Sound blaster katana speaker vulnerable to remote pc attacks

A researcher has shown that the Sound Blaster Katana V2X speaker from Creative Technologies can be used to infect a connected computer with malicious commands over Bluetooth. The attack requires no pairing and works even without physical access to the device.

Rasmus Moorats discovered the issue after buying the $283 speaker, which connects to computers via USB or Bluetooth. He found that an unauthenticated Bluetooth device could upload custom firmware to the speaker without code signing protections.

Moorats then modified the firmware to make the speaker emulate a keyboard. This allowed commands sent over Bluetooth to reach the connected PC, where they could open a terminal and run arbitrary code.

In a proof of concept, Moorats executed the command "echo pwned" on the target machine. He reported the findings to Creative Technologies, which said its engineers did not view the behavior as a vulnerability.

The attack is limited to devices within Bluetooth range, such as those belonging to neighbors or housemates. Bluetooth remains active on the speaker even during sleep mode.

Labaran da ke da alaƙa

A proof-of-concept exploit shows how websites can bypass safety guardrails in AI browsers by feeding them false information. The technique, called BioShocking, prompts the embedded AI models to accept incorrect facts such as 2 + 2 = 5, creating an alternate reality where restrictions no longer apply.

An Ruwaito ta hanyar AI

Hackers are misusing legitimate remote access tools to target business computers. The tools involved include UltraVNC, Splashtop, and ScreenConnect.

Security researchers have flagged a new risk to users of Microsoft's Phone Link application. An unidentified threat actor is using the tool to steal SMS messages and one-time passwords.

Wannan shafin yana amfani da cookies

Muna amfani da cookies don nazari don inganta shafin mu. Karanta manufar sirri mu don ƙarin bayani.
Ƙi