Latest News

Read all latest blog posts

SLUBStick risk assessment for embedded systems
August 25, 2024

SLUBStick risk assessment for embedded systems

SLUBStick risk assessment for embedded systems The Linux kernel is susceptible to memory safety vulnerabilities due to its size and complexity.

Read More
VaultBoot: Attestation as a Service
June 27, 2022

VaultBoot: Attestation as a Service

VaultBoot In the highest level of security profile (CRITICAL), the Vault 111 hardware node enables multi-trust anchors through the chip security features.

Read More
VED (Vault Exploit Defense): Open source implementation
June 16, 2022

VED (Vault Exploit Defense): Open source implementation

VED - Linux kernel threat detection and prevention system LKM version of VED goes public finally.

Read More
Tetragon: case study of security product's self-protection
May 25, 2022

Tetragon: case study of security product's self-protection

Story background CTO of cloud-native security company Isovalent announced that their eBPF-based Security Observability and Runtime Enforcement solution Tetragon ( WayBackMachine 20220516 ) become open source after years of development in May 16 2022.

Read More
Exploiting CVE-2021-26708 (Linux kernel) with sshd
March 1, 2022

Exploiting CVE-2021-26708 (Linux kernel) with sshd

Kernel vulnerability CVE-2021-26708 Alexander Popov has published an article Four Bytes of Power: Exploiting CVE-2021-26708 in the Linux kernel which use a four-byte overwrite vulnerability to do privilege escalation.

Read More
Intel SGX deprecation review
January 15, 2022

Intel SGX deprecation review

The rumors about Intel SGX deprecated in new processors has been confirmed, 12th generation processors (Workstation/Desktop/Laptop/embedded platforms) will deprecate SGX and the SGX will continue to support only in high-end Xeon CPU for server:

Read More
Risk analysis of Log4Shell (CVE-2021-44228) and mitigation
December 17, 2021

Risk analysis of Log4Shell (CVE-2021-44228) and mitigation

Risk analysis of Log4Shell (CVE-2021-44228) and mitigation Log4Shell is a high impact exploitable bug in Java logging framework logj4.

Read More
VaultBoot: Next-Gen Firmware Security Solution
September 19, 2021

VaultBoot: Next-Gen Firmware Security Solution

Background Firmware is a special type of software, mainly used for the control and communication of the underlying hardware.

Read More
VaultFuzzer: A state-based approach for Linux kernel
September 13, 2021

VaultFuzzer: A state-based approach for Linux kernel

Background Since the beginning of computer software development, software quality has become an inevitable issue in the field of software testing.

Read More
VED (Vault Exploit Defense): A threat detection and prevention system
September 6, 2021

VED (Vault Exploit Defense): A threat detection and prevention system

Background In the beginning of the hacker's era, a long-term battle for control of the “CORE” in memory has been waged since Aleph One published the paper Smashing The Stack For Fun And Profit on Phrack Issue 49 in 1996.

Read More