06Jun

Tens of thousands – perhaps hundreds of thousands — of Windows 10 users are vulnerable to a “wormable bug” so serious it has been given the highest score possible of the Common Vulnerability Scoring System.

Although Microsoft issued a fix for the bug in March, Homeland Security’s Cybersecurity and Infrastructure Security Agency issued an alert warning of the potential risk to systems that have not installed the fix.

Commonly referred to as SMBGhost, the vulnerability in Windows 10 systems was recently shown to be exploitable. That could give hackers complete access to the computer and, because the vulnerability is considered “wormable,” the exploit code can spread throughout a network, infecting all connected Windows 10 systems.

By default, Windows 10 automatically checks and installs updates. Home and small business users should already have the patch installed. You can check by following the directions from Microsoft.

However, estimates of the unprotected PCs range from the tens of thousands into the hundreds of thousands. For these systems, the risk of being successfully attacked and having the exploit spread is what prompted the Homeland Security warning. The agency warned that “Malicious cyber actors are targeting unpatched systems.”

In 2017, a wormable bug lead to the WannaCry ransomware spread, which disrupted businesses, government and transportation, and in the UK forced hospitals to halt activities and even turn patients away. Microsoft had issued a patch for the hacking tools that had been developed and stolen from the National Security Agency, but millions did not install it, leading to the disruption and damages worldwide estimated in the billions.

Photo by Caspar Camille Rubin on Unsplash

[bdp_post_carousel]

World’s Most Popular Software Hacked in 5 Minutes

Here’s news guaranteed to keep a CTO up at night: Chinese hackers successfully launched new exploits against some of the most widely used programs in the world.

And it took them 5 minutes or less to do it.

Fortunately, the successful hackers were part of the 15 teams competing in this year’s Tianfu Cup — China’s largest and most prestigious hacking competition. Using new, never before seen exploits, they were able to successfully hack the web browsers Chrome, Firefox and Safari.

They were also successful against Windows 10, Ubuntu, iOS 14 running on an iPhone 11 Pro, Docker (Community Edition), VMWare EXSi (hypervisor), QEMU (emulator & virtualizer), TP-Link and ASUS router firmware. And Adobe Reader.

Each team got three, 5 minute tries to successfully hack their target with an original exploit.

“Many mature and hard targets have been pwned (compromised) on this year’s contest,” organizers said last week, announcing the results of the competition. The winning team from Chinese tech giant Qihoo 360 earned $744,500, with the balance of the $1.21 million prize spread among 7 other teams.

The software providers were informed of the exploits. ZDNet says patches for all the bugs will be provided in the coming days and weeks, “as it usually happens after every TianfuCup and Pwn2Own (the west’s version).”

Pointing out that teams were able to hack so many widely used programs and applications, Tech Times commented, “The Chinese hacking competition shows powerful and new hacking systems that are never before seen by the technology security industry. The talented computer youngsters showcased how easily and rapidly they hacked into the world’s popular operating systems.”

Photo by Setyaki Irham on Unsplash

[bdp_post_carousel]

Origami-Inspired Robot Shows It Can Do Delicate Surgery

A tiny robot, inspired by the paper-folding art of origami, may someday take on surgical tasks as delicate as pushing through a human eye to reach the hair-sized veins inside.

Two engineers recently demonstrated how a device weighing as much as a penny and no larger than a tennis ball can perform such delicate procedures with far more precision than a human. They described their work in the August issue of Nature Machine Intelligence.

The device was able to outperform a human in a test that involved tracing a square smaller than the tip of a ballpoint pen. The so-named miniature remote center of motion manipulator or mini-RCM, was 68% more accurate than a tool controlled by hand.

In a second test, the device successfully punctured a mock vein twice the size of a human hair, simulating a procedure that involves puncturing an eye to reach the blood vessels at the rear in order to inject a medication. Such surgeries have been done on an experimental basis with other robots, but are considered too risky to be performed exclusively by hand.

An article on Harvard’s Wyss Institute for Biologically Inspired Engineering describes how Robert Wood, an engineering professor at Harvard, and Hiroyuki Suzuki, a robotics engineer at Sony Corporation, built the robot.

For years, miniaturized tools and cameras have enabled doctors to perform minimally invasive surgeries. Now, large robots are assisting surgeons by handling multiple tools with great precision. The downside is the size of these robots and their tools, and the cost. There’s also research suggesting that for many types of procedures these robots – costing $2 million and more – get no better results than traditional laparoscopic surgery.

Te mini-RCM, although still just a prototype, holds promise for reducing the size and cost of medical robots and has potential utility as a precise tool for teleoperated microsurgery.

“The Wood lab’s unique technical capabilities for making micro-robots have led to a number of impressive inventions over the last few years,” says Suzuki . ”I was convinced that it also had the potential to make a breakthrough in the field of medical manipulators as well.”

“This project has been a great success.”

Photo by Ben Wicks on Unsplash

[bdp_post_carousel]