Tuesday, April 21, 2020

Starbleed Vulnerability - A new security bug that impacts Xilinx FPGA chipsets.- Why is it important? - These chips are in many safety-critical applications today, from cloud data centers and mobile phone base stations to encrypted USB-sticks and industrial control systems

. This vulnerability allows an attacker to crack the bitstream encryption and tamper with the operations stored inside the bitstream, allowing the attacker to load their own malicious code on vulnerable devices. Intellectual properties included in the bitstream can be stolen. It is also possible to insert hardware Trojans into the FPGA by manipulating the bitstream.


https://www.zdnet.com/article/starbleed-bug-impacts-fpga-chips-used-in-data-centers-iot-devices-industrial-equipment/

Wednesday, April 15, 2020

Manufacturer of AirSense 10, the world’s most widely used CPAP says the AirSense 10 would require “significant rework to function as a ventilator,” while (surprise!) many ventilator functions were already built into the device firmware.

 Security researcher Trammel Hudson has released a patch (dubbed Airbreak) that he says unlocks the hidden capabilities buried deep inside the AirSense 10.


https://arstechnica.com/information-technology/2020/04/firmware-jailbreak-lets-low-cost-medical-devices-act-like-ventilators/