The article highlights a novel hardware supply chain threat called HAMLOCK, a backdoor attack targeting deep learning systems on edge devices that splits malicious functionality between hardware (FPGAs/ASICs) and software to evade detection. It also notes separate, active exploitation incidents involving the theft of 74,000 Fortinet firewall credentials and a remote code execution vulnerability in Splunk Enterprise, but the summary lacks the specific technical details, CVSS scores, version ranges, patches, or workarounds required for a complete technical advisory on those events.
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring … More → The post Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack appeared first on Help Net Security .