Best website builder of 2020: Wix, Squarespace, Hostgator, Weebly and more tested, rated
The best website builder options don't have to be complicated or expensive - check out our guide.
Read MoreCybersecurity researchers have shared details about eight vulnerabilities in the Bluetooth Low Energy (BLE) software stack of the open source real-time Zephyr OS.
Developed under the aegis of the Linux Foundation, Zephyr started at Wind River before it was acquired by Intel and eventually open sourced. The OS supports over 200 boards and counts the likes of Intel, Linaro, Texas Instruments, Nordic Semiconductor, Bose, Facebook, Google, and others as members, many of whom have devices that run Zephyr.
Security vendor Synopsys, who discovered the vulnerabilities, divides the flaws into three high-level categories. Some of the vulnerabilities can lead to remote code execution, while others could be exploited to grab confidential information like encryption keys.
“All the reported vulnerabilities can be triggered from within the range of Bluetooth LE. Triggering the vulnerability does not require authentication or encryption,” writes Synopsys in its advisory.
Synopsys notes that the only requirement for the exploitation of the vulnerabilities is for a Zephyr-powered device to be in advertising mode and accepting connections.
Speaking to The Register, Matias Karhumaa, senior software engineer at the Synopsys Cybersecurity Research Centre, shared that bluetooth devices like smartwatches, fitness trackers, and medical devices like continuous glucose monitoring sensors operate in the advertising mode to facilitate external devices to connect to them.
Just last month, researchers at the French National Agency for the Security of Information Systems (ANSSI) identified a number of vulnerabilities in two critical Bluetooth services that could’ve been exploited to allow attackers to hijack a pairing request in order to conduct Man-in-the-Middle (MitM) attacks.
When questioned about the exploitability of the Zephyr Bluetooth vulnerabilities, Karhumaa shared that he believes businesses shouldn’t spend time trying to figure out whether a vulnerability is exploitable in the real-world, and rather work “to make it easy to identify, reproduce, and resolve the bugs regardless of their exploitability."
According to Synopsys’ advisory, the vulnerabilities were shared with Zephyr back in March 2021, who started fixing them immediately, culminating with the Zephyr 2.6.0 release earlier in June with patches for all the reported vulnerabilities.
The best website builder options don't have to be complicated or expensive - check out our guide.
Read MoreLooking for a great value Apple slate? The new 2021 Apple iPad 10.2 has just had a $30 price cut at Amazon - its biggest yet.
Read MoreFlipkart has made a strategic investment in USPL, a premium youth-focused fashion brand house, as it strengthens its fashion portfolio.
Read MoreWork is underway on a new version of Parallels Desktop that will bring Windows 11 to Mac devices.
Read MoreWant to hire best people for your project? Look no further you came to the right place!