Tag: Hardware
-
DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory
A newly disclosed hardware attack dubbed DDRop can undermine Intel Trust Domain Extensions (TDX) by manipulating DDR5 memory traffic, allowing an attacker with physical server access to force confidential virtual machines into debug mode and extract private memory in plaintext. Researchers from KU Leuven, ETH Zurich, Google, Durham University, and other institutions released proof-of-concept code,…
-
12 Best Browser Isolation Solutions Compared (2026): Features Pricing
Quick Answer: Zscaler and Cloudflare lead RBI delivered inside SSE platforms; Menlo Security leads isolate-everything efficacy; Garrison (Everfox) owns hardware-grade high assurance for government; Authentic8 Silo dominates managed OSINT/investigations; Kasm is the self-host value play. RBI typically prices per user per month. The browser executes more untrusted code than any other program on an endpoint…
-
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current.The attack requires an attacker who already controls the server’s software and can briefly access…
-
Cylake Gets $245M to Build Cloud-Free Cybersecurity Platform
Nir Zuk’s Startup Targets Firms Unable to Send Sensitive Security Data to the Cloud. Cylake, led by Palo Alto Networks founder Nir Zuk, raised $245 million to build an on-premises cybersecurity system combining hardware, storage, security software and local AI for regulated organizations that can’t send sensitive data to external clouds. First seen on govinfosecurity.com…
-
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
This is the second data breach affecting a company that hardware crypto wallet maker Trezor relies on. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/
-
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. This vulnerability is tracked as CVE-2026-0310 and stems from PAN-OS XML processing. It impacts both the firewall management web interfaces and the dataplane interfaces. The…
-
A new open standard locks AI weights to approved hardware
OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/weight-custody-manifest-open-standard/
-
Smashing Security podcast #484: How websites are tracking you with silence
When a chap called Matt noticed his Bluetooth headphones wouldn’t switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser – playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking…
-
Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/
-
New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away
Security researchers have unveiled InjectEave, an electromagnetic side-channel attack that can turn ordinary headphones into unintended transmitters. By directing radio-frequency energy at vulnerable hardware and collecting the resulting emissions, an attacker can reconstruct audio playing through a target device. In a long-range experiment using amplified equipment, researchers successfully recovered audible speech from wireless headphones at…
-
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
-
The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced
Best value overall: Ubiquiti. Published hardware pricing, no mandatory licensing, and WPA3 with VLAN segmentation included for organizations whose compliance requirements don’t demand enterprise wireless intrusion prevention. Best capability: HPE Aruba. Best management: Cisco Meraki and Juniper Mist. Best if you own the firewall: Fortinet, utilizing your existing FortiGate firewalls. The critical cost question in…
-
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company’s…
-
On-device AI security gains traction with hardware telemetry
First seen on scworld.com Jump to article: www.scworld.com/brief/on-device-ai-security-gains-traction-with-hardware-telemetry
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/linux-foundation-trace-standard-ai/
-
New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
Tags: HardwareTCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirements First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/guidance-verify-quantum-safe/
-
Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers
Microsoft is currently investigating a compatibility issue with Windows 11, in which certain games crash, freeze, or cause unexpected system restarts on devices equipped with RGB lighting hardware and related low-level drivers. This problem was reported following the release of Windows updates on August 11, 2026, including the KB5121003 update for OS Build 26100.9168. Microsoft…
-
The Enterprise Passkey Migration Decision Framework: When Device-Bound vs. Synced Passkeys Actually Matter
A decision framework for enterprise passkeys: when device-bound hardware keys beat synced passkeys, mapped to user risk, device context, compliance, and total cost. Includes the three failure patterns that surface only after rollout. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-enterprise-passkey-migration-decision-framework-when-device-bound-vs-synced-passkeys-actually-matter/
-
Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near
The coming threat of super-powerful computers capable of cracking today’s algorithms requires upgrading encryption now. Tech companies have begun building defenses. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/hardware-makers-implement-post-quantum-cryptography

