US lawmakers wave red flags over Chinese drone dominance

June 27, 2024 at 09:49AM US Congress members raise concerns about Chinese dominance in the drone industry, comparing it to the threats posed by semiconductors and ships. They highlighted China’s strategy to dominate through subsidies and predatory pricing and advocated for sanctions and market access barriers. The hearing also discussed the potential national security risks … Read more

Ransomware Group Claims Theft of Data From Chipmaker Nexperia 

April 15, 2024 at 11:06AM Netherlands-based chipmaker Nexperia, a subsidiary of Wingtech Technology, was targeted by ransomware group Dark Angels, who claimed to have stolen 1 Tb of data, including sensitive information of major companies. Nexperia confirmed the breach and initiated an investigation while disconnecting affected systems and notifying authorities. The ransomware group is also … Read more

North Korea hacks two South Korean chip firms to steal engineering data

March 4, 2024 at 09:47AM The National Intelligence Service (NIS) of South Korea has warned of increased cyber espionage attacks by North Korean hackers targeting domestic semiconductor manufacturers. The attacks exploit known vulnerabilities in internet-exposed servers to steal sensitive data. South Korean chipmakers, including Samsung Electronics and SK Hynix, are crucial in the global semiconductor … Read more

MITRE Rolls Out 4 Brand-New CWEs for Microprocessor Security Bugs

February 29, 2024 at 02:28PM The MITRE-led CWE program added four new microprocessor-related weaknesses, including exposure of sensitive information during transient execution and data leaks tied to microarchitectural structures and incorrect data forwarding. These vulnerabilities help processors address major issues like Meltdown and Spectre and contribute to a common language for discussing microprocessor weaknesses in … Read more

CISA HBOM Framework Doesn’t Go Far Enough

February 15, 2024 at 04:12PM CISA’s hardware bill of materials (HBOM) framework aims to address semiconductor chip security but is deemed insufficient. While it supports supply chain management and risk assessment, it lacks life cycle tracking and fails to address vulnerabilities like Downfall. Despite early shortcomings, CISA’s initiative is a step towards bolstering chip security … Read more