ZeroHour

Search: “exfiltration”

2 stories in the last 24h

Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs

Researchers demonstrate exfiltration through nominally input-only analog pins in mixed-signal ICs, recovering data at 10 kbps on a 55nm PPG front-end.

The paper identifies a directionality-based attack class in analog/mixed-signal (AMS) ICs where data-dependent circuit-offset modulation converts a nominally input-only pin into an outbound information channel. Three host conditions enable the attack: a closed-loop amplifier, an exposed amplifier input, and sufficiently high impedance at that pin. Silicon validation on a photoplethysmography analog front-end in 55nm CMOS showed exfiltration at up to 10 kbps with error-free PRBS recovery, under 0.001% area overhead, and only 0.03 dB SNR reduction.

arXiv cs.CR · 15h agoResearch

CISA promotes a fresh way to deter cyberattackers: Lie to them

CISA issued first-time guidance advising critical infrastructure operators to deploy honeypots, honeytokens, and decoys to detect and distract intruders.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response,' a 22-page guide marking the agency's first guidance on decoys such as honeypots and honeytokens. Acting executive director Chris Butera described decoys as a low-cost, high-fidelity way to detect adversaries already inside networks, complementing zero-trust and assume-compromise approaches. The guidance covers decoy principles, definitions, deployment scenarios, and is aimed especially at resource-constrained critical infrastructure sectors.

CyberScoop · 13h agoAdvisory