# disclosure

Published articles for disclosure.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Attacking UNIX Systems via CUPS, Part I

DevFeed: [Attacking UNIX Systems via CUPS, Part I](<https://devfeed.tech/articles/attacking-unix-systems-via-cups-part-i-41270.md>)

Original publisher: [Read original article](<https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/>)

Author: Simone Margaritelli

Published: 2024-09-26T14:51:30Z

Content type: article

Language: en

Sources: [evilsocket](<https://devfeed.tech/sources/evilsocket.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [gnu linux](<https://devfeed.tech/topics/gnu-linux.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [cups](<https://devfeed.tech/tags/cups.md>), [cups-browsed](<https://devfeed.tech/tags/cups-browsed.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2024-47076](<https://devfeed.tech/tags/cve-2024-47076.md>), [cve-2024-47175](<https://devfeed.tech/tags/cve-2024-47175.md>), [cve-2024-47176](<https://devfeed.tech/tags/cve-2024-47176.md>), [cve-2024-47177](<https://devfeed.tech/tags/cve-2024-47177.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [gnu-linux](<https://devfeed.tech/tags/gnu-linux.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [ipp](<https://devfeed.tech/tags/ipp.md>), [lan](<https://devfeed.tech/tags/lan.md>), [linux-security](<https://devfeed.tech/tags/linux-security.md>), [mdns](<https://devfeed.tech/tags/mdns.md>), [no-authentication](<https://devfeed.tech/tags/no-authentication.md>), [port](<https://devfeed.tech/tags/port.md>), [print-services](<https://devfeed.tech/tags/print-services.md>), [printer](<https://devfeed.tech/tags/printer.md>), [printers](<https://devfeed.tech/tags/printers.md>), [printing](<https://devfeed.tech/tags/printing.md>), [rce](<https://devfeed.tech/tags/rce.md>), [responsible-disclosure](<https://devfeed.tech/tags/responsible-disclosure.md>), [security](<https://devfeed.tech/tags/security.md>), [udp](<https://devfeed.tech/tags/udp.md>), [unauthenticated-access](<https://devfeed.tech/tags/unauthenticated-access.md>), [unix](<https://devfeed.tech/tags/unix.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>), [zeroconf](<https://devfeed.tech/tags/zeroconf.md>)

### AI overview

A security writeup describes multiple vulnerabilities in CUPS components affecting GNU/Linux and other UNIX systems. It reports that remote unauthenticated attackers may replace printer IPP URLs and trigger arbitrary command execution when a print job starts, with attacks possible over the public internet or via spoofed LAN advertisements.

### Source excerpt

Hello friends, this is the first of two, possibly three (if and when I have time to finish the Windows research) writeups. We will start

## The Uber CSO indictment

DevFeed: [The Uber CSO indictment](<https://devfeed.tech/articles/the-uber-cso-indictment-37012.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-uber-cso-indictment/>)

Author: Adam

Published: 2020-08-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>), [ftc](<https://devfeed.tech/tags/ftc.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [law](<https://devfeed.tech/tags/law.md>)

### AI overview

An analysis of the Uber CSO indictment and Mark Rasch's essay on concealing and failing to report a data breach. The article emphasizes due process for Joe Sullivan and argues that the case may make organizations and lawyers more cautious about breach disclosures, potentially reducing their usefulness for learning from mistakes.

### Source excerpt

Thoughts on Mark Rasch's essay, Conceal and Fail to Report - The Uber CSO Indictment

## Medical Device Security Standards

DevFeed: [Medical Device Security Standards](<https://devfeed.tech/articles/medical-device-security-standards-36882.md>)

Original publisher: [Read original article](<https://shostack.org/blog/medical-device-security-standards/>)

Author: Adam

Published: 2019-11-02T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [standard](<https://devfeed.tech/topics/standard.md>)

Tags: [checksums](<https://devfeed.tech/tags/checksums.md>), [connectivity](<https://devfeed.tech/tags/connectivity.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [digital-signature](<https://devfeed.tech/tags/digital-signature.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>), [funding](<https://devfeed.tech/tags/funding.md>), [medical-devices](<https://devfeed.tech/tags/medical-devices.md>), [network](<https://devfeed.tech/tags/network.md>), [pii](<https://devfeed.tech/tags/pii.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

This commentary compares four cybersecurity approaches for medical devices: a comprehensive process-centered framework, MITA's factual material data sheet, disclosure of device behavior and cybersecurity properties, and funded threat-modeling work. It notes that differing national requirements can increase costs and create conflicting demands.

### Source excerpt

Recently, I've seen four cybersecurity approaches for medical devices, and we can learn by juxtaposing them.

## SEC Fines Yahoo $35 Million Over Disclosure of Russian Hacking

DevFeed: [SEC Fines Yahoo $35 Million Over Disclosure of Russian Hacking](<https://devfeed.tech/articles/35m-for-covering-up-a-breach-36648.md>)

Original publisher: [Read original article](<https://shostack.org/blog/35m-for-covering-up-a-breach/>)

Author: Adam

Published: 2018-04-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [company](<https://devfeed.tech/tags/company.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>)

### AI overview

The article discusses the SEC's $35 million fine against Yahoo for failing to disclose a Russian hacking incident to investors. It highlights the SEC's view that the company's response warranted enforcement action.

### Source excerpt

[no description provided]

## Speculative Execution Threat Model

DevFeed: [Speculative Execution Threat Model](<https://devfeed.tech/articles/speculative-execution-threat-model-36981.md>)

Original publisher: [Read original article](<https://shostack.org/blog/speculative-execution-threat-model/>)

Author: Adam

Published: 2018-03-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [execution](<https://devfeed.tech/topics/execution.md>), [side channel](<https://devfeed.tech/topics/side-channel.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [context](<https://devfeed.tech/topics/context.md>)

Tags: [context](<https://devfeed.tech/tags/context.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>), [execution](<https://devfeed.tech/tags/execution.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [prevent](<https://devfeed.tech/tags/prevent.md>), [side-channel](<https://devfeed.tech/tags/side-channel.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A commentary on Matt Miller's threat model for speculative execution side-channel hardware vulnerabilities. It describes primitives such as conditional and indirect branch misprediction and exception delivery or deferral, along with disclosure gadgets and mitigation models.

### Source excerpt

[no description provided]