Backdoor Firmware Found on Millions of PC Motherboards

General News

Summary

Cybercriminals have increasingly employed a devious tactic by concealing malicious programs within a computers UEFI firmware—the fundamental code responsible for booting the operating system. These vulnerabilities create a potential risk of malicious actors exploiting the mechanism, who could utilize it to install malware instead of the intended Gigabyte program. Surprisingly, the researchers automated detection scans flagged Gigabytes updater mechanism for engaging in suspicious activities reminiscent of state-sponsored hacking tools. Furthermore, there is a genuine fear that Gigabytes mechanism could fall victim to exploitation by hackers who infiltrate the motherboard manufacturer, leveraging its hidden access for a nefarious software supply chain attack. Shockingly, it downloads code to the users machine without undergoing proper authentication, and in some instances, it even utilizes an insecure HTTP connection instead of the more secure HTTPS.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M