Security News

GIGABYTE releases new firmware to fix recently disclosed security flaws
2023-06-05 15:09

GIGABYTE has released firmware updates to fix security vulnerabilities in over 270 motherboards that could be exploited to install malware. The firmware updates were released last Thursday in response to a report by hardware security company Eclypsium, who found flaws in a legitimate GIGABYTE feature used to install a software auto-update application in Windows.

Critical Firmware Vulnerability in Gigabyte Systems Exposes ~7 Million Devices
2023-05-31 13:18

Cybersecurity researchers have found "Backdoor-like behavior" within Gigabyte systems, which they say enables the UEFI firmware of the devices to drop a Windows executable and retrieve updates in an unsecure format. "Most Gigabyte firmware includes a Windows Native Binary executable embedded inside of the UEFI firmware," John Loucaides, senior vice president of strategy at Eclypsium, told The Hacker News.

HP rushes to fix bricked printers after faulty firmware update
2023-05-20 14:04

HP is working to address a bad firmware update that has been bricking HP Office Jet printers worldwide since it was released earlier this month. While HP has yet to issue a public statement regarding these ongoing problems affecting a subset of its customer base, the company told BleepingComputer that it's addressing the blue screen errors seen by a "Limited number" of users.

TP-Link routers implanted with malicious firmware in state-sponsored attacks
2023-05-17 12:39

A Chinese state-sponsored APT group implanted malicious firmware into TP-Link routers as part of attack campaigns aimed at European foreign affairs entities, say Check Point researchers. The malicious firmware was exclusively created for TP-Link routers.

Hackers infect TP-Link router firmware to attack EU entities
2023-05-16 16:25

The backdoor malware is deployed in a custom and malicious firmware designed specifically for TP-Link routers so that the hackers can launch attacks appearing to originate from residential networks. While Check Point has not determined how the attackers infect TP-Link routers with the malicious firmware image, they said it could be by exploiting a vulnerability or brute-forcing the administrator's credentials.

Kingston's SSD firmware has Coldplay lyrics hidden within it
2023-05-10 14:13

What has firmware got to do with pop rock, you ask? That's the question that crossed a security researcher's mind as he analyzed Kingston's firmware and stumbled upon the lyrics of a popular Coldplay song buried deep within it. The researcher, surprised by this finding, reached out to BleepingComputer disclosing the details of the firmware version-and the Coldplay song.

Surprise! Coldplay lyrics hidden in Kingston SSD firmware
2023-05-10 14:13

What has firmware got to do with pop rock, you ask? That's the question that crossed a security researcher's mind as he analyzed Kingston's firmware and stumbled upon the lyrics of a popular Coldplay song buried deep within it. The researcher, surprised by this finding, reached out to BleepingComputer disclosing the details of the firmware version-and the Coldplay song.

MSI’s firmware, Intel Boot Guard private keys leaked
2023-05-08 11:25

The cybercriminals who breached Taiwanese multinational MSI last month have apparently leaked the company's private code signing keys on their dark web site. MSI is a corporation that develops and sells computers and computer hardware.

Drone goggles maker claims firmware sabotaged to ‘brick’ devices
2023-05-03 19:40

Orqa, a maker of First Person View drone racing goggles, claims that a contractor introduced code into its devices' firmware that acted as a time bomb designed to brick them. On early Saturday, Orqa started receiving reports from customers surprised to see their FPV.One V1 goggles enter bootloader mode and become unusable.

Drone goggles maker claims ‘ransomware’ attack after firmware sabotage
2023-05-03 19:40

Orqa, a maker of First Person View drone racing goggles, claims that a contractor introduced code into its devices' firmware that acted as a time bomb designed to brick them. On early Saturday, Orqa started receiving reports from customers surprised to see their FPV.One V1 goggles enter bootloader mode and become unusable.