UEFI firmware vulnerabilities affect tech vendors including Intel and Fujitsu

clock • 3 min read
Malware injected into a UEFI memory chip can survive reboots, formats and OS reinstalls, enabling threat actors to maintain their presence on compromised machines
Image:

Malware injected into a UEFI memory chip can survive reboots, formats and OS reinstalls, enabling threat actors to maintain their presence on compromised machines

Millions of enterprise devices could be impacted

Researchers at firmware security firm Binarly have discovered nearly two dozen vulnerabilities in the InsydeH2O UEFI firmware, which several major enterprise vendor ecosystems use. The 23 high-s...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Microsoft, Dell and Lenovo laptops vulnerable to Windows Hello authentication flaw

Threats and Risks

Researchers employed reverse engineering techniques on both software and hardware

clock 27 November 2023 • 2 min read
Interview: Jason Daniels, Fujitsu UK, UK IT Industry Awards finalist

Leadership

'We believe that enhancing customer experience through a digital-first service powered by a combination of human expertise, analytics and AI capabilities is essential for success in today's digital landscape'

clock 27 October 2023 • 3 min read
Three zero-days addressed in October 2023 Patch Tuesday

Threats and Risks

'Critical' rating assigned to twelve bugs

clock 11 October 2023 • 3 min read

More on Threats and Risks

Google rushes out patch for Chrome zero-day with exploit available in the wild

Google rushes out patch for Chrome zero-day with exploit available in the wild

Other Chromium-based browsers are also vulnerable to the flaw in the Skia graphics library

clock 30 November 2023 • 3 min read
18,000 customers at risk of phishing attacks after security firm Otka hacked

Customers at risk of phishing attacks after hack, Okta warns

Software security firm Otka has warned that some of its 18,000 corporate and government customers have been left vulnerable to phishing attacks after hackers broke into its computer systems a month ago.

clock 30 November 2023 • 1 min read
Microsoft, Dell and Lenovo laptops vulnerable to Windows Hello authentication flaw

Microsoft, Dell and Lenovo laptops vulnerable to Windows Hello authentication flaw

Researchers employed reverse engineering techniques on both software and hardware

clock 27 November 2023 • 2 min read