➀ CrowdStrike President Michael Sentonas accepted the Pwnie Epic Fail award at DEF CON for a major software update failure that caused widespread IT outages. ➁ Sentonas used the acceptance speech to apologize and emphasize the importance of owning mistakes. ➂ The towering Pwnie trophy will serve as a reminder at CrowdStrike's HQ of the potential for such failures.
Recent #cybersecurity news in the semiconductor industry
1. Cisco is expected to report earnings this week with low expectations due to recent layoffs and weak IT spending. 2. The company remains optimistic in the long term due to its high-quality business model, attractive valuation, and growing software and cybersecurity operations. 3. The stock is trading at a discounted valuation with low expectations, potentially offering a good entry point for long-term investors.
➀ Google researchers discovered 9 vulnerabilities in Qualcomm's Adreno GPU; ➁ These vulnerabilities could allow hackers full control over Qualcomm-powered devices; ➂ Qualcomm has already patched the issues, but users should still be cautious.
➀ AMD's 'Sinkclose' vulnerability affects millions of processors, allowing deep system infiltration. ➁ The flaw leverages an ambiguous feature in AMD chips, enabling persistent malware installation. ➂ AMD has begun patching affected products, urging users to apply fixes promptly.
1. Russia-affiliated criminals have hijacked an estimated 30,000 domains using the Sitting Ducks technique since 2019. 2. The technique exploits weak DNS services, allowing unauthorized changes to domain records. 3. Hijacked domains are often used for phishing, scams, spam, and other illegal activities, posing risks to both owners and visitors.
1. Fraunhofer FIT, in collaboration with the CyberSEAS consortium, has developed solutions to enhance the resilience of Electric Power and Energy Systems (EPES) against cyber-physical threats. 2. The CyberSEAS project aims to improve energy supply chain resilience and protect consumer data. 3. Key contributions include the validation of cybersecurity tools in the Fraunhofer FIT Testing Lab and the development of a Cybersecurity Playbook Management Tool.
1. Microsoft calls for new laws against AI-generated deepfake videos. 2. The company emphasizes the need to hold creators accountable for nefarious uses. 3. Brad Smith highlights the risks of deepfakes being used for fraud, abuse, and manipulation, especially targeting children and the elderly.
1. CrowdStrike's faulty update caused approximately 8.5 million Windows PCs to enter infinite boot loops. 2. The global IT outage is estimated to cost affected companies billions of dollars. 3. Industries hit hardest include airlines, banking, healthcare, and retail.
1. Stalker 2: Heart of Chornobyl is set to release on November 20th, following multiple delays due to the Ukraine conflict and cyberattacks. 2. A new gameplay deep dive will be hosted on Xbox YouTube channel next month. 3. The game will be available on Xbox Series X/S, PC, and for Game Pass subscribers on day-one, with some changes in Game Pass tiers affecting access.
1. Southwest Research Institute identified cybersecurity vulnerabilities in EV fast-charging systems using direct current technology. 2. Researchers exploited vulnerabilities in power line communication (PLC) to access network keys and digital addresses. 3. The team developed an adversary-in-the-middle device to test cyber resiliency and propose encryption as a security enhancement.
1. CrowdStrike's Falcon platform caused a global outage, leading to an 11% drop in share price. 2. Despite the outage, the company's core SaaS business is rapidly growing and generating significant free cash flow. 3. The outage presents a buying opportunity for risk-tolerant investors due to oversold conditions and strong financials.
1. CrowdStrike's faulty driver update caused millions of Windows PCs to go offline. 2. The outage affected critical infrastructure globally and required physical intervention to fix. 3. Microsoft's initial estimate of affected devices was potentially doubled by expert analysis.
1. CrowdStrike's faulty driver update caused a global Windows outage affecting millions of PCs. 2. The outage impacted various sectors including emergency services, hospitals, and stock exchanges. 3. Microsoft estimates that less than 1% of all Windows machines, specifically 8.5 million, were affected.
1. A historic global IT outage affecting millions of Windows PCs has led to a dangerous phishing scam. 2. The outage was caused by a faulty driver update from CrowdStrike, disrupting industries and critical infrastructure. 3. The Singapore Cyber Emergency Response Team warns of phishing scams impersonating CrowdStrike staff and selling fake recovery solutions.
1. Microsoft CEO Satya Nadella addressed the largest IT outage in history, where millions of Windows PCs experienced blue screens. 2. The outage was caused by a faulty driver in an update from cybersecurity company CrowdStrike. 3. A manual fix has been provided, requiring systems to boot in safe mode and delete a specific file.
1. CrowdStrike released an update causing millions of Windows PCs to experience a blue screen of death loop; 2. The issue was traced back to a faulty driver update 'C-00000291.sys'; 3. CrowdStrike has provided workaround steps for individual hosts and public cloud environments.
1. Millions of Windows-based systems experienced BSOD due to a faulty update in CrowdStrike's Falcon security software. 2. The Falcon Sensor component, running in Kernel Mode, caused a Kernel Panic leading to system-wide crashes. 3. The issue can be resolved by accessing the Windows Recovery Environment and deleting the problematic driver files.
1. Riot Games Korea is working on resolving various issues such as DDoS attacks and errors with its anti-cheat program, Vanguard. 2. The company has collaborated with the security industry to address DDoS issues but acknowledges that fundamental solutions require more involvement from the central office. 3. The LCK league has been affected by DDoS attacks, leading to game delays and the decision to switch to recorded broadcasts without a live audience. T1, a top team, has also been a target, prompting them to demand action from Riot Games. Vanguard has caused connection errors and black screen issues, leading to a global server outage in April. Security experts believe that resolving these issues will take time and require more effort from Riot's central office.
1. Cybercriminals are targeting Paris Olympics attendees with phishing emails. 2. Proofpoint reports that 66% of official Paris Olympics partners have inadequate security policies to prevent domain spoofing. 3. The company suggests that DMARC products are the best solution for preemptive protection.
1. The HAL2025 ideas competition, organized by the Agentur für Innovation in Cybersicherheit, seeks innovative solutions in autonomous intelligent systems in a swarm. 2. Participants can submit their ideas until August 31, 2024, with the top three receiving contracts to further develop their concepts. 3. The best idea will win 100,000 euros, with the potential for subsequent research projects in national security.