Weekly in Security 202248

2022-11-28 to 2022-12-05

2 min read - 261 words

Introduction

Weekly in Security is a summary of the cybersecurity news from the past week. This post covers 2022-11-28 to 2022-12-05.

Vulnerabilities

CVE-2022-4262 - Chrome Type Confusion in V8

Google Threat Analysis Group (TAG) seemed to have observed a Type Confusion in V8.

Interesting Reads

LastPass Breach

LastPass was breached again. The attackers gained acces using information obtained in the August 2022 incident. Cleaning up after an incident is a complicated task.

Medieval Secret Message decrypted

An ecrypted letter by Charles V, Emperor of the Holy Roman Empire has finally been decrypted after almost 500 Years by a team around cryptographer Cecile Pierrot. The letter revealed, that the emperor lived in fear of an assassination attempt by an Italian mercenary.

Under the reign of Chalres V the Habsburg Empire included the Holy Roman Empire, the Spanish Empire, Austria and many more territories. Historically the House of Habsburg is quite interessting.

Black Hat USA 2022 Recordings

Black Hat USA 2022 recordings are online. There are lot of cool talks to watch.

TeamViewer font for Fraud Detection

A recent post on reddit provided some details of current fraud protection capabilities of banks. In this case Barcely used a font installed by TeamViewer to flag a transaction.

TeamView is using this font when starting a session via their website . Javascript will try to detect the font, which would indicate whether TeamViewer is installed. More background information is available here and here. TeamViewer also provided some details

The TeamViewer font is used to implement a smooth user experience from web to the native client