TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Procolored printer drivers contained malware

142 点作者 bundie5 天前

8 条评论

canvascritic3 天前
SnipVex clipjacking wallets is almost beside the point, the real failure is a printer vendor treating software like a side gig. Printer and hardware companies get a pass on basic infosec hygiene that would be unacceptable for open source maintainers.<p>until that changes, airgap your weird hardware setups I guess<p>Also this is a perfect storm for lateral movement. USB-borne worms still work frighteningly well in small biz environments, especially ones with no centralized IT and people plugging printers directly into Windows desktops with admin perms. Here SnipVex is just a cherry on top-a nice, opportunistic payload for the growing class of infostealers targeting crypto wallets
评论 #44027799 未加载
评论 #44027837 未加载
评论 #44028082 未加载
shakna3 天前
&gt; While some redditors speculate that the trojan was planted on purpose, there is no evidence to support this claim. Outdated malware with an inactive command-and-control server is not advantageous for any attacker nor does superinfection make sense for this scenario. A far more plausible explanation points to the absence or failure of antivirus scanning on the systems used to compile and distribute the software packages. Procolored promises to improve this process, so that it cannot happen again.<p>That this system is so insecure as to be hit multiple times, I don&#x27;t know how much stock anyone should put in &quot;improved processes&quot;. This is a company who seems to have gone out of their way to create an insecure environment - probably out of some frustration, but all the same, insecure.
评论 #44030112 未加载
评论 #44032722 未加载
razakel3 天前
Hosting drivers on mega.co.nz.<p>Totally fills you with confidence.
评论 #44027759 未加载
评论 #44027822 未加载
评论 #44027774 未加载
评论 #44032732 未加载
评论 #44027871 未加载
HPsquared3 天前
What is it with printers and (pardon the pun) shady practices?
评论 #44027807 未加载
评论 #44027391 未加载
rvnx3 天前
If Bitcoin wallets would be designed properly they would ask for a second confirmation before sending 100k USD.<p>This may be the main thing to fix here, as it&#x27;s very plausible that hacks happen again and again... by design.<p>Today it&#x27;s an infected printer, tomorrow it will be a game on Steam.
评论 #44027915 未加载
评论 #44027702 未加载
评论 #44027598 未加载
评论 #44027770 未加载
评论 #44027698 未加载
评论 #44030483 未加载
评论 #44027788 未加载
M95D3 天前
Somehow, I was expecting to be about HP.
whimsicalism3 天前
crazy to me that people are still writing malware in delphi
elmt353 天前
The printer company in question is: Procolored
评论 #44027810 未加载
评论 #44027668 未加载