Security researchers from around the web are reporting finding an increasing number of instances of proof of concept (PoC) code that incorporates the recently discovered Spectre and Meltdown vulnerabilities.
If you somehow missed those earlier reports, Spectre and Meltdown are a pair of critical security flaws recently discovered in literally every Intel chip set made over the last decade. Exploiting these vulnerabilities would give a hacker root-level access to the impacted system.
Since the discovery, the chip giant has been scrambling to fix the issue. However, their first attempt to do so caused so many system problems for people who installed the patch that the company is now recommending that users avoid it until they can come up with a better solution.
Unfortunately, that leaves you between the proverbial rock and a hard place. Installing the patch will protect you, but cause you to experience system reboots several times a day and seriously degraded performance. Not installing it leaves you at the mercy of the hackers.
So far, at least, it appears that most of the proof of concept code found is the result of security researchers playing with the exploits. This includes testing them, seeing how they work, and how to prevent them. That said, the researchers point out that it’s all but certain that some of the PoC examples were created by teams of hackers who plan to use them in their next round of attacks.
To make matters worse, Mozilla has confirmed that the Spectre flaw can be executed remotely by inserting commands into Javascript. Given that, plus the increased appearance of PoC code fragments, it seems it’s just a matter of time before we see the first ever Spectre-based hack. The clock is ticking.
Oracle is currently the third-largest provider of POS (Point of Sale) software on the market today, which means that there’s a fairly good chance you’re using an Oracle POS system. If you are, there’s trouble ahead. A recently discovered security flaw could put your system at risk.
Google recently released their Play Store stats for 2017. The results are both encouraging and disheartening. Overall, Google caught and removed more than 700,000 malicious apps from the Play Store, minimizing their impact on the company’s massive Android user base.
Recently, Apple found itself in hot water with its normally adoring user base. This happened when it became known that the company was intentionally throttling (slowing down) the speed of older iPhones.
Recently a critical flaw was found inside every Intel chip made during the last decade. The flaw makes two different exploits possible. These exploits have been dubbed “Meltdown” and “Spectre.”
All companies collect data on their customers, but some are better than others when it comes to being upfront about what kinds of data are collected. Over the past year, Microsoft has made many moves that have been well-received by their enormous user base. They’ve become increasingly transparent and offer an unprecedented level of control to the users themselves.
Do you play Blizzard online computer games such as World of Warcraft, Diablo III, Hearthstone, Starcraft II, or Overwatch? If so, there’s a potential problem you need to be aware of.
By now, we’ve seen enough large-scale Point of Sale (POS) credit card thefts that patterns are beginning to emerge. Some companies follow the general arc of the narrative better than others and deserve credit for doing so, but in the end, the story is about the same.
It’s official, the first macOS malware of 2018 is here. Discovered by an independent security researcher and dubbed “OSX/MaMi,” the code is functionally similar to DNSChanger malware.
The ThreatMetrix Cybercrime Report 2017 is out, and is a troubling read for anyone who has anything to do with data security. As a fraud prevention company protecting nearly a billion and a half users around the world, they’re uniquely positioned to know, and their insights on the threat landscape is invaluable.