#side-channel-attack

[ follow ]
Information security
fromTheregister
1 week ago

LLM side-channel attack could allow snoops to guess topic

A side-channel attack named Whisper Leak can infer prompt topics from encrypted streaming LLM traffic by analyzing packet size and timing, exposing user communications.
fromThe Hacker News
2 weeks ago

Microsoft Uncovers 'Whisper Leak' Attack That Identifies AI Chat Topics in Encrypted Traffic

Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with capabilities to observe network traffic to glean details about model conversation topics despite encryption protections under certain circumstances. This leakage of data exchanged between humans and streaming-mode language models could pose serious risks to the privacy of user and enterprise communications, the company noted. The attack has been codenamed Whisper Leak.
Information security
Information security
fromThe Hacker News
3 weeks ago

New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves

Physical interposition on DDR5 memory enables extraction of cryptographic and attestation keys from Intel and AMD TEEs, compromising CPU and GPU confidential computing.
Information security
fromWIRED
1 month ago

A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones

Pixnapping enables a permissionless Android app to read other apps' on-screen sensitive data, stealing 2FA codes and messages in under 30 seconds.
#android-security
fromZDNET
1 month ago
Information security

This new 'Pixnapping' exploit can steal everything on your Android screen - even 2FA codes

fromZDNET
1 month ago
Information security

This new 'Pixnapping' exploit can steal everything on your Android screen - even 2FA codes

fromArs Technica
1 month ago

No fix yet for attack that lets hackers pluck 2FA codes from Android phones

The new attack, named Pixnapping by the team of academic researchers who devised it, requires a victim to first install a malicious app on an Android phone or tablet. The app, which requires no system permissions, can then effectively read data that any other installed app displays on the screen. Pixnapping has been demonstrated on Google Pixel phones and the Samsung Galaxy S25 phone and likely could be modified to work on other models with additional work.
Information security
fromCSO Online
1 month ago

Is your computer's mouse listening to you?

What makes this attack practical is the sensitivity of today's mice, both their high polling rate (the frequency at which they sample movement, measured in kHz), and the resolution with which they detect movement, measured in dots per inch (DPI).
Information security
fromTheregister
1 month ago

How your mouse could eavesdrop and rat you out

The mouse sitting next to you can be turned into a microphone thanks to some cunning use of its sensors to pick up vibrations from your voice in an attack dubbed Mic-E-Mouse. Researchers at UC Irvine have found that optical mice equipped with 20,000 DPI sensors and decent latency can be used as a basic microphone with software designed to figure out speech patterns based on the vibration of the user's voice. The team used a $35 mouse to test the system and found it could capture speech with 61 percent accuracy, depending on voice frequency.
Information security
fromsfist.com
1 month ago

Some Optical Gaming Mice Can Be Manipulated to Spy on Users Through AI, Researchers Warn

Researchers at UC Irvine uncovered a vulnerability that enables some gaming mice with polling rates of 4,000 Hz or higher many of which are developed in the Bay Area to be turned into spyware, capturing conversations through desk vibrations using AI. As Tom's Hardware reports, security researchers from the University of California Irvine found a way to use high-end optical gaming mice containing advanced sensors that can sample data up to 8,000 times per second, per Hoodline, to record users' conversations via desk vibrations.
Information security
Privacy professionals
fromTheregister
4 months ago

AMD warns of new Meltdown, Spectre-like bugs affecting CPUs

AMD's chips are vulnerable to a new side-channel attack called the Transient Scheduler Attack, which could lead to information disclosure.
[ Load more ]