Doorzoek en filter alle geregistreerde cyberdreigingen voor gemeenten.
412 dreigingen gevonden · pagina 30 van 35
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement. Audio Attack Surface The Dolby UDC is part of the 0-click attack surface of most Android devices because of audio transcription in the Google Messages application. Incoming audio messages are transcribed before a user interacts with t
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessible from the mediacodec SELinux context. BigWave is hardware present on the Pixel SOC that accelerates AV
The Center for AI Standards and Innovation (CAISI) at the U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has published a Request for Information (RFI) seeking insights from industry, academia, and the security
Understanding mDL credential formats Standards in the VDC Ecosystem In our first blog post in this series, we highlighted that VDCs can represent a wide range of credentials, from a driver’s license to a diploma to proof of age. The ability to use VDCs in a wide variety of use cases is a major reason why many are looking at the VDC ecosystem as technology that can change how we present identity and attributes (both in person and online). While credential variety is a good thing, interoperability requires a common set of standards and protocols for issuing, using, and verifying VDCs. The next
Rodney Petersen has served as the Director of NICE at the National Institute for Standards and Technology (NIST) for the past eleven years where his focus has been on advancing cybersecurity education and workforce development. He will be retiring from federal government service at the end of the 2025 calendar year. Prior to his role at NIST, he has worked in various technology policy and leadership roles with EDUCAUSE and the University of Maryland. The NICE program, led by the National Institute of Standards and Technology (NIST) in the U.S. Department of Commerce, has its origins in the
Openbaar gemaakte documenten na een verzoek om informatie over de relatie tussen de Baseline Informatiebeveiliging Overheid (BIO) en de ISO/IEC 27001:2022 en 2023. Het gaat om een verzoek op basis van de Wet open overheid (Woo). Let op: dit...
Besluit op een verzoek om informatie over de relatie tussen de Baseline Informatiebeveiliging Overheid (BIO) en de ISO/IEC 27001:2022 en 2023. Het gaat om een verzoek op basis van de Wet open overheid (Woo). Besluit Woo-verzoek over Baseline...
Minister Van Weel (JenV) informeert de Tweede Kamer over de stand van zaken van de informatiebeveiliging van het Openbaar Ministerie (OM) en de impact ervan op de werkprocessen van het OM. Kamerbrief over voortgang informatiebeveiliging OM
TK Beslisnota bij Kamerbrief Informatiebeveiliging OM
TK Brief Informatiebeveiliging OM
Het non paper bevat de Nederlandse reactie voor de Europese Commissie en lidstaten. Het paper gaat over het verwachte voorstel dat de Europese Commissie voor de herziening van de Cyberbeveiligingsverordening (Cyber Security Act, CSA). Non paper...