U1 News
  • Home
  • World
  • U.S.
  • Business
  • Technology
  • Science
  • Entertainment
  • Sport
  • Health
Global News

Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

July 30, 2024

Taylor Swift speaks out after Southport mass stabbing at dance class

July 30, 2024

3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

July 30, 2024
Facebook Twitter Instagram
Trending
  • What to know about Cushing’s syndrome, which led to Amy Schumer's dramatic weight loss
  • Major measles outbreak leads to hundreds quarantined in US county, officials say
  • Man’s extreme energy drink habit leads to concerning medical discovery, doctors say
  • 5 winter-weather essentials to protect skin health in dangerously cold temperatures
  • Insufficient sleep linked to major hidden health risk, study reveals
  • Massachusetts man diagnosed with deadly lung disease linked to popular kitchen countertops
  • Relationship coach blames Oprah for pushing family estrangement 'for decades'
  • Sperm donor with hidden cancer gene fathers nearly 200 kids, families blindsided
Saturday, December 13
U1 News
  • Home
  • World

    Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

    July 30, 2024

    Taylor Swift speaks out after Southport mass stabbing at dance class

    July 30, 2024

    3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

    July 30, 2024

    Kerala, India, hit by landslides, killing at least 99

    July 30, 2024

    Taylor Swift ‘in shock’ after horrific UK stabbing, as police say 3rd child dies

    July 30, 2024
  • U.S.

    Biden criticises ‘extreme’ Supreme Court in push for reform

    July 30, 2024

    FBI details shooter’s search history before Trump assassination attempt

    July 30, 2024

    Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

    July 29, 2024

    Biden to call for major Supreme Court reforms, including term limits, at Civil Rights Act event Monday

    July 29, 2024

    Sonya Massey’s death revives pain for Breonna Taylor, Floyd activists

    July 29, 2024
  • Business

    AMD stock jumps on earnings beat driven by AI chip sales

    July 30, 2024

    Amazon is responsible for dangerous products sold on its site, federal agency rules

    July 30, 2024

    Microsoft investigating new outages of services after global CrowdStrike chaos

    July 30, 2024

    S&P 500, Nasdaq Tumble as Chip Stocks Slide Ahead of Big Tech Earnings

    July 30, 2024

    American consumers feeling more confident in July as expectations of future improve

    July 30, 2024
  • Technology

    Apple says Safari protects your privacy. We fact checked those claims.

    July 30, 2024

    GameStop Dunks On Xbox 360 Store Closing And Gets Savaged

    July 30, 2024

    Logitech has an idea for a “forever mouse” that requires a subscription

    July 30, 2024

    Friend: a new digital companion for the AI age

    July 30, 2024

    London Sports Mod Community Devolves Into War

    July 30, 2024
  • Science

    NASA’s Lunar Gateway has a big visiting vehicles problem

    August 1, 2024

    Boeing’s Cursed ISS Mission May Finally Make It Back to Earth

    July 30, 2024

    Should you floss before or after you brush your teeth?

    July 30, 2024

    Ancient swimming sea bug ‘taco’ had mandibles, new fossils show

    July 30, 2024

    NASA’s DART asteroid impact mission revealed ages of twin space rock targets (images)

    July 30, 2024
  • Entertainment

    Richard Gadd Backs Netflix to Get ‘Baby Reindeer’ Lawsuit Dismissed

    July 30, 2024

    Batman: Caped Crusader review: a pulpy throwback to DC’s Golden Age

    July 30, 2024

    Channing Tatum Praises Ryan Reynolds For Taking Gamble On Gambit

    July 30, 2024

    ‘Star Wars Outlaws’ somehow made me fall in love with Star Wars again

    July 30, 2024

    Great Scott and O’Brien’s Pub find new life in Allston

    July 30, 2024
  • Sport

    How Snoop Dogg became a fixture of the Paris Olympics

    July 30, 2024

    Team USA’s Coco Gauff exits Olympics singles tournament with a third-round loss : NPR

    July 30, 2024

    French police investigating abuse targeting Olympic opening ceremony DJ over ‘Last Supper’ scene

    July 30, 2024

    French DJ Takes Legal Action

    July 30, 2024

    Why BYU’s Jimmer Fredette is at the 2024 Paris Olympics

    July 30, 2024
  • Health

    What to know about Cushing’s syndrome, which led to Amy Schumer's dramatic weight loss

    December 13, 2025

    Major measles outbreak leads to hundreds quarantined in US county, officials say

    December 12, 2025

    Man’s extreme energy drink habit leads to concerning medical discovery, doctors say

    December 12, 2025

    5 winter-weather essentials to protect skin health in dangerously cold temperatures

    December 12, 2025

    Insufficient sleep linked to major hidden health risk, study reveals

    December 12, 2025
U1 News
Home»Technology»Secure Boot useless on hundreds of PCs from major vendors after key leak • The Register
Technology

Secure Boot useless on hundreds of PCs from major vendors after key leak • The Register

u1news-staffBy u1news-staffJuly 29, 2024No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Boot Shutterstock.jpg
Share
Facebook Twitter LinkedIn Pinterest Email

Information Security Overview Securing your computer’s BIOS and boot process is essential to modern security, but knowing it’s important and actually taking the steps to do so are not the same thing.

For example, let’s take research as an example. Published The findings were announced last week by security experts at firmware security vendor Binarily. hundreds PCs sold by Dell, Acer, Fujitsu, Gigabyte, HP, Lenovo and Supermicro, as well as components sold by Intel, use a 12-year-old test Platform Key (PK) that was supposedly leaked in 2022 to protect their UEFI Secure Boot implementations.

“An attacker who has access to the private part of the PK can easily circumvent Secure Boot by manipulating the Key Exchange Key Database, the Signature Database, and the Forbidden Signature Database,” Binarily researchers wrote.

And it’s not as though the manufacturer using the PK in question had no reason to know that it was unreliable and not intended for use outside of a laboratory – it was clearly stated on the packaging.

“These test keys have strong indications that they should not be trusted,” Binarily points out. “For example, the certificate issuer contains the strings ‘do not trust’ or ‘do not ship.'”

According to Binarily, over 10% of the firmware images in the dataset are vulnerable to attack with an untrusted PK, likely published by American Megatrends International in May 2012. The researchers note that this problem is “one of the longest-running.” [supply chain vulnerabilities] Something of that kind.”

If an attacker leverages the PK in an attack, they could execute untrusted code during the boot process, even if Secure Boot is enabled.

“This puts the entire security chain at risk, from firmware to operating system,” Binary added.

Binarily is Free Scan Tools It checks your system for a vulnerability called PKFail, which seems like a wise move to make. It requires some effort from device manufacturers to fix this issue.

Critical Vulnerability of the Week: KEV how old?

This week starts with new reports of a very old vulnerability being exploited in the wild.

According to NIST, Internet Explorer versions 6 through 8 contain a use-after-free vulnerability that could allow remote attackers to execute arbitrary code. Detected and identified It was discovered in the wild in 2012. Still being exploited today.

If for some reason you still have machines running IE 6 through 8, it may be time to retire them.

Also, last week, the Internet System Consortium (CVE-2024-4076, CVE-2024-1975, CVE-2024-1737, CVE-2024-0760).

These flaws, if exploited, could lead to a denial of service, and although they are not as severe as other vulnerabilities, because they exist at the DNS level they are still worth installing patches as soon as possible.

Stalkerware vendor breached again

It seems possible Just 2 weeks We’re here before the stalkerware vendors get in. Handed over A trove of files were stolen from Minnesota-based SpyTech last week.

The files, which were allegedly verified as authentic, were installed on phones, tablets and computers monitored by SpyTec software, which secretly monitors devices and spies on users’ activities. Data was found on more than 10,000 devices dating back to 2013.

Interestingly, SpyTech’s CEO reportedly had no knowledge of the breach when asked about it, showing that these stores are prioritizing making money over protecting the personal data they collect on behalf of their customers.

…and turn on MFA

Cisco Talos security researchers Quarterly Reporting As we looked at incident response trends over the last week, one surprising trend emerged: Nearly 80% of ransomware attacks in Q2 occurred at organizations whose systems did not employ multi-factor authentication.

And we thought Snowflake Maybe it taught the world something.

Talos noted that compromised credentials were the most common way to gain initial access for three consecutive quarters, which is the exact same reason behind all of Snowflake’s outages.

Ransomware efforts overall increased 22% from Q1 to Q2 and accounted for 30% of all incidents Talos responded to. Coupled with the rise in attacks using stolen credentials and exploiting a lack of MFA, this week may be a good time to enable MFA for all users, without exception.

TracFone fined $16 million for three violations

Verizon subsidiary TracPhone has agreed to pay $16 million to the FCC to end an investigation into three data breaches the company experienced between 2021 and 2023.

According to the FCC, TracFone failed to protect several of its customer database APIs, allowing criminals to steal customer account and device information and personally identifiable information. The breach led to “numerous unauthorized port-outs.”

Not to be confused SIM swap Porting out is another scam that most carriers are completely unable to prevent. Porting out involves transferring your number entirely to another carrier, both of which can give attackers control over your customers’ devices.

TracFone has been ordered to implement a mandatory cybersecurity program with new provisions to mitigate API vulnerabilities, as well as SIM swap and port-out protections.®

Boot hundreds key leak major PCs Register Secure Useless vendors
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
u1news-staff
u1news-staff
  • Website

Related Posts

Major measles outbreak leads to hundreds quarantined in US county, officials say

December 12, 2025

Insufficient sleep linked to major hidden health risk, study reveals

December 12, 2025

Breakthrough GLP-1 implant promises major weight-loss benefits for pets

December 9, 2025

New baldness treatment shows dramatic hair-regrowth gains in major trial

December 9, 2025
Add A Comment

Leave A Reply Cancel Reply

Latest Posts

What to know about Cushing’s syndrome, which led to Amy Schumer's dramatic weight loss

December 13, 2025

Major measles outbreak leads to hundreds quarantined in US county, officials say

December 12, 2025

Man’s extreme energy drink habit leads to concerning medical discovery, doctors say

December 12, 2025

5 winter-weather essentials to protect skin health in dangerously cold temperatures

December 12, 2025
Unites States

Biden criticises ‘extreme’ Supreme Court in push for reform

July 30, 2024

FBI details shooter’s search history before Trump assassination attempt

July 30, 2024

Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

July 29, 2024

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Copyright ©️ All rights reserved. | U1 News
  • Home
  • About Us
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.