James Forshaw from Google Project Zero revealed a critical Windows vulnerability in accessing COM objects via the IDispatch interface. This flaw allows attackers to exploit remoting technologies for executing code in higher-privileged server processes. Despite improvements in type library validation, risks remain, emphasizing the need for secure handling of objects across process boundaries in complex systems.
Malware Found in Healthcare Patient Monitors Linked to Chinese IP Address
Contec CMS8000 patient monitors have revealed a cybersecurity vulnerability of embedded malware that risks both patient safety and data security. The U.S. Cybersecurity and Infrastructure