Prime Day

Como cliente Amazon Prime obtén 3 meses de Audible gratis

Diseño de la portada del título NSA Tips

NSA Tips

Blacklotus Mitigation Guide

Muestra

Escúchalo ahora gratis con tu suscripción a Audible

Prueba gratis durante 30 días
Después de los 30 días, 9,99 €/mes. Cancela tu siguiente plan mensual cuando quieras.
Disfruta de forma ilimitada de este título y de una colección con 90.000 más.
Escucha cuando y donde quieras, incluso sin conexión.
Sin compromiso. Cancela tu siguiente plan mensual cuando quieras.

NSA Tips

De: National Security Agency
Narrado por: Tom Brooks
Prueba gratis durante 30 días

Después de los 30 días, 9,99 €/mes. Cancela cuando quieras.

Compra ahora por 5,96 €

Compra ahora por 5,96 €

BlackLotus is a recently publicized malware product garnering significant attention within tech media. Similar to 2020’s BootHole (CVE-2020-10713), BlackLotus takes advantage of a boot loader flaw—specifically CVE-2022-21894 Secure Boot bypass known as “Baton Drop”—to take control of an endpoint from the earliest phase of software boot. Microsoft® issued patches for supported versions of Windows to correct boot loader logic. However, patches were not issued to revoke trust in unpatched boot loaders via the Secure Boot Deny List Database (DBX). Administrators should not consider the threat fully remediated as boot loaders vulnerable to Baton Drop are still trusted by Secure Boot. As described in this Cybersecurity Information Sheet (CSI), NSA recommends infrastructure owners take action by hardening user executable policies and monitoring the integrity of the boot partition. An optional advanced mitigation is to customize Secure Boot policy by adding DBX records to Windows® endpoints or removing the Windows Production CA certificate from Linux® endpoints.

PLEASE NOTE: When you purchase this title, the accompanying PDF will be available in your Audible Library along with the audio.

©2023 Tom Brooks (P)2023 Tom Brooks
adbl_web_anon_alc_button_suppression_t1
No hay reseñas aún