🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🪟 Windows TippsHeader and Footer not showing in Excel(14.09.2026 um 22:43 Uhr)
🕵️ SicherheitslückenBurn Out, Or Fade Away(14.09.2026 um 14:25 Uhr)
🪟 Windows TippsKB5129194 Windows 11 26H1 Out of Band Update - Deskmodder.de(14.09.2026 um 19:25 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🪟 Windows TippsHeader and Footer not showing in Excel(14.09.2026 um 22:43 Uhr)
🕵️ SicherheitslückenBurn Out, Or Fade Away(14.09.2026 um 14:25 Uhr)
🪟 Windows TippsKB5129194 Windows 11 26H1 Out of Band Update - Deskmodder.de(14.09.2026 um 19:25 Uhr)

🎥 IT Security Video 🕛 vor 5 Tagen 2 Min Lesezeit SECURITY-FEED
0

USENIX: WOOT '26 - CATana: On the Dangers of SIM-Originating AT Commands

↗ Quelle (YouTube · USENIX)
🗣️ Stimme:
📺
YouTube · USENIX
193 YouTube-Aufrufe
CATana: On the Dangers of SIM-Originating AT Commands

Tomasz Piotr Lisowski, University of Birmingham; Kristian Covic, Fuzzware; Marius Muench, University of Birmingham

Hostile SIMs have been discussed as an attack vector against Mobile Equipment (ME) connected to cellular networks. One main attack path are proactive commands sent from the SIM to the victim device. In this work, we examine the threats posed by the RUN AT command which are SIM-originating requests for the ME to execute a specified AT command, effectively creating a SIM AT interface.
To explore this interface, we introduce the CATana toolkit and use it to analyze real-world devices. Despite existing community knowledge on proactive commands and the dangers of AT commands, our investigation shows that SIM AT commands pose a significant security risk for MEs.
We survey 26 different MEs (8 IoT devices and 18 smartphones) and find that 9 expose the SIM AT interface, leading to the discovery of 4 vulnerabilities. We present case studies demonstrating the impact of discovered vulnerabilities, including command execution, arbitrary file read, downgrading connections to 2G, and Denial-of-Service (DoS) of the ME. Crucially, our work emphasizes the security benefit of hardening, deprecating, or disabling, the SIM AT interface.

View the full WOOT '26 program at https://www.usenix.org/conference/woot26/technical-sessions
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
Header and Footer not showing in Excel
1 Quelle
Burn Out, Or Fade Away