North Korean Hackers Posed as Recruiters.They Infected 30k Devices Worldwide
North Korean hackers used fake recruiter profiles to target individuals worldwide. They infected approximately 30,000 devices through this deception. (inc.com)
A security analysis presents DeCENC, a generic exploit against the MPEG-CENC encrypted media container that demonstrates a fundamental design flaw: use of encryption without authentication. DeCENC enables decryption of encrypted video streams without direct knowledge of the content key by manipulating codec-level features in widely used codecs (h264/AVC and h265/HEVC). The work explains how common DRM architectures and Content Decryption Modules (CDMs) fit together, catalogs practical attack vectors (analog capture, HDMI interception, exfiltrating decrypted-but-undecompressed frames, stealing content keys or CDM secrets), and supplies a proof-of-concept implementation with testing guidance for ClearKey on GitHub. Explanations are self-contained because relevant MPEG specifications are paywalled.
Technically, the exploit constructs specially crafted video bitstreams that abuse features such as I_PCM macroblocks, NAL emulation-prevention bytes, chroma subsampling and limited-range color to induce predictable plaintext from AES-CTR-encrypted data, then substitutes or forges video stream units and metadata to coax decoders into revealing decrypted content. The write-up details AES-CTR background, bitstream crafting, metadata preparation, stream substitution, capability limits and practical mitigations, and concludes with reflections on why a specification-level omission of authentication makes encrypted containers inherently brittle in real-world DRM deployments.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
North Korean hackers used fake recruiter profiles to target individuals worldwide. They infected approximately 30,000 devices through this deception. (inc.com)
Google AI Studio's data deletion practices are questioned due to a CWE-459 vulnerability and evidence of data retention, according to AI Weekly. Industry experts express concerns over backend data hoarding and UI misrepresentation. (bitu79.substack.com)
Flock partnered with a nonprofit accused of using AI to create fake grassroots support for its surveillance cameras. Critics argue the campaign manipulates public opinion and raises privacy concerns. (theintercept.com)
Sports betting apps like FanDuel and DraftKings are being sued for being designed to create addiction, similar to the effects of crack cocaine in the 1980s. Attorneys argue that these apps cause financial and personal devastation for users, with some losing their homes and families. (cbsnews.com)
The Snowden Archive is a collection of documents and information leaked by NSA whistleblower Edward Snowden. Its current status and accessibility have become topics of discussion and concern. (libroot.org)
OpenAI's CEO Sam Altman is scheduled to brief the UN Security Council next week. The meeting will focus on AI-related topics and global security concerns. (reuters.com)
Today's best Hacker News stories, summarized and screenshotted, one email a day.