Search results

  1. Depov

    Why your Wi-Fi works worse at lunch: about microwaves, aquariums and other unexpected enemies of home internet

    Home Wi-Fi can spoil not only a thick concrete wall or a weak router. Sometimes the connection disappears from a dinner in a microwave, an aquarium between rooms, a large mirror, or a TV that reflects a radio signal to the side. In winter, snow, frost and overloaded networks are added to...
  2. Depov

    Malicious code captures the device before the Linux starts. Six holes in the U-Boot bootload make antivirus useless witness

    Malicious firmware can hijack the device before Linux is launched and remain almost invisible to security programs. Binarly researchers have discovered six vulnerabilities in the U-Boot bootload, which uses routers, server equipment, industrial systems, and many IoT devices. U-Boot is...
  3. Depov

    15 years in the Linux kernel. Just one press gives your smartphone under the full control of intruders

    Even one click on the link is able to run a chain of operation of vulnerabilities, which overcomes several levels of smartphone protection at once. Nebula Security introduced IonStack is a test exploit for Android 17 that combines two previously unknown vulnerabilities and allows you to gain...
  4. Depov

    Hacking is easy, actually

  5. Depov

    How To Start Ethical Hacking in 2026

  6. Depov

    Attack on ML-DSa through a lack of sleep deprivation: from ILWE mathematics to key recovery in a second

    On June 4, 2026, Daniel Bernstein posted the work "Exploting ML-DSA bugs" (c.yp.to/papers/mldsa-20260601.pdf) - 59 pages, two working demonstrations key recovery from ML-DSA (FIPS 204). Both attacks end in less than a second on one kernel of a laptop: at the entrance - a public key and two...
  7. Depov

    Bit2Watt: manipulation of the GPU-load as a vector of cyber attack on the data center power system

    Coordinated load modulation of 1,000 GPU in the local power grid with a capacity of 1 MW with 90% DER - and total harmonic distortion of the current flies to 46.8%, and the damping coefficient fails to -0.27. The system is invaluable. This is a synchronized model of the worst case - but the...
  8. Depov

    Attack on ML-DSa through a lack of sleep deprivation: from ILWE mathematics to key recovery in a second

    On June 4, 2026, Daniel Bernstein posted the work "Exploting ML-DSA bugs" (c.yp.to/papers/mldsa-20260601.pdf) - 59 pages, two working demonstrations key recovery from ML-DSA (FIPS 204). Both attacks end in less than a second on one kernel of a laptop: at the entrance - a public key and two...
  9. Depov

    10 out of 10 points on CVSS - and the attacks began even before the release of the patch. We understand the dangers of two critical vulnerabilities in

    Two critical vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla are already used in attacks, and attackers began to act before the release of fixes. Both errors allow you to download malicious PHP-file to the site and execute the code on the server without logging in to the...
  10. Depov

    A permanent digital trail. Tell about GDID – the secret number of your computer, which Microsoft has been hiding from users for years

    Microsoft has been approcribing Windows computers with a hidden identifier that lasted after system updates and allowed you to distinguish one installation from another. The existence of the Global Device Identifier, or GDID, became widely known only after U.S. prosecutors uncovered the details...
  11. Depov

    BitTorrent is 25 years old. How the program of one person changed the Internet and put Hollywood in a dead end

    On July 2, 2001, little-known programmer Bram Cohen wrote to the participants of the mailings for peer developers of peers that his new BitTorrent program was already working, and offered to look at the result. The question about the appointment of the program Cohen did not answer. A few years...
  12. Depov

    MITRE ATT&CK and ISO 27001: how to combine frameworks for real infrastructure protection

    According to CrowdStrike Global Threat Report 2025, the average time of horizontal movement of the attacker after primary access is 62 minutes. The record is 51 seconds. At the gap-analysis of last year, I looked at the company’s infrastructure with the current ISO 27001 certificate and saw a...
  13. Depov

    Malicious browser extensions and AI chat theft: the anatomy of attacks on LLM-context

    In one of the samples that I met in the first of this year, the Chrome extension was positioned as an improved interface for working with ChatGPT. In a manifest - a typical payment set: activeTab, storage, tabs. Nothing criminal at first glance. Content script through MutationObserver tracked...
  14. Depov

    CVSS 9.2 and the maximum urgency from the vendor itself. Palo Alto Networks asks to close the hole in TSA as soon as possible

    One specially generated network request can turn the Palo Alto Networks firewall from a security tool to a penetration point. Vulnerability in PAN-OS allows a remote attacker without a record to disrupt the operation of the device, and if a successful attack, potentially perform an arbitrary...
  15. Depov

    10/10 and full site capture in one click. In the extensions of Joomla and Langflow found critical vulnerabilities

    The US authorities have warned of three vulnerabilities that attackers are already using in real attacks. The U.S. Cyber Security and Infrastructure Protection Agency has added dangerous errors to the vulnerability catalog and urged organizations to establish fixes as soon as possible...
  16. Depov

    There is no need for a hacker genius. Enough of one login and 49 minutes. Analysis of the attack on the supply chain Injective

    The usual update of the library to work with cryptocurrency wallets in 49 minutes turned into a trap that can transfer full control over users to the attackers. In the package @injectivelabs/sdk-ts for the Injective platform, a code was built that stole recovery phrases and private keys when the...
  17. Depov

    Your site could have stolen. CISA Confirms Real Attacks on Users of JoomShaper and Langflow

    When vulnerability moves from a technical description to real attacks, the time for elimination is drastically reduced, and the U.S. Infrastructure Security and Infrastructure Protection Agency (CISA) has added in the catalog of known operated KEV vulnerabilities at once three new records. CISA...
Top Bottom