Security News

Worried about bootkits, rootkits, UEFI nasties? Have you tried turning on Secure Boot, asks the No Sh*! Agency
2020-09-16 00:40

The American surveillance super-agency's 39-page explainer [PDF] covers UEFI security and, in particular, how folks can master Secure Boot and avoid switching it off for compatibility reasons. Secure Boot is a mechanism that uses cryptography to ensure you're booting an operating system that hasn't been secretly meddled with; any addition of a bootkit or rootkit should be caught by Secure Boot.

AMD Preparing Patches for UEFI SMM Vulnerability
2020-06-22 10:11

AMD last week said it was preparing patches for a vulnerability affecting the System Management Mode of the Unified Extensible Firmware Interface shipped with systems that use certain notebook and embedded processors. Discovered by security researcher Danny Odler in AMD's Mini PC and tracked as CVE-2020-12890, the vulnerability is one of the three issues reported in April, allowing an attacker to manipulate secure firmware and execute arbitrary code while avoiding detection.

Microsoft Defender ATP Gets UEFI Scanner
2020-06-18 15:21

Microsoft has extended the protection capabilities of Microsoft Defender Advanced Threat Protection with the addition of a Unified Extensible Firmware Interface scanner. With hardware and firmware-level attacks increasing in frequency over the past several years, Microsoft has decided to expand its security solution's capabilities to ensure it can continue to keep users secure.

Microsoft Pulls UEFI-Related Windows Update After Users Report Problems
2020-02-17 12:16

Microsoft has decided to remove a couple of Windows security updates that address a UEFI issue after some users complained that the updates caused serious problems. Some users reported that their devices became unusable after trying to install the KB4524244 security update for Windows 10.

Detailed: How Russian government's Fancy Bear UEFI rootkit sneaks onto Windows PCs
2019-01-02 23:13

ESET sheds new light on 'Lojax' firmware infection ESET eggheads have shed more light on the Unified Extensible Firmware Interface (UEFI) rootkit being used by the Kremlin's Fancy Bear hacking crew.…

First Ever UEFI Rootkit Tied to Sednit APT
2018-12-28 20:02

Researcher at ESET outlines research on the first successful UEFI rootkit used in the wild.

How BMC and UEFI can be exploited to brick servers and take down your data center
2018-12-19 15:00

Out-of-band management systems can be a weak link to securing your data center. Here's how a debug utility can be leveraged to brick your systems.

Week in review: First-ever UEFI rootkit, Apple DEP vulnerability, new tactics subvert traditional security measures
2018-09-30 18:48

Here’s an overview of some of last week’s most interesting news and articles: What do you mean by storage encryption? Depending on the threat context and how you define “storage encryption,” it...

Resident evil: Inside a UEFI rootkit used to spy on govts, made by you-know-who (hi, Russia)
2018-09-28 02:07

Deep dive into motherboard firmware-lurking code A UEFI rootkit, believed to have been built from an anti-thief software program by Kremlin spies to snoop on European governments, has been...

Cybersecurity Researchers Spotted First-Ever UEFI Rootkit in the Wild
2018-09-27 14:33

Cybersecurity researchers at ESET have unveiled what they claim to be the first-ever UEFI rootkit being used in the wild, allowing hackers to implant persistent malware on the targeted computers...