News Gist .News

Articles | Politics | Finance | Stocks | Crypto | AI | Technology | Science | Gaming | PC Hardware | Laptops | Smartphones | Archive

Google Researchers Release Kit to Exploit Microcode Vulnerability in AMD CPUs

A team of Google researchers has identified a significant exploit, named "EntrySign," affecting AMD's Zen 1 through Zen 4 processors, which allows users with local admin privileges to push custom microcode updates. This vulnerability, while requiring high-level access to exploit, poses serious implications for security, as it enables users to manipulate CPU behavior and potentially weaken system protections. AMD has issued a BIOS patch to address the issue, but many CPUs remain vulnerable until updated, highlighting the ongoing challenges of CPU security management.

See Also

Microsoft Discoveries Vulnerable Software Attack. Δ1.76

Microsoft has confirmed that its Windows drivers and software are being exploited by hackers through zero-day attacks, allowing them to escalate privileges and potentially drop ransomware on affected machines. The company patched five flaws in a kernel-level driver for Paragon Partition Manager, which were apparently found in BioNTdrv.sys, a piece of software used by the partition manager. Users are urged to apply updates as soon as possible to secure their systems.

Firm Says AI-Assisted Security Analyzer Found 16 Bugs in OpenRISC CPU Core in Under 60 Seconds Δ1.76

Caspia Technologies has made a significant claim about its CODAx AI-assisted security linter, which has identified 16 security bugs in the OpenRISC CPU core in under 60 seconds. The tool uses a combination of machine learning algorithms and security rules to analyze processor designs for vulnerabilities. The discovery highlights the importance of design security and product assurance in the semiconductor industry.

Researchers Uncover Unknown Android Flaws Used to Hack Into a Student's Phone Δ1.76

Amnesty International said that Google fixed previously unknown flaws in Android that allowed authorities to unlock phones using forensic tools. On Friday, Amnesty International published a report detailing a chain of three zero-day vulnerabilities developed by phone-unlocking company Cellebrite, which its researchers found after investigating the hack of a student protester’s phone in Serbia. The flaws were found in the core Linux USB kernel, meaning “the vulnerability is not limited to a particular device or vendor and could impact over a billion Android devices,” according to the report.

Broadcom Releases Fixes for Multiple VMware Security Flaws Δ1.74

Broadcom has released patches for three critical vulnerabilities in its VMware products, which are already being exploited in the wild. The bugs were described as VM escape flaws and affect all supported versions of VMware ESX, vSphere, Cloud Foundation, and Telco Cloud Platform. These issues were deemed severe enough to warrant immediate attention from users, who are urged to apply the fixes as soon as possible.

Top Bluetooth Chip Security Flaw Could Put a Billion Devices at Risk Worldwide Δ1.74

A "hidden feature" was found in a Chinese-made Bluetooth chip that allows malicious actors to run arbitrary commands, unlock additional functionalities, and extract sensitive information from millions of Internet of Things (IoT) devices worldwide. The ESP32 chip's affordability and widespread use have made it a prime target for cyber threats, putting the personal data of billions of users at risk. Cybersecurity researchers Tarlogic discovered the vulnerability, which they claim could be used to obtain confidential information, spy on citizens and companies, and execute more sophisticated attacks.

Huge Cyberattack Found Hitting Vulnerable Microsoft-Signed Legacy Drivers to Get Past Security Δ1.74

A massive cybercriminal campaign has been discovered utilizing outdated and vulnerable Windows drivers to deploy malware against hundreds of thousands of devices. The attackers leveraged a signed driver, allowing them to disable antivirus programs and gain control over infected machines. This campaign is believed to be linked to the financially motivated group Silver Fox, which is known for its use of Chinese public cloud servers.

Thousands of Misconfigured Building Access Systems Have Been Leaked Online Δ1.73

Misconfigured Access Management Systems (AMS) connected to the internet pose a significant security risk to organizations worldwide. Vulnerabilities in these systems could allow unauthorized access to physical resources, sensitive employee data, and potentially even compromise critical infrastructure. The lack of response from affected organizations raises concerns about their readiness to mitigate potential risks.

Windows 11 24H2 Performance Issues Spark Intel-BASED Crisis Δ1.73

The two latest patches for Windows 11 24H2 are causing some users problems, allegedly due to Intel's latest microcode update. Some users of Windows 11 24H2 have been experiencing game crashes and slowdowns, with the problem appearing exclusive to the latest updates. The user experience has been less than ideal since the most recent version rolled out on October 1, 2024.

Breaking Into Code: Security Threat Impacts Customer Data at Zapier Δ1.72

Zapier has disclosed a security incident where an unauthorized user gained access to its code repositories due to a 2FA misconfiguration, potentially exposing customer data. The breach resulted from an "unauthorized user" accessing certain "certain Zapier code repositories" and may have accessed customer information that had been "inadvertently copied" to the repositories for debugging purposes. The incident has raised concerns about the security of cloud-based platforms.

Threat Posed by New VMware Hyperjacking Vulnerabilities Is Hard to Overstate Δ1.72

A recently discovered trio of vulnerabilities in VMware's virtual machine products can grant hackers unprecedented access to sensitive environments, putting entire networks at risk. If exploited, these vulnerabilities could allow a threat actor to escape the confines of one compromised virtual machine and access multiple customers' isolated environments, effectively breaking all security boundaries. The severity of this attack is compounded by the fact that VMware warned it has evidence suggesting the vulnerabilities are already being actively exploited in the wild.

Intel Releases Arrow Lake CPUs Für Business Laptops, Heralding New Era of Efficiency Δ1.72

The release of Intel's Arrow Lake platform for business laptops marks a significant shift towards more efficient mobile workstation designs, addressing the frustrations of customers who had to wait two years for updates. The new CPUs are poised to deliver improved performance and power efficiency, allowing businesses to upgrade their existing fleets without compromising on capabilities. With the introduction of special vPro versions with enhanced management and security features, Intel is targeting large corporate customers.

A Shocking AI Chip Scandal Just Rocked the Market--And Nvidia Could Be Caught in the Crossfire Δ1.72

Singapore's recent fraud case has unveiled a potential smuggling network involving AI chips, raising concerns for Nvidia, Dell, and regulatory bodies worldwide. Three individuals have been charged in connection with the case, which is not tied to U.S. actions but coincides with heightened scrutiny over AI chip exports to China. The investigation's implications extend beyond Singapore, potentially affecting the entire semiconductor supply chain and increasing pressure on major companies like Nvidia and Dell.

Exposing Confidential Data: Microsoft's Copilot Reaches Github Δ1.72

Microsoft's Copilot AI assistant has exposed the contents of over 20,000 private GitHub repositories from companies like Google and Intel. Despite these repositories being set to private, they remain accessible through Copilot due to its reliance on Bing's search engine cache. The issue highlights the vulnerability of private data in the digital age.

AMD Zen 6 CPUs Tipped to Arrive with up to 96 MB L3 Cache on Non-X3D Model Δ1.72

The potential launch of AMD's next-gen Zen 6 CPUs has shed new light on the company's plans for its upcoming processors, which could offer significant improvements over their current lineup. The leak suggests that some models may feature increased amounts of L3 cache, potentially allowing for more efficient processing and better performance in demanding applications. However, it remains to be seen how these changes will impact the overall user experience.

AMD Unveils Ryzen 9900X3D and 9950X3D CPUs with Enhanced Cache Δ1.72

The new Ryzen 9900X3D and 9950X3D CPUs from AMD combine the benefits of a higher cache size with those of standard CPU cores, promising improved performance for specific workloads. These X3D chips utilize a unique design that stacks extra cache under one of two CPU chiplets, allowing for more efficient handling of demanding applications. By leveraging this technology, AMD aims to enhance its competitiveness in the high-performance computing market.

AMD Accelerates Performance with New 9950X3D Chip Δ1.72

AMD's latest processor, the 16-core Ryzen 9 9950X3D, delivers impressive performance gains over its predecessor, with single-threaded performance rivaling that of non-X3D counterparts and a 14% lead in PassMark benchmarking. The chip boasts elevated clock speeds and higher power limits thanks to its integration of AMD's 2nd generation V-Cache technology. While the cache configuration remains largely unchanged, the new X3D architecture promises significant thermal headroom and performance boosts.

Counterfeit CPUs Sold on Amazon Put Tech Enthusiasts at Risk Δ1.72

Well-known hardware reviewers aren't immune to tech retail fakers, and to demonstrate this, Hardware Busters has shared images of a counterfeit AMD Ryzen 7 9800X3D and its packaging. Dealing with fakes seems to be part and parcel of being a tech enthusiast nowadays, but luckily Aris from Hardware Busters will very likely get his money back, via the returns process he has now begun on Amazon.de. The use of fake CPUs highlights the need for increased scrutiny when purchasing components online. Counterfeit parts can have serious consequences, including damage to motherboards and harm to consumers.

Advanced Cyber Threats on Network Devices Worry Global Internet Security Δ1.71

Sophisticated, advanced threats have been found lurking in the depths of the internet, compromising Cisco, ASUS, QNAP, and Synology devices. A previously-undocumented botnet, named PolarEdge, has been expanding around the world for more than a year, targeting a range of network devices. The botnet's goal is unknown at this time, but experts have warned that it poses a significant threat to global internet security.

Tech Giant Google Discloses Scale of AI-Generated Terrorism Content Complaints Δ1.71

Google has informed Australian authorities it received more than 250 complaints globally over nearly a year that its artificial intelligence software was used to make deepfake terrorism material, highlighting the growing concern about AI-generated harm. The tech giant also reported dozens of user reports warning about its AI program Gemini being used to create child abuse material. The disclosures underscore the need for better guardrails around AI technology to prevent such misuse.

Malware Hijacks Nearly 1 Million Windows Devices in Advanced Malvertising Attack Δ1.71

A broad overview of the four stages shows that nearly 1 million Windows devices were targeted by a sophisticated "malvertising" campaign, where malware was embedded in ads on popular streaming platforms. The malicious payload was hosted on platforms like GitHub and used Discord and Dropbox to spread, with infected devices losing login credentials, cryptocurrency, and other sensitive data. The attackers exploited browser files and cloud services like OneDrive to steal valuable information.

AMD's Zen 6-Based Desktop Processors May Feature Up to 24 Cores Δ1.71

AMD's anticipated Zen 6 processors are set to bring significant enhancements, including a new chiplet design that allows for up to 24 cores in desktop models while remaining compatible with the AM5 socket. Premium offerings will also incorporate 3D V-Cache, supporting gamers with improved performance metrics. The shift to 12-core chiplet dies marks a substantial transition from previous generations, positioning AMD to leverage advanced manufacturing processes in the coming years.

Servers Used in Singapore Fraud Case May Contain Nvidia Chips Δ1.71

The Singaporean government has revealed that servers involved in a recent fraud case may have contained Nvidia's advanced chips, supplied by U.S. firms Dell Technologies and Super Micro Computer before being sent to Malaysia. The move raises concerns about the potential misuse of these chips by the Chinese company DeepSeek, which was at the center of the alleged chip movement scandal. Authorities are now investigating the case independently, with Singapore asking the US authorities if the servers contained U.S. export control items.

Hackers Stole Engineer's Password Manager Database: A Nightmare Scenario Δ1.71

A software engineer for the Disney Company unwittingly downloaded malware on his computer that turned his life upside down. The malware gave outside attackers full access to his 1Password database and session cookies, allowing them to compromise his online accounts, including his employer's Slack channel. As a result, he lost his job after Disney's forensic examination reportedly showed that he had accessed pornographic material on his work laptop in violation of company policy.

Intel Unveils Its Most Powerful AI PCs Yet - New Intel Core Ultra Series 2 Processors Pack in vPro Features Δ1.70

Intel has introduced its Core Ultra Series 2 processors at MWC 2025, showcasing significant advancements in performance tailored for various workstations and laptops. With notable benchmarks indicating up to 2.84 times improvement over older models, the new processors are positioned to rejuvenate the PC market in 2025, particularly for performance-driven tasks. Additionally, the launch of the Intel Assured Supply Chain program aims to enhance procurement transparency for sensitive data handlers and government clients.

Quantum Computing Advantages Gain Traction with Amazon's Chip Lead Δ1.70

Amazon has unveiled its first-generation quantum computing chip called Ocelot, marking the company's entry into the growing field of quantum computing. The chip is designed to efficiently address errors and position Amazon well for tackling the next phase of quantum computing: scaling. By overcoming current limitations in bosonic error correction, Amazon aims to accelerate practical quantum computers.