Security News

What do a Lenovo touch pad, an HP camera and Dell Wi-Fi have in common? They'll swallow any old firmware, legit or saddled with malware
2020-02-19 08:02

Eclypsium said on Monday that, despite years of warnings from experts - and examples of rare in-the-wild attacks, such as the NSA's hard drive implant - devices continue to accept unsigned firmware. The infosec biz said a miscreant able to alter the firmware on a system - such as by intercepting or vandalizing firmware downloads, or meddling with a device using malware or as a rogue user - can do so to insert backdoors and spyware undetected, due to the lack of cryptographic checks and validations of the low-level software.

What does a Lenovo touch pad, an HP camera and Dell Wi-Fi have in common? They'll swallow any old firmware, legit or saddled with malware
2020-02-19 08:02

Eclypsium said on Monday that, despite years of warnings from experts - and examples of rare in-the-wild attacks, such as the NSA's hard drive implant - devices continue to accept unsigned firmware. The infosec biz said a miscreant able to alter the firmware on a system - such as by intercepting or vandalizing firmware downloads, or meddling with a device using malware or as a rogue user - can do so to insert backdoors and spyware undetected, due to the lack of cryptographic checks and validations of the low-level software.

Lenovo, HP, Dell Peripherals Face Unpatched Firmware Bugs
2020-02-18 11:00

TouchPad and TrackPoint firmware in Lenovo Laptops, HP Wide Vision FHD camera firmware in HP laptops and the Wi-Fi adapter on Dell XPS laptops were all found to lack secure firmware update mechanisms with proper code-signing. Eclypsium researchers analyzed a Lenovo ThinkPad X1 Carbon 6th Gen laptop, which contains two vulnerable firmware mechanisms: Touchpad firmware and TrackPoint firmware.

Pivot3 provides its HCI software platform to Lenovo DCG to deliver integrated edge computing solutions
2019-12-06 01:30

Pivot3, a leading provider of intelligent infrastructure solutions, announced that it is providing its hyperconverged infrastructure (HCI) software platform to Lenovo Datacenter Group (DCG) to...

Asus, Lenovo and Other Routers Riddled with Remotely Exploitable Bugs
2019-09-16 17:48

Independent researchers found 125 different CVEs across 13 different router and NAS models.

Nokia and Lenovo lead global survey on regularity of Android brand software and security updates
2019-08-30 16:45

As more people keep their smartphones for longer, the survey found that most companies are failing to update older versions.

Someone find a make-me-admin hole in your laptop crapware? Don't want fix the bug? Just move the EOL date – right, Lenovo?
2019-08-23 18:14

Uninstall Solution Centre or your security could be gone in 300 seconds Not only has a vulnerability been found in Lenovo Solution Centre (LSC), but the laptop maker fiddled with end-of-life dates...

Security gone in 600 seconds: Make-me-admin hole found in Lenovo Windows laptop crapware. Delete it now
2019-08-23 18:14

Solution Centre WONTFIX amid EOL date shenanigans Not only has a vulnerability been found in Lenovo Solution Centre (LSC), but the laptop maker fiddled with end-of-life dates to make it seem less...

Lenovo High-Severity Bug Found in Pre-Installed Software
2019-08-23 16:00

Security researchers at Pen Test Partners have found a privilege escalation flaw in the much-maligned Lenovo Solution Center software.

Lenovo Warns on ThinkPad Bugs, One Unpatched
2019-08-14 17:56

The notebook maker is warning users of three separate vulnerabilities.