More bad news for Intel. Yet another security flaw has been identified in the processors the company makes. This one is so newly discovered that the full technical details have yet to be released. Here’s what we know so far, from a recent Intel announcement:
“System software may opt to utilize Lazy FP state restore instead of eager save and restore of the state upon a context switch…Lazy restored states are potentially vulnerable to exploits where one process may infer register values of other process through a speculative execution side channel that infers their value.”
In simpler terms, what this means is that a hacker could use this exploit to gain partial cryptographic keys used by other programs running on the target computer.
While related to the recent Spectre and Meltdown security flaws, this one is different in two ways. First, it’s not quite as severe as the formerly discovered flaws in scope or scale. To make use of this, one would require an incredibly exotic attack that would simply be beyond the capabilities of most hackers.
Also, it should be noted that where Spectre and Meltdown impacted dozens of chipsets dating back more than a decade, the “Lazy FP State Restore” flaw only impacts chips beginning at Sandy Bridge.
The other key difference is that the flaw in this case, does not reside in the hardware. That’s good news for businesses of all shapes and sizes, because it means that when Intel and their hardware vendors have a patch ready, it will be quick and relatively painless to install it.
Unfortunately, since the initial discovery of Spectre and Meltdown, a number of variants of those flaws have emerged, and now this new one. It’s unlikely that this will be the last we’ve seen of these types of issues, so if you’re using Intel equipment, brace yourself. There’s likely more to come.
Change is coming, and not everyone is happy about it. Recently, Google redesigned its G-mail interface, and since then, they’ve allowed their free users to opt into the new changes. G-Suite users may or may not see the option to try the new interface, depending on whether their administrators have enabled the option and made it visible.
It’s the end of the line for Yahoo Messenger. As of July, it will be no more, marking the end of an era.
Facebook is in hot water again. Recently, the company admitted that while testing a new feature on the site, they inadvertently made public the posts of more than fourteen million users. The incident occurred between May 18th and May 22nd and occurred when Facebook was testing a new “Featured Posts” enhancement.
Another week, another new threat. This time, in the form of a new strain of malware that researchers are calling InvisiMole. The new threat was discovered by researchers at ESET, who found it on a number of hacked computers in Russia and the Ukraine.
Big changes are coming from Microsoft starting in July (exact date unknown), and it has potentially dire implications if you’re using some of the company’s older technology.
Cyber-criminals around the world are increasingly focusing their attention on job seekers. According to the security firm Flashpoint, there has been a notable uptick in ploys involving phony job listings that attempt to get job seekers to give up personal information.
Another week, another high-profile data breach, but this one can be filed under “Missed Opportunity.” The site in question is “TicketFly,” which is a web-based event ticket sales website owned by a company called Eventbrite. The TicketFly website was down since May 31st, and the normal homepage had been replaced by an image of Guy Fawkes with the message “Your Security Down I’m Not Sorry.”
A new study recently published by HPE Aruba called “The Right Technologies Unlock The Potential Of The Digital Workplace,” reveals some interesting details about technology in the workplace that’s worth paying attention to.
Microsoft just made a big, significant purchase that has raised more than a few eyebrows. They just acquired GitHub for a hefty $7.5 billion.