own Toronto consumer-focused hacking competition has been extended to four days (between December 6th and December 8th) after 26 individual contestants and teams registered to exploit 66 targets across all contest categories.
The full schedule for Pwn2Own Toronto 2022’s second day and the results for each challenge are available. You can also find the complete schedule of the competition.
On the third day of the competition, Samsung Galaxy S22 will once again be put to the test by hackers with the Pentest Limited and Qrious Secure teams.
Press Release
MICROSOFT IS IN TERMS TO BUY SPEECH TECHNOLOGY COMPANY NUANCE COMMUNICATIONS FOR ABOUT $16 BILLION, OR $56 A SHARE, A 23% OVERPAYMENT TO NUANCE’S FRIDAY CLOSE, According to Sources (BLOOMBERG)
Bloomberg:
According to sources, Microsoft is in advanced talks to acquire Nuance Communications, a provider of speech technology, for about $16 billion, or $56 per share, a 23% premium to Nuance’s Friday close. The proposed price would value Nuance at $56 per share. This week could see the announcement of a deal.
Press Release
Nine widely used WiFi routers had 226 vulnerabilities.
Even when using the most recent firmware, security researchers examined nine widely used WiFi routers and discovered a total of 226 possible vulnerabilities in them.
Millions of people use the tested routers, which are made by Asus, AVM, D-Link, Netgear, Edimax, TP-Link, Synology, and Linksys.
The TP-Link Archer AX6000, which has 32 problems, and the Synology RT-2600ac, which has 30 security flaws, are the two devices with the most vulnerabilities.
The examination process
In partnership with CHIP magazine, researchers at IoT Inspector conducted security tests with a focus on models primarily used by small businesses and residential users.
According to Florian Lukavsky, CTO & Founder at IoT Inspector, “vendors provided them with current models, which were upgraded to the newest firmware version, for Chip’s router review.”
“IoT Inspector automatically examined the firmware versions and searched for more than 5,000 CVEs and other security flaws.”
Although not all defects posed the same risk, the researchers discovered a few widespread issues that impacted the majority of the evaluated models:
The firmware contains an outdated Linux kernel.
stale VPN and multimedia features
over-reliance on BusyBox’s earlier iterations
weak default passwords like “admin” are used
Hardcoded credentials are present in plain text.
Changing the router’s default password when configuring it for the first time is one of the most crucial steps you can take to secure it, according to Jan Wendenburg, CEO of IoT Inspector.
Whether an IoT device is used at home or in a corporate network, changing the password upon first use and turning on automatic updates must be regular procedure, according to Wendenburg.
In addition to manufacturer-introduced vulnerabilities, utilising an IoT device with the adage “plug, play, and forget” poses the greatest risk.
Press Release
MASSACHUSETTS COURT SUPPORTS A REQUEST FROM THE IRS TO OBTAIN THE RECORDS OF ALL CIRCLE CUSTOMERS WHO HAD $20K+ IN CRYPTO TRANSACTIONS BETWEEN 2016 AND 2020 (ZACK SEWARD/COINDESK)
Massachusetts court supports a request from the IRS to obtain the records of all Circle customers who had $20K+ in crypto transactions between 2016 and 2020 — A Massachusetts court is supporting a request from the IRS to obtain the records Circle customers, the Department of Justice said.
-
Apps1 year ago
Why is Everyone Talking About Hindi Keyboards?
-
Social Media1 year ago
Who is Rouba Saadeh?
-
Apps1 year ago
Things you need to know about Marathi keyboard today
-
Apps1 year ago
Stuck with Your default Bangla keyboard? Isn’t it time for a change?
-
Social Media1 year ago
Mati Marroni Instagram Wiki (Model’s Age, Net Worth, Body Measurements, Marriage)
-
Entertainment1 year ago
12 Online Streaming Sites that Serve as Best Alternatives to CouchTuner
-
Games12 months ago
Top 7 Popular Puzzle and Card Games for Relaxing Your Brain on Mobile, Featuring Solitaire
-
Entertainment1 year ago
Movierulz Website: Movierulzz 2021 Latest Movies on Movierulz.com