March 5, 2015 By Shane Schick 2 min read

In an age of streaming services such as Netflix and Hulu, it’s easy to forget many people watch Blu-ray Discs — and it’s even easier to overlook the technology as a potential target for malware.

At the recent Securi-Tay conference held in Scotland, a researcher from consultancy firm NCC Group presented evidence that attackers could use two vulnerabilities in common Blu-ray systems to inject malware and steal user data.

According to the firm’s blog, the NCC researcher demonstrated how a flaw in an application called PowerDVD could be breached and how an embedded system at the hardware level could potentially provide root access.

Consumers could be completely oblivious to these types of attacks, PCWorld pointed out, because those exploiting the vulnerabilities could create a Blu-ray disc that plays real content while it figures out which flaw offers the best attack vector. This is not unlike similar attempts to commit cybercrime via CDs and other forms of removable media.

Of course, Blu-ray software and hardware do come with some security safeguards, but in this case, the exploits would potentially let cybercriminals overcome Microsoft Windows’ auto-run prevention, according to TechWorm. There are other features to safeguard Blu-ray discs, but in some cases, such as PowerDVD, they may not have been updated for more than five years.

It should be pointed out that there is no sense that anyone has actually distributed malware via these Blu-ray system vulnerabilities and that what has been discovered was done through ethical hacking to educate security professionals. In fact, as SC Magazine suggested, many users of Blu-ray products may not realize the extent to which they are more digitally connected and, therefore, more open to attack.

The Register, however, noted that other ways to break into Blu-ray systems via digital rights management controls were revealed just a few months ago. Perhaps more people will pay greater attention to these types of holes. The only real prevention methods, of course, are much like those suggested for warding off cyberattacks via email: Don’t accept a Blu-ray disc that looks suspicious or comes from someone you don’t know. And, of course, you could always ditch the Blu-ray system and opt for streaming movies, instead.

More from

Apple Intelligence raises stakes in privacy and security

3 min read - Apple’s latest innovation, Apple Intelligence, is redefining what’s possible in consumer technology. Integrated into iOS 18.1, iPadOS 18.1 and macOS Sequoia 15.1, this milestone puts advanced artificial intelligence (AI) tools directly in the hands of millions. Beyond being a breakthrough for personal convenience, it represents an enormous economic opportunity. But the bold step into accessible AI comes with critical questions about security, privacy and the risks of real-time decision-making in users’ most private digital spaces. AI in every pocket Having…

Government cybersecurity in 2025: Former Principal Deputy National Cyber Director weighs in

4 min read - As 2024 comes to an end, it’s time to look ahead to the state of public cybersecurity in 2025.The good news is this: Cybersecurity will be an ongoing concern for the government regardless of the party in power, as many current cybersecurity initiatives are bipartisan. But what will government cybersecurity look like in 2025?Will the country be better off than they are today? What are the positive signs that could signal a good year for national cybersecurity? And what threats should…

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today