Ever seen printer malware in motion? Set up this HP Ink patch – or chances are you'll discover out • The Register
von Satoshi Nakamoto

HP Inc has posted an replace to deal with a pair of great safety vulnerabilities in its InkJet printers.
The firmware replace patches CVE-2018-5924 and CVE-2018-5925, two flaws that may be exploited by printing a file that triggers a stack or static buffer overflow, supplying you with the flexibility to then execute malicious code on the focused printer. Discovery of the bugs was credited to HP's in-house Product Safety Response Crew.
In complete, HP says the patch will have to be utilized to some 225 totally different fashions of inkjet printers throughout its Pagewide, DesignJet, OfficeJet, Deskjet, and HP Envy product traces.
Count on to see extra of this going ahead. HP Inc not too long ago opened up a bug bounty program to carry extra researchers into the fold and discover printer bugs earlier than they'll flip into zero-day exploits.
That bug bounty program, introduced earlier this week in partnership with Bugcrowd, will see the printers n' PCs facet of the Hewlett Packard break-up provide researchers as much as $10,000 apiece for reporting safety vulnerabilities.

Need to spy on the boss? Do this phone-mast-in-an-HP printer
READ MORE
The intention, says HP print safety chief technologist Shivaun Albright, is to maintain HP printers shielded from the rising crop of botnets and malware packages that concentrate on printers and different internet-facing gadget which have historically had little to no safety safety in place.
"As we navigate an more and more complicated world of cyber threats, it’s paramount that trade leaders leverage each useful resource doable to ship trusted, resilient safety from the firmware up," Albright stated.
"HP is dedicated to engineering essentially the most safe printers on the earth."
The bug bounty program additionally offers HP one other level for an ongoing advertising and marketing push the seller is making to enterprise prospects across the safety of its printer line.
HP stated that not solely will it's handing out bounty funds for beforehand unknown bugs, but in addition "good religion" payouts to researchers who report bugs that HP itself had already found, however not gotten round to patching and disclosing but. ®
Sponsored:
Following Bottomline’s journey to the Hybrid Cloud
Source link
Read the full article
Satoshi Nakamoto
Keine Verbindung
Verbindung wird wiederhergestellt
Etwas ist schiefgelaufen
Wir sind gleich wieder da