Listen "BTS #56 - Vulnerabilities & Backdoors In IT Infrastructure"
Episode Synopsis
In this episode, the hosts discuss various cybersecurity topics, focusing on Nvidia vulnerabilities, the implications of backdoors in technology, and the importance of secure boot and certificate management. They also delve into SonicWall's security challenges and the ongoing debate of building versus buying security solutions, particularly in the context of AI infrastructure and cloud services. Articles and topics for this week: https://blog.trailofbits.com/2025/08/04/uncovering-memory-corruption-in-nvidia-triton-as-a-new-hire/ https://mjg59.dreamwidth.org/72892.html - Secure Boot and certificates https://www.tomshardware.com/pc-components/gpus/nvidia-defiant-over-backdoors-and-kill-switches-in-gpus-as-u-s-mulls-tracking-requirements-calls-them-permanent-flaws-that-are-a-gift-to-hackers - https://www.bleepingcomputer.com/news/security/sonicwall-urges-admins-to-disable-sslvpn-amid-rising-attacks/ - https://www.darkreading.com/endpoint-security/shade-bios-technique-beats-security - Researcher’s previous paper on SMM and malware: https://arxiv.org/abs/2405.04355 He presented at Blackhat last year on Option ROMS: https://www.blackhat.com/us-24/briefings/schedule/index.html#youve-already-been-hacked-what-if-there-is-a-backdoor-in-your-uefi-orom-39579 - YouTube video: https://www.youtube.com/watch?v=_S6EymfaBqQ
More episodes of the podcast Below the Surface (Audio) - The Supply Chain Security Podcast
HybridPetya and UEFI Threats - BTS #60
22/09/2025
Exploit Marketplaces - BTS #59
10/09/2025
When Windows 10 Expires - BTS #51
30/05/2025