
ISC StormCast for Thursday, March 2nd, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
UEFI Rootkit - Black Lotus Rootkit
CERT.org is warning about buffer overflow, actually two buffer overflows in the TPM 2.0 reference implementations. This buffer overflow may allow an attacker to then read cryptographic keys they would otherwise not have access to also possibly overwrite some of them. And in other vulnerabilities, we have several vulnerabilities being patched by Aruba in Aruba OS. These vulnerabilities lead all the way up to the unauthenticated command injection.
Transcript
Play full episode