ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Researchers at USENIX Security 2024 presented Einstein, a tool that automatically generates data-only attacks, which corrupt program data without hijacking control flow. Such attacks were long considered too complex for practical use. Einstein targets syscall arguments, letting attackers execute arbitrary programs. The team urges vendors to rethink mitigation strategies, as about 70% of Microsoft, Google and Mozilla security bugs are memory safety flaws.
Tap to vote and see what everyone thinks.
Summary by ByteBrief