Intel has had a tough time of things so far this year. The most recent trouble stems from yet another newly discovered security flaw in the company’s processors, bearing the inelegant name of “L1 Terminal Fault,” or “Foreshadow” by those who have discovered it.
The attack can take one of three different shapes (so far), and ultimately allows a hacker to access sensitive data stored in the computer’s memory or on third-party cloud-based storage services. This sensitive data includes passwords, pictures, other sorts of data files, and encryption keys.
The three variants of the attack have been grouped into two distinct categories, known as Foreshadow and Foreshadow NG (Next Gen).
The standard Foreshadow variant (Reference CVE-2018-3615) targets Intel’s Software Guard Extensions (SGX), which is new technology designed by intel to help keep user data from falling into the wrong hands, even if the whole system comes under attack.
As the researchers who discovered it describe it:
“Foreshadow enables an attacker to extract SGX sealing keys, previously sealed data can be modified and re-sealed. With the extracted sealing key, an attacker can trivially calculate a valid Message Authentication Code (MAC), thus depriving the data owner from the ability to detect the modification.”
The Foreshadow: Next Generation attack (reference CVE-2018-3620 and CVE-2018-3646) targets virtualization environments like those used by large cloud-based service providers like Microsoft and Amazon.
From the researchers again:
“Using Foreshadow-NG, a malicious program running on the computer might be able to read some parts of the kernel’s data. As the kernel has access to data stored by other programs, a malicious program might be able to exploit Foreshadow-NG to access data belonging to other programs.
Foreshadow is different from Meltdown as it targets virtual machines and SGX, in addition to data stored in the operating system’s kernel (which was targeted by Meltdown).”
According to Intel, none of these attacks have been seen in the wild, but of course, that’s just a matter of time now. No word from Intel yet on a time frame to address these issues, but stay tuned.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Nothing bad could possibly happen to your company’s network if the only piece of information the hackers have is your fax number, right?
How seriously does the average consumer take data theft? It’s an interesting (and fair) question, and one that Radware recently attempted to answer when the company sent out surveys. They contacted more than three thousand people to conduct its recent survey titled “Consumer Sentiments: Cybersecurity, Personal Data and the Impact on Customer Loyalty.”
These days, we expect giant corporations, government agencies and medical facilities to be the targets of hackers. However, golf is something new.
If you’re a Reddit user, it’s time to change your password. According to the company, they recently discovered evidence of a hack that exposed all company data from the site’s launch (2005) to 2007, including user emails and account credentials.
F-Secure recently published a new report, and their findings are disturbing.
File this away under things you already knew. Coronet recently released a report entitled “Attention All Passengers: Airport Networks Are Putting Your Devices & Cloud Apps At Severe Risk,” and the news is about what you’d expect.
Mimecast’s 2018 “State of Email Security” report is out, and although it’s contents are hardly a surprise, the news it contains is mostly bad.
There’s a new Bluetooth security vulnerability to be aware of, tracked as CVE-2018-5383, and it’s a nasty one.
Positive Technologies has just released a new report that paints a grim picture for IT professionals. If your sense is that the number of cyberattacks are increasing, you’re not wrong. In fact, it’s probably worse than you realize.