Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
6 résultats taggé list  ✕
MITRE Updates List of Most Common Hardware Weaknesses https://www.securityweek.com/mitre-updates-list-of-most-common-hardware-weaknesses/
24/08/2025 12:38:26
QRCode
archive.org

securityweek.com ByIonut Arghire| August 22, 2025 - MITRE has updated the list of Most Important Hardware Weaknesses to align it with evolving hardware security challenges.

The non-profit MITRE Corporation this week published a revised CWE Most Important Hardware Weaknesses (MIHW) to align it with the evolution of the hardware security landscape.

Initially released in 2021, the CWE MIHW list includes frequent errors that lead to critical hardware vulnerabilities, and is meant to raise awareness within the community, to help eradicate hardware flaws from the start.

The updated list includes 11 entries and comes with new classes, categories, and base weaknesses, but retains five of the entries that were included in the 2021 CWE MIHW list. It shows a focus on resource reuse, debug mode bugs, and fault injection.

‘CWE-226: Sensitive Information in Resource Not Removed Before Reuse’ is at the top of MITRE’s 2025 CWE MIHW list.

It refers to resources that are released and may be made available for reuse without being properly cleared. If memory, for example, is not cleared before it is made available to a different process, data could become available to less trustworthy parties.

“This weakness can apply in hardware, such as when a device or system switches between power, sleep, or debug states during normal operation, or when execution changes to different users or privilege levels,” CWE-226’s description reads.

Second on the revised list is ‘CWE-1189: Improper Isolation of Shared Resources on System-on-a-Chip (SoC)’, which was at the top four years ago.

Other entries that were kept from the previous version of the list include ‘CWE-1191: On-Chip Debug and Test Interface With Improper Access Control’, ‘CWE-1256: Improper Restriction of Software Interfaces to Hardware Features’, ‘CWE-1260: Improper Handling of Overlap Between Protected Memory Ranges’, and ‘CWE-1300: Improper Protection of Physical Side Channels’.

“These entries represent persistent challenges in hardware security that are both theoretically significant and commonly observed in practice. Their continued inclusion, even with the shift to a hybrid expert and data-driven selection process, underscores their ongoing importance,” MITRE notes.

Of the six new CWEs that made it to the revised MIHW list, two were added to the CWE after the 2021 MIHW list was released.

In addition to the 11 weaknesses included in the main MIHW list, MITRE warns of five others that are also highly important and could lead to serious security defects. These include four entries that were in the previous iteration of the list.

“Hardware weaknesses propagate upward: once embedded in silicon, they constrain software, firmware, and system-level mitigations. Engineers working at higher layers need to understand that some risks are inherited and may never be fully remediated at their level. That makes transparency from vendors, independent evaluation ecosystems, and better incentives for proactive security in design critical,” NCC Group managing security consultant Liz James said.

securityweek.com MITRE Hardware weaknesses CWE MIHW list updates
Cyberhaven Incident https://www.extensiontotal.com/cyberhaven-incident-live
15/01/2025 08:25:52
QRCode
archive.org

Stay updated on the latest developments of the Chrome Web Store incident involving Cyberhaven's compromised extension. Follow live updates, detailed analysis, impacted extensions, and expert recommendations for safeguarding your organization against similar attacks

extensiontotal EN 2025 Extensions Chrome-extension compromised hijacked list Cyberhaven
RockYou2024: 10 billion passwords leaked in the largest compilation of all time https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/
12/07/2024 10:39:05
QRCode
archive.org

The largest password compilation with nearly ten billion unique passwords was leaked on a popular hacking forum. The Cybernews research team believes the leak poses severe dangers to users prone to reusing passwords.

The king is dead. Long live the king. Cybernews researchers discovered what appears to be the largest password compilation with a staggering 9,948,575,739 unique plaintext passwords. The file with the data, titled rockyou2024.txt, was posted on July 4th by forum user ObamaCare.

cybernews EN 2024 RockYou2024 list combo passwords
Microsoft’s April 2023 Patch Tuesday Addresses 97 CVEs (CVE-2023-28252) https://www.tenable.com/blog/microsofts-april-2023-patch-tuesday-addresses-97-cves-cve-2023-28252
12/04/2023 09:58:46
QRCode
archive.org
thumbnail

Microsoft addresses 97 CVEs, including one that was exploited in the wild as a zero day

tenable EN 2023 PatchTuesday april zero-day microsoft list
U.S. ‘No Fly List’ Leaks After Being Left in an Unsecured Airline Server https://www.vice.com/en/article/93a4p5/us-no-fly-list-leaks-after-being-left-in-an-unsecured-airline-server
23/01/2023 13:47:57
QRCode
archive.org
thumbnail

The list, which was discovered by a Swiss hacker, contains names and birth dates and over 1 million entries.

vice EN 2023 nofly list leak
List of the most common passwords https://en.wikipedia.org/wiki/List_of_the_most_common_passwords
13/02/2022 01:56:54
QRCode
archive.org

This is a list of the most common passwords, discovered in various data breaches. Common passwords generally are not recommended on account of low password strength

Wikipedia EN reference list passwords common
4719 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio