Recent #Vulnerability news in the semiconductor industry

6 months ago

➀ Io_uring was introduced in 2019 to improve the efficiency and flexibility of input and output operations on Linux, but it also created critical blind spots for Linux security tools.

➁ Security researchers have discovered that io_uring operations can completely evade conventional system call monitoring, leading to undetectable activities.

➂ A rootkit called Curing was built to exploit this vulnerability, which can execute commands, read files, and interact with the network without detectable system calls.

LinuxVulnerabilitysecurity
about 1 year ago
➀ A 5-year-old vulnerability in AVTECH's network cameras has been exploited to inject a Mirai variant known as Corona Mirai. ➁ The vulnerability, CVE-2024-7029, allows remote code execution and command injection with a CVSS score of 8.7. ➂ Despite being known since 2019, the vulnerability remains unpatched, and the Mirai variant has been active since at least December 2023.
Mirai BotnetVulnerabilitycybersecurity