#root-of-trust

[ follow ]
fromSecurityWeek
1 week ago

Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack

Supermicro informed customers in January that a researcher from Nvidia had discovered several BMC firmware vulnerabilities, including CVE-2024-10237, an image authentication issue that could allow an attacker to conduct malicious firmware updates. "An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process," Supermicro explained. A malicious firmware update would enable the attacker to gain complete and persistent control of the BMC and the operating system.
Information security
Information security
fromTheregister
1 month ago

Microsoft shows off custom silicon keeping Azure on lockdown

Microsoft secures Azure compute with layered silicon security using integrated HSMs, trusted execution environments, smartNIC offloads, and an open-source Root of Trust (Caliptra 2.0).
[ Load more ]