Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

ALERT: Meltdown/Spectre Hardware Vulnerability Requires Action

ALERT: Meltdown/Spectre Hardware Vulnerability Requires Action

Just a few months after finding themselves in a firmware fiasco, Intel is making news for all the wrong reasons. This issue had the potential to affect the CPU of a device, causing a severe dip in the performance of the device.

In a blog post by a user going by the name Python Sweetness, an issue was reported, describing “an embargoed security bug impacting apparently all contemporary CPU architectures that implement virtual memory, requiring hardware changes to fully resolve.” This means that, thanks to this bug, the interactions that different programs would have with the CPU would be affected.

Under normal circumstances, a CPU will have two modes that it operates under: kernel, which permits the user to make changes to the computer itself, and user, which is considered a ‘safe’ mode. Python Sweetness discovered a bug that blurred the distinction between the two modes. The bug allowed programs run in user mode to also access kernel mode, possibly allowing malware to access the computer’s hardware.

However, the circumstances have proven to be less dire than they originally appeared. The expectation was that this bug would cause entire processes to shift back and forth between user and kernel mode, hamstringing the speed at which the device would operate. There was also the expectation that this issue would not be able to be resolved without a hardware change.

For PCs with Windows 10 installed and an antivirus that supports the patch, the fix should already be in place. However, to confirm this, go to Settings > Update & Security to see if there are any updates waiting to be installed. If not, check your update history for Security Update for Windows (KB4056892) or check with your antivirus provider to find out when it will be supported, the patch will not install until it sees that the antivirus has been updated to a version that the vendor verifies supports this patch.

Android devices had an update pushed on January 5 to provide some mitigations, with more protections coming in later updates. These patches have already been pushed to Google-branded phones, like the Nexus and Pixel lines, and may have been on other Android devices. It doesn’t hurt to check, and if you haven’t been updated, go online and put pressure on your carrier on a public forum.

Google Chrome should be updated with similar mitigations on January 23, with other browsers updating soon after. To help protect yourself until then, have your IT team activate Site Isolation to minimize the chance of a malicious site accessing data from another browser tab.

Other devices (like NAS devices, smart appliances, networking equipment, media equipment, etc.) may also be at risk, as they are using similar hardware. It’s really important for business owners to have their entire infrastructure reviewed and audited.

These kinds of issues help to demonstrate the value of an MSP’s, or managed service provider’s, services. MSPs like Total Tech Care are sure to keep themselves informed on the latest developments in IT security and any resolutions they can pass on to businesses like yours, if they don’t implement them on your behalf.

As a result, you and the rest of your team can go about your business without having to concern yourself with solving issues like these, knowing that you can trust the team who is solving it for you. For more ways that an MSP can help keep your business security and operations optimized, reach out to Total Tech Care at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 23 November 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Google Business Network Security Internet Microsoft Email Malware Backup Workplace Tips Innovation Data User Tips Computer Mobile Devices Hardware IT Services Android VoIP Disaster Recovery communications IT Support Smartphones Communication Business Continuity Miscellaneous Smartphone Mobile Device Browser Small Business Network Collaboration Productivity Cybersecurity Quick Tips Business Management Users Managed IT Services Phishing Upgrade Windows Ransomware Data Backup Outsourced IT Windows 10 Server Save Money Data Recovery Office Cloud Computing Windows 10 Passwords Chrome Gadgets Virtualization Tech Term Social Media Saving Money Holiday Managed IT Services Microsoft Office Managed Service Automation Operating System Artificial Intelligence Computers Facebook Cybercrime Hacking Internet of Things Wi-Fi BYOD Mobile Device Management Health Networking IT Support Managed Service Provider Spam Covid-19 Information Office 365 Alert Telephone Systems Information Technology Remote BDR Social Engineering Mobility Recovery Employer-Employee Relationship Bandwidth Router Remote Monitoring Law Enforcement Big Data Data Breach App History Password Mobile Computing Money Application Encryption Applications Human Resources Government Blockchain Mobile Office Paperless Office Private Cloud Managed IT Office Tips Training Apps How To VPN Data Storage Remote Computing Patch Management Vulnerability Mouse Windows 7 Avoiding Downtime HaaS Word Servers Flexibility Infrastructure Voice over Internet Protocol Bring Your Own Device Marketing Data Management Wireless Work/Life Balance WiFi Data Security IT solutions Entertainment Gmail Website Budget Settings Google Drive Two-factor Authentication Vendor Social Managed Services Scam Display User Error Telephone System Staff Software as a Service Meetings Machine Learning Vendor Management Employee/Employer Relationship Connectivity Remote Work Save Time RMM Risk Management Hacker Cleaning The Internet of Things Lithium-ion battery USB End of Support Data Protection Physical Security Education Firewall Safety HIPAA Sports Virtual Reality Redundancy Apple Keyboard Conferencing Network Congestion Access Control Business Intelligence Best Practice eWaste Database Virtual Assistant YouTube Remote Workers Worker Authentication Audit Black Market IT Management Processor Botnet Document Management IT Plan Wearable Technology Retail Hard Drives Solid State Drive Update Wireless Technology Hard Drive Downtime Virus Instant Messaging How to Excel Unsupported Software Robot Google Docs Unified Threat Management Identity Theft Data storage Computer Accessories Computing Charger Biometrics Automobile Virtual Desktop Compliance OneNote Computer Care Computing Infrastructure Current Events DDoS Augmented Reality Telephony Going Green Fraud Printer Samsung SharePoint Digital Signage Bluetooth Remote Worker Value Battery Cryptocurrency Shadow IT Customer Service Electronic Medical Records Environment Legal Spam Blocking Procurement Workplace Strategy Net Neutrality IT Consultant Internet Exlporer Fax Server Hiring/Firing Help Desk Comparison Printing CES PDF Humor SaaS Business Technology Content Management Proactive IT Managed Services Provider Batteries Printers Bloatware Tools Video Games Consultant Monitoring Millennials Windows 8.1 Wireless Charging Analytics Digitize Television Smart Office Worker Commute Experience Tablets Windows Server 2008 R2 Virtual Private Network Entrepreneur Scalability Best Available Customer relationships Workforce WIndows 7 Email Best Practices Cables IT Assessment Public Computer Manufacturing Business Owner Shortcut Regulations NarrowBand Transportation Managed IT Service Rootkit Security Cameras Project Management Cost Management Nanotechnology Search Computer Tips Telecommuting Computer Fan Virtual CIO Cortana iPhone OneDrive Biometric Security Social Networking Digital Signature Peripheral Workers Benefits Using Data Warranty Digital Security Cameras FENG HVAC User Google Apps Files PowerPoint Copiers IBM Windows Media Player Running Cable 5G Memory Analysis Flash Quick Tip Chromecast Smart Technology Smartwatch Administrator Devices Ergonomics Enterprise Content Management Managing Stress Software Tips Colocation Development Supercomputer Uninterrupted Power Supply OLED MSP Accountants Sync PCI DSS Emails Virtual Machine Credit Cards Monitor Cameras Fiber Optics Employee Microchip Thought Leadership 2FA Password Management Science Password Manager Messaging Cabling Two Factor Authentication Policy Multi-Factor Security Netflix Hypervisor Root Cause Analysis Reputation Trend Micro Streaming Media Search Engine Twitter Dark mode NIST Content Business Mangement HBO SMS Knowledge Tech Support Distributed Denial of Service Default App Music Customer Relationship Management Analyitcs Smart Tech Skype Techology Procedure Trending Laptop Saving Time Amazon Data loss Customers Printer Server Shopping Google Search Programming Addiction dark theme Audiobook Recycling Outlook AI Leadership IT Infrastructure Troubleshooting Bing Wiring Practices Start Menu FinTech Touchpad Amazon Web Services Screen Mirroring Social Network Loyalty Antivirus Cache Safe Mode Politics Windows 8 Criminal Frequently Asked Questions Advertising Investment Books Employee/Employer Relationships IT service GDPR Hosted Computing Mobile Employees Windows 10s Windows 365 Online Shopping Cast Notifications ISP Wireless Internet File Sharing Tablet Tip of the week Video Conferencing webinar ROI Emergency Bitcoin Employer Employee Relationship Domains Shortcuts Camera Inventory Professional Services Sales Specifications Public Cloud Point of Sale Evernote Relocation Personal Assessment Cryptomining Wire Maintenance Windows Server 2008 Supply Chain Management Travel IaaS

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code