惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
博客园 - 【当耐特】
博客园_首页
The GitHub Blog
The GitHub Blog
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
博客园 - 三生石上(FineUI控件)
D
Docker
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
酷 壳 – CoolShell
酷 壳 – CoolShell
雷峰网
雷峰网
小众软件
小众软件
I
InfoQ
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
S
SegmentFault 最新的问题
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky

Security Affairs

Digital attacks drive a new wave of cargo theft, FBI says Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
NCSC launches SilentGlass, a plug-in device to secure HDM...
Pierluigi Pa · 2026-04-28 · via Security Affairs

NCSC’s SilentGlass blocks malicious HDMI/DisplayPort links, protecting monitors from hardware attacks. Now commercialized for global use.

The UK’s National Cyber Security Centre (NCSC) has launched SilentGlass, a new device to protect one of the most overlooked parts of modern IT systems: the physical links between screens and computers. It is a small plug-in security device designed to monitor and block suspicious activity on HDMI and DisplayPort connections.

Developed through research led by the NCSC and now licensed for production to Goldilock Labs in partnership with Sony UK Technology Centre, SilentGlass represents a shift in how hardware interfaces are treated in cybersecurity. Instead of focusing only on software threats, it addresses risks that arise when physical connections themselves are exploited.

“First commercially available product licensed to use NCSC branding granted to Goldilock Labs in manufacturing partnership with Sony UK Technology Centre.” reads the announcement. “UK government and businesses to be protected at scale by the affordable plug-in cyber security device”

The device works in a simple but powerful way. It sits between a computer and a display and inspects everything passing through the connection. If anything unexpected, unauthorized, or potentially malicious is detected, it immediately blocks the transmission. This prevents attackers from using display channels as an entry point or surveillance path.

According to the NCSC, monitors and screens are increasingly attractive targets for attackers because they often display sensitive information and are widely deployed across organizations. In some cases, they can even be used as an indirect pathway into larger systems, especially in environments where physical access or supply chain exposure is possible. As more advanced adapters and intermediary devices have been introduced over time, the attack surface has grown without many organizations realizing it.

SilentGlass was created to close this gap. It is designed as a plug-and-play solution that does not require complex configuration, making it suitable for large-scale deployment in both government and private-sector environments. It is also intended to be affordable, allowing wider adoption beyond highly specialized security operations.

“Display screens and monitors are everywhere in modern business environments, and the SilentGlass device will help protect previously vulnerable IT infrastructure with unprecedented ease.

Its development and commercialisation shows the impact that the NCSC can have, alongside industry partners, with an affordable and effective product now globally available.” said Ollie Whitehouse, NCSC Chief Technology Officer.

“By helping to launch a UK company onto the global market with this world-class innovation, we are breaking new ground and helping to strengthen national prosperity.

The technology has already been tested in high-security government settings and is now being introduced to the broader market at CYBERUK, the UK government’s main cybersecurity conference. Its commercial release marks a significant step in bringing national-security-grade innovation into everyday business environments.

From the industry side, Goldilock Labs highlights that hardware interfaces have historically been treated as trusted components rather than security boundaries. However, these interfaces can be exposed to risks from supply chains, third-party maintenance, or direct physical manipulation. SilentGlass reframes this assumption by enforcing security checks directly at the point of connection.

The device is also part of a broader shift in cybersecurity thinking: instead of reacting to software vulnerabilities alone, it introduces control mechanisms at the hardware level before data even enters a system. This proactive approach aims to reduce entire categories of attacks that have traditionally been difficult to detect or mitigate.

By combining government-led research with commercial manufacturing and global distribution, SilentGlass is positioned as a practical example of how public-sector innovation can be transformed into widely deployable security solutions. It reflects a growing recognition that cybersecurity must extend beyond networks and applications to include the physical pathways that connect them.

With its global release, SilentGlass is expected to be adopted by governments, critical infrastructure operators, and security-conscious organizations seeking stronger protection against increasingly sophisticated physical and hardware-based threats.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, NCSC)