4 ms·
Unfortunately, I am suspicious based on some recent circumstances that this bug is being exploited in the wild. If you do run Windows, be sure to check that yo
by rbastic2 3y ago
Unfortunately, I am suspicious based on some recent circumstances that this bug is being exploited in the wild.
If you do run Windows, be sure to check that your TPM/SecureBoot devices are enabled, and that Core Isolation/Code Integrity (for example, Hypervisor Enforced Code Integrity) is enabled if possible. Unfortunately, this setting can sometimes cause driver incompatibilities and enabling it via the registry manually may be experimental/crashprone.
https://learn.microsoft.com/en-us/windows/security/threat-protection/device-guard/enable-virtualization-based-protection-of-code-integrity https://learn.microsoft.com/en-us/windows/security/threat-pr...
Network-based IDS helps a lot in this area -- something like pfSense with pfblocker-ng + Suricata. Unfortunately, there is also malware that can masquerade protocol/etc: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
- ericpauley 3y agoI think people are overly quick to dismiss the effectiveness of IDS. Yes, rules often match symptoms/exploit instances rather than actual vulnerability semantics (though this has improved. But like a bike lock, even imperfect IDS gives you protection against opportunistic attacks that are pervasive for any system connected to the Internet. The fact that IDS can respond without needing to validate a new software release means it can also very often outpace remediation through software updates.