Cisco – a company that likes to remind us how much of their hardware makes up the infrastructure of the internet – has released a statement warning that an “unintentional debugging credential” has not been removed from some of their devices before they were sold. This affects devices found in …
Hiding the threat in plain sight
Attackers are always looking for new way to get their illicit packages through defences and this research paper outlines how by exploiting Unicode, malicious code can be written into software so that human code reviewers cannot recognise that it is there. Trojan Source: Invisible Vulnerabilities “This work has been under …