HackerNews Digest Daily

Subscribe
Archives
June 12, 2023

Hacker News Top Stories with Summaries (June 12, 2023)

Hacker News Top Stories

Here are the top stories from Hacker News with summaries for June 12, 2023 :

Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures

https://www.usenix.org/conference/usenixsecurity23/presentation/rohlmann

Summary: Researchers from Ruhr University Bochum discovered major security flaws in Microsoft Office's Office Open XML (OOXML) Signatures, used for signing documents to guarantee authenticity and integrity. The team identified five new attack classes that allow attackers to modify signed content while signatures appear valid. All tested Office versions on Windows, macOS, and Linux were found vulnerable. Microsoft acknowledged the issue and awarded the researchers a bug bounty.

Want to read the full issue?
Powered by Buttondown, the easiest way to start and grow your newsletter.