Security News

AMD Unveils New Security Features With Launch of EPYC 7003 Series Processors
2021-03-15 15:18

Chipmaker AMD on Monday announced the launch of its new EPYC 7003 series server processors - codenamed Milan - and the company has shared some information about new and improved security features. The new CPUs are based on the Zen 3 architecture and AMD says they bring significantly improved performance for enterprise, cloud and HPC workloads.

Microsoft brings its on-die Pluton security processor to Intel, AMD CPUs
2020-11-17 09:00

Microsoft is integrating its Pluton security processor directly into Intel, AMD, and Qualcomm CPUs to better secure Windows PCs. Windows 10 gains enhanced security by utilizing specialized chips called Trusted Platform Modules to provide hardware-based security functions. Microsoft is now partnering with Intel, AMD, and Qualcomm to introduce the Pluton security processor as an on-die chip in their CPUs.

Intel, ARM, IBM, AMD Processors Vulnerable to New Side-Channel Attacks
2020-08-06 22:34

Sharing its findings with The Hacker News, a group of academics from the Graz University of Technology and CISPA Helmholtz Center for Information Security finally revealed the exact reason behind why the kernel addresses are cached in the first place, as well as presented several new attacks that exploit the previously unidentified underlying issue, allowing attackers to sniff out sensitive data. The new research explains microarchitectural attacks were actually caused by speculative dereferencing of user-space registers in the kernel, which not just impacts the most recent Intel CPUs with the latest hardware mitigations, but also several modern processors from ARM, IBM, and AMD - previously believed to be unaffected.

Google Cloud Unveils Confidential VMs Powered by AMD EPYC Processors
2020-07-14 12:17

Google on Tuesday unveiled the first product in its Google Cloud Confidential Computing portfolio: Confidential VMs. Currently in beta for Google Compute Engine, Confidential VMs are designed to help organizations, particularly ones in regulated industries, protect sensitive data by providing memory encryption capabilities that can be leveraged to isolate cloud workloads. Confidential VMs leverage the Secure Encrypted Virtualization feature in 2nd Gen AMD EPYC processors to ensure that sensitive data remains encrypted at all times, including while it's used, queried or indexed.

AMD: Fixes For High-Severity SMM Callout Flaws Upcoming
2020-06-22 15:37

An attacker with physical or privileged access to certain AMD powered systems could exploit the flaws to execute arbitrary code or take control of the firmware. AMD, which dubs the flaws "SMM Callout Privilege Escalation" bugs, released a fix for one of the three, CVE-2020-14032, on June 8.

AMD Preparing Patches for UEFI SMM Vulnerability
2020-06-22 10:11

AMD last week said it was preparing patches for a vulnerability affecting the System Management Mode of the Unified Extensible Firmware Interface shipped with systems that use certain notebook and embedded processors. Discovered by security researcher Danny Odler in AMD's Mini PC and tracked as CVE-2020-12890, the vulnerability is one of the three issues reported in April, allowing an attacker to manipulate secure firmware and execute arbitrary code while avoiding detection.

Thought you'd fixed those Linux Spectre issues? Guess again, and AMD users need to be especially on their toes
2020-06-09 19:39

In three posts marked urgent to the Linux kernel mailing list on Tuesday, Anthony Steinhauser points out problems with countermeasures put in place to block Spectre vulnerabilities in modern Intel and AMD x86 microprocessors that perform speculative execution. The Spectre family of flaws involve making a target system speculate - perform an operation it may not need - in order to expose confidential data so an attacker can obtain it through an unprotected side channel.

New Noise-Resilient Attack On Intel and AMD CPUs Makes Flush-based Attacks Effective
2020-05-30 03:32

Modern Intel and AMD processors are susceptible to a new form of side-channel attack that makes flush-based cache attacks resilient to system noise, newly published research shared with The Hacker News has revealed. It also works seamlessly against non-Linux Operating Systems, like macOS. "Like any other cache attacks, flush based cache attacks rely on the calibration of cache latency," Biswabandan Panda, assistant professor at IIT Kanpur, told The Hacker News.

New Noise-Resilient Attack On Intel and AMD CPUs Makes Flush-based Attacks Effective
2020-05-30 03:32

Modern Intel and AMD processors are susceptible to a new form of side-channel attack that makes flush-based cache attacks resilient to system noise, newly published research shared with The Hacker News has revealed. It also works seamlessly against non-Linux Operating Systems, like macOS. "Like any other cache attacks, flush based cache attacks rely on the calibration of cache latency," Biswabandan Panda, assistant professor at IIT Kanpur, told The Hacker News.

AMD dials 911, emits DMCA takedowns after miscreant steals a load of GPU hardware blueprints, leaks on GitHub
2020-03-26 19:10

On Wednesday, AMD confirmed intellectual property related to its graphics processors was stolen last year, though insisted the leaked files will not damage its business nor compromise product security. Two days ago, AMD issued two Digital Millennium Copyright Act takedown notices to GitHub, directing the Microsoft-owned code storage biz to remove five repositories - an original repo and four copies - that contained confidential internal hardware source code for its Navi family of GPUs.