Source code for the BIOS used with Intel's 12th-gen Core processors has been leaked online, possibly including details of undocumented model-specific registers (MSRs) and even the private signing key for Intel's Boot Guard security technology. . The source code was apparently shared via 4chan and GitHub, in a file containing tools and code for generating and optimizing BIOS/UEFI firmware images, plus related documentation. Word quickly spread to Twitter at the weekend, Alder Lake being the code-name for the x86 giant's 12th-gen desktop processors. The source code may reveal exploitable vulnerabilities in the firmware that miscreants could abuse in future on people's PCs. . Uncover the exposed Intel Alder Lake firmware source code, highlighting possible vulnerabilities and hidden functionalities.. Intel BIOS Leak, Alder Lake Security Threats, Firmware Exploits. . LinuxSecurity.com Team
Macs older than a year are vulnerable to exploits that remotely overwrite the firmware that boots up the machine, a feat that allows attackers to control vulnerable devices from the very first instruction. . The attack, according to a blog post published Friday by well-known OS X security researcher Pedro Vilaca, affects Macs shipped prior to the middle of 2014 that are allowed to go into sleep mode. He found a way to reflash a Mac's BIOS using functionality contained in userland, which is the part of an operating system where installed applications and drivers are executed. By exploiting vulnerabilities such as those regularly found in Safari and other Web browsers, attackers can install malicious firmware that survives hard drive reformatting and reinstallation of the operating system.. Older Mac models face increased risks from firmware exploits due to outdated software and lack of updates, enabling remote attacks and data breaches. Mac Security,Firmware Exploits,Remote Control Attacks,OS X Vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.