New SnailLoad side-channel attack detailed


SecurityWeek reports that website and content inferencing could be remotely conducted by threat actors without direct network traffic access via the new SnailLoad side-channel attack technique.

Several latency measurements for websites and YouTube videos viewed by targets are being conducted by threat actors to establish digital fingerprints before luring targets to download files from a malicious server. Such content is slowly loaded by the server to enable continued tracking of connection latency, with threat actors potentially using a convolutional neural network for content inferencing.

Read more…
Source: SC Media


Sign up for our Newsletter


Related:

  • Kenya Airways suffers passenger data breach in cyber attack

    January 9, 2024

    Cybercriminals attacked Kenya Airways’ (KQ) information systems and obtained sensitive information, including contact details and identification documents, of passengers and staff of the airline, an authoritative source at KQ has confirmed. The cyber attack, which occurred late last month, led to unauthorised access to police investigation reports, phone numbers, email addresses, and passports of an unspecified ...

  • Deceptive Cracked Software Spreads Lumma Variant on YouTube

    January 8, 2024

    FortiGuard Labs recently discovered a threat group using YouTube channels to distribute a Lumma Stealer variant. We found and reported on a similar attack method via YouTube in March 2023. These YouTube videos typically feature content related to cracked applications, presenting users with similar installation guides and incorporating malicious URLs often shortened using services like TinyURL ...

  • Hundreds of museums hit by cyber attack

    January 8, 2024

    Hundreds of art institutions and museums have been affected by a cyber attack on the Gallery Systems software company, with those impacted having used the software to organise their online archives. Last month, Gallery Systems informed its clients that computers using its software had become encrypted and could no longer operate. They launched an investigation, enlisted ...

  • Lebanon: Beirut airport screens come under cyberattack

    January 8, 2024

    Beirut airport on Sunday came under a cyberattack, Lebanon’s state news agency said, with footage shared by local media showing anti-Hezbollah messages had replaced screen displays at its terminal. Lebanon’s National News Agency said “the cyberattack on the departure and arrival screens at the airport disrupted the BHS baggage inspection system.” It added that authorities were ...

  • Explained: SMTP smuggling

    January 7, 2024

    SMTP smuggling is a technique that allows an attacker to send an email from pretty much any address they like. The intended goal is email spoofing—sending emails with false sender addresses. Email spoofing allows criminals to make malicious emails more believable. Let’s take a closer look at what it is exactly, and how cybercriminals can use ...

  • Bangladesh: Cyber attack on Smart Election Commission app from two countries

    January 7, 2024

    A cyber attack has been carried out on the app ‘Smart Election Management BD’ of the Election Commission (EC) from Ukraine and Germany, said EC Secretary Md Jahangir Alam on Sunday. He told the media that the Election Commission (EC) had created a mobile application which was providing real-time voting information. However, voters were complaining since ...