Breaking News

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards Sony Unveils 1000X THE COLLEXION Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Say Apple Macs and PCs at Risk From Boot Bug

Researchers Say Apple Macs and PCs at Risk From Boot Bug

PC components Sep 29,2017 0

Apple Mac computers are being exposed to security risks because their extensible firmware interface (EFI) core software is outdated, research suggests.

Duo Security found that 4.2% of the 74,000 Macs it tested ran insecure versions of software that helps get the machines running. It said the figure was likely to be replicated in the global population of Macs and worse on PCs.

EFI is the pre-boot environment that has, by and large, replaced the legacy BIOS environment that had been common since the mid to late 1970s.

EFI environment holds particular fascination for security researchers and attackers due to the level of privilege it affords if compromise is successful. In a nutshell, attacking at the EFI layer means that you exert control of a system at a level that allows you to circumvent security controls put in place at higher levels, including the security mechanisms of the OS and applications.

In addition to the ability to circumvent higher level security controls, attacking EFI also makes the adversary very stealthy and hard to detect; it also makes the adversary very difficult to remove - installing a new OS or even replacing the hard disk entirely is not enough to dislodge them.

Duo Security analysed all Apple Mac updates released over the last three years (10.10.0 - 10.12.6) to produce a taxonomy of EFI updates that were contained within the larger OS and Security updates released by Apple.

Duo surveyed 74,000 Mac computers operating in the real world and found that 4.2 percent of them were not running the firmware they should have been based on their operating system. In some models - such as the 21.5-inch iMac released in late 2015 - 43 percent of machines had out-of-date firmware.

That left many Macs open to hacks like the 'Thunderstrike' attack, where hackers can control a Mac after plugging an Ethernet adapter into the machine's so-called thunderbolt port.

Duo said that it had informed Apple of its findings before making them public on Friday. Apple said it was aware of the issue and is moving to address it.

Tags:
Previous Post
Nintendo Closes the Wii Shop
Next Post
TSMC to Build 3nm Fab in Taiwan

Related Posts

Latest News

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards
GPUs

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards

COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards
PC components

COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards

Sony Unveils 1000X THE COLLEXION
Consumer Electronics

Sony Unveils 1000X THE COLLEXION

Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors
Enterprise & IT

Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor
Consumer Electronics

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed