New SnailLoad side-channel attack detailed


SecurityWeek reports that website and content inferencing could be remotely conducted by threat actors without direct network traffic access via the new SnailLoad side-channel attack technique.

Several latency measurements for websites and YouTube videos viewed by targets are being conducted by threat actors to establish digital fingerprints before luring targets to download files from a malicious server. Such content is slowly loaded by the server to enable continued tracking of connection latency, with threat actors potentially using a convolutional neural network for content inferencing.

Read more…
Source: SC Media


Sign up for our Newsletter


Related:

  • DEV-0139 launches targeted attacks against the cryptocurrency industry

    December 6, 2022

    Over the past several years, the cryptocurrency market has considerably expanded, gaining the interest of investors and threat actors. Cryptocurrency itself has been used by cybercriminals for their operations, notably for ransom payment in ransomware attacks, but Microsoft researchers have also observed threat actors directly targeting organizations within the cryptocurrency industry for financial gain. Attacks ...

  • Industry 4.0: CNC Machine Security Risks – Part 3

    December 6, 2022

    In this final installation of Trend Micro three-part blog series, Trend Micro researchers lay out countermeasures that enterprises can do to protect their machines. They’ll also discuss their responsible disclosure as well as the feedback they got from the vendors they evaluated. Countermeasures Trend Micro found that only two of the four vendors analyzed support authentication. Neither ...

  • Amnesty International Canada intruder was in system for 17 months before detection

    December 6, 2022

    A suspected Chinese-based threat actor was in the IT system of Amnesty International Canada for 17 months before being detected, according to the head of the non-profit group. The Canadian branch of the human rights organization said in a news release Monday that the breach of security controls was detected in October. To its knowledge, this ...

  • Four suspects cuffed, face extradition to US over tax refund scam plot

    December 6, 2022

    Four men suspected of plotting to commit wire fraud and identity theft have been arrested and now face extradition to America. It is alleged they conspired to break into US companies’ servers, steal people’s personally identifiable information (PII), use that info to file fraudulent tax returns to Uncle Sam, and collect victims’ tax refunds. In newly unsealed ...

  • Russian VTB bank reports major DDoS attack on bank from overseas

    December 6, 2022

    VTB’s technical infrastructure is currently under a major cyberattack from abroad. The bank’s customers may face temporary problems when using the application and the web version of VTB online due to the measures in tackling the attack that are in progress, the press service of Russia’s second-biggest lender reported on Tuesday. “VTB’s technological infrastructure is currently ...

  • Ransomware hits city of Antwerp

    December 6, 2022

    Cybercriminals infected the city’s IT systems with ransomware. Residents are unable to make appointments for public affairs. Antwerp’s police and museums are partially offline. The attack took place on the night of December 5-6. A city spokesperson told De Standaard that ransomware was found on several systems. The identity of the attacker(s) is unknown at the ...