Tag Archive for Intel

UEFI Malware: The Silent Threat to Your PC

UEFI Malware: The Silent Threat to Your PCHackers have been compromising PCs with UEFI malware and your anti-virus software doesn’t know it. Cybersecurity firm Eclypsium has detected an ongoing campaign that targets motherboards manufactured by Taiwan based Gigabyte Technologies (2376). The attacks use a hidden backdoor installed by Gigabyte which is being exploited by attackers.

millions of Gigabyte motherboardsThe flaw impacts up to millions of Gigabyte motherboards. The flaw goes back to the AMD 400-series chipsets up to the latest Intel 700-series or AMD 600-series motherboards. Eclypsium found that every time a computer with an affected Gigabyte motherboard (PDF) restarts, its firmware silently runs an update program which downloads and launches another piece of software. While this is meant to keep your PC hardware up to date, Eclypsium says the hidden code implemented insecurely, it can use an HTTP connection, potentially allowing the mechanism to be hijacked and used to install malware instead of Gigabyte’s intended program.

Because the updater program is triggered from the computer’s UEFI firmware, it loads before Windows loads, making it difficult to detect or remove. UEFI stands for Unified Extensible Firmware Interface, and it is the software that runs before the operating system starts. By running before the operating system, any planted malware can bypass security mechanisms such as Secure Boot and antivirus scans. UEFI malware can also persist across operating system reinstalls or hard drive replacements, making it difficult to detect and remove.

How to determine if your PC has UEFI malware

There are a few steps you can take to check for signs of infection:

  1. Use the command prompt to check the motherboard model. Open the Command Prompt from the Start Menu, and type in:
wmic baseboard get product,Manufacturer

Windows will return the manufacturer and Product.

Command prompt

2. If the command prompt freaks you out, you can use the Windows GUI to find you motherboard’s manufacturer. From the Start menu type “System Information” into the search bar and bring up the System Information app.

System information
The System Information page will display. BaseBoard Manufacturer is the motherboard manufacturer, and BaseBoard Product is the name of the motherboard.



3.If neither of these options work, you can try a 3rd party utility. HWInfo, and CPU-Z are popular 3rd party tools that can determine the manufacturer of your motherboard.

What to look for

Some UEFI malware may cause noticeable changes in your system performance, stability, or functionality. For example, you may experience frequent crashes, blue screens, boot errors, slow boot times, missing files, network issues, or unexpected pop-ups. These symptoms may also be caused by other factors, so they are not conclusive evidence of infection, but they can be indicators that something is wrong.

What to do if you have UEFI malware

If you suspect that your PC has UEFI malware, you should take immediate action to remove it and prevent further damage. The best way to do this is to reset or reflash the firmware using a trusted source from your device manufacturer. This will overwrite the malicious code and restore the original firmware. However, this process can be risky and complex, and it may require physical access to the device or special tools. You should carefully follow the instructions from your device manufacturer and back up your data before attempting this procedure.

How do I prevent UEFI malware?

The first step is to dig into you BIOS and set a BIOS password. This will help prevent any future changes without your knowledge. If getting into the BIOS makes you nervous, you can use software.

Some antivirus systems include a UEFI scanner. For example, Microsoft Defender ATP has a UEFI scanner that brings its protection capabilities to the firmware level. Another example is Kaspersky Anti-Virus for UEFI (KUEFI) Kaspersky says KUEFI provides effective protection from rootkits and bootkits and ensures safe OS loading.

These tools detect a threat, they will alert you and provide instructions on how to repair the firmware. However, not all antivirus programs have this feature, and some UEFI malware may evade detection by hiding or encrypting itself.

Gigabyte has released an update to close the hole.

rb-

UEFI malware can compromise your system security and privacy. To protect yourself from this type of attack, you should:

  1. Keep your firmware and operating system updated with the latest patches and security fixes.
  2. Use a reliable antivirus program that can scan and protect your firmware as well as your files.
  3. Avoid opening suspicious attachments or links from unknown sources.
  4. Be careful when downloading or installing software from untrusted websites.

How you can help Ukraine!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

10 More Times McAfee Was in the Spotlight

Updated – 06/24/2021 – John McAfee was found dead in a Spanish jail on 06/23/2021 from an apparent suicide. The Guardian reports his body was found hours after Spain’s highest court approved his extradition to the United States. Mr. McAfee faced federal criminal charges for tax evasion. The charges carried a prison sentence of up to 30 years.

Updated – 10/26/2020McAfee’s second IPO did not go as planned. IPO shares of MCFE were pegged to open at $20.00 per share. It was only able to hit a high of $19.50 per share. Barron’s called the McAfee IPO “a broken deal.”

10 More Times McAfee Was in the SpotlightFollowers of the Bach Seat still recognize the name, McAfee. John McAfee founded the anti-malware company McAfee Associates in 1987. By 1994, he’d been forced out after telling everyone that the Michelangelo Virus was going to smash up the world’s computers on March 6, 1992. It didn’t. He looked stupid.  McAfee Associates debuted on Nasdaq in October 1992. Even today, McAfee anti-malware still protects 500 million people’s computers. 

McAfee anti malwareMcAfee was bought by Intel in August 2010 for $7.6 billion. Intel (INTC) had hoped to integrate security into the company’s chips. Intel renamed McAfee – Intel Security in January 2014. Intel lost interest in running the cybersecurity company and in September 2016 sold 51% of the security firm for $4.2 billion to VC’s TPG Global, LLC, and Thoma Bravo. The VCs resurrected the McAfee brand and filed to go public in September 2020.

Now Mr. McAfee is back in the news too. The former 2016 and 2020 Libertarian Party candidate for U.S. president was arrested at the Barcelona airport, boarding a flight to Istanbul with a British passport. He is awaiting extradition to the U.S. on federal charges, including anti-fraud provisions and tax evasion.

Uncle Sam wants youThe U.S. Department of Justice and the Securities and Exchange Commission filed criminal charges against him. The DOJ has charged with tax evasion they claim Mr. McAfee did not file tax returns between 2014 and 2018. McAfee was said to have received up to $23 million in compensation in the form of tokens, ethereum, and bitcoin. The SEC has accused McAfee and his bodyguard, Jimmy Watson Jr., of “illegally promoting initial coin offerings (ICOs).

The SEC maintains that “McAfee promoted multiple ICOs on Twitter, allegedly pretending to be impartial and independent even though he was paid more than $23 million in digital assets … denied receiving any compensation from the issuers … McAfee made other false and misleading statements … he had personally invested in some of the ICOs and that he was advising certain issuers.

CryptocurrencyThe SEC complaint against Mr. Watson alleges that he, “assisted Mr. McAfee by negotiating the promotion deals with the ICO issuers, helping Mr. McAfee cash out the digital asset payments for the promotions and … having his then-spouse tweet interest in the ICO. Mr. Watson was allegedly paid at least $316,000 for his role .. investors were left holding digital assets that are now essentially worthless.

This is not McAfee’s first time in the spotlight.

1 – April 2012 – Mr. McAfee’s compound in Belize, was raided by the Belize Police Gang Suppression Unit on suspicion it was a front for making meth. Police discovered an arsenal of weapons and a drug lab that he apparently used in an attempt to purify MDPV, a drug that’s said to enhance sexual pleasure.

John McAfee2 – November 2012 –  Mr. McAfee was wanted by Belize Police for questioning in the murder of his neighbor, American expatriate Gregory Faull, 52. He refused to speak with authorities about the case, making him a fugitive in the eyes of Belize authorities. He disappeared for a month.

3 – December 2012 –  Mr. McAfee was arrested in Guatemala for illegally crossing the border from Belize in an attempt to find asylum from police in Belize. He was about to be deported back to Belize when he faked a heart attack, telling ABC News “Sure, I faked it … What would you have done?” His attorney was able to obtain a stay of deportation to Belize for him and Guatemalan authorities deported him to Miami.

4 – June 2013 – Mr. McAfee released an NSFW video on YouTube slamming the McAfee product.

5 – November 2013 – Mr. Faull’s family filed a wrongful death suit against Mr. McAfee. In June 2018 a Florida court issued a default ruling against (PDF). The court ordered Mr. McAfee to pay the Faull family more than $25 million.

under the influence.6 – August 2015 – Mr. McAfee was arrested by the Tennessee Highway Patrol. He was arrested for DUI and possession of a handgun while under the influence. McAfee blamed Xanax. He told CNBC, “I had just that morning received a prescription for Xanax from a doctor, I’d never taken them before.” 

7 – May 2016 – He was appointed chief executive chairman of MGT Capital Investments. The penny stock mobile gaming company became a “technology company” under McAfee. MGT surged more than 1,200% after the announcement it would transform into a cybersecurity company led by John McAfee. MGT changed its name to John McAfee Global Technologies, Inc.  

Bitcoin miningIt was then when McAfee decided to move to the mining of bitcoin and cryptocurrencies. He said that this would help MGT to increase their funds as well as their expertise in dealing with blockchains. Resulting in an SEC subpoena and stock crash and delisting from the NYSE.

8 – July 2017 – Mr. McAfee in full cryptocurrency hucksterism mode tweeted about how cryptocurrencies like Tron (TRX), Verge (XVG) and Reddcoin (RDD) could revolutionize the world. He even promised to do something NSFW to himself if cryptocoin Bitcoin (BTC) didn’t hit $500K within three years.

9 – Mr. McAfee taunted U.S. regulators – January 2019 he tweeted he hasn’t filed a tax return for eight years because “taxation is illegal.” June 2019  – He tweeted from Cuba –  promoting BeatzCoin (BTZC) – “Yes SEC, I’m promoting. Fucking come and get me.

10 – July 2019 –  The Dominican Republic military arrested Mr. McAfee and associates in Puerto Plata after they found several large-caliber weapons without proper documentation. He was deported to London. After landing in London he asked his Twitter followers whether he should also campaign to be British prime minister.

rb-

John McAfee had $100 million when he left McAfee. Now he broke, paranoid, and a tax dodger. Sound like a good candidate for U.S. President.

What next? Prison? Up to 30 years if DOJ has its way. The SEC, wants him to pay back his profits and to ban him from serving as an officer or director to any company that sells securities.  Let’s see if he can worm his way out of this.

 

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Symantec Sold

Updated 01/08/2020 – Broadcom is selling off parts Symantec less than 2 months after closing the deal. Reports have consulting giant Accenture buying Symantec’s Cyber Security Services unit for an undisclosed amount.

Under the deal, Accenture will take over Symantec’s global network of six security operations centers located in the U.S., the U.K., India, Australia, Singapore, and Japan. The SOC’s provide threat monitoring, analysis, and incident response services. Accenture says it will use the Symantec business unit to boost its managed security services.

Updated 09/17/2019 – As predicted below, Symantec has started slashing jobs. According to reports, up to 230 Symantec employees will be terminated on October 15, 2019.

Symantec SoldI could have saved a bunch of people a bunch of money– IF you had read this post – you would already have a doubt about this deal – before professional prognosticators Forester said the same thing on August 9th. In their report analyzing the deal, the market researcher cited Intel’s 2010 acquisition of McAfee and subsequent $3 billion loss spinning the security company to private equity in 2016. They said the deal should serve as a warning to CISO’s about the future of Symantec’s product portfolio under Broadcom. Well NO DUH

Broadcom (AVGO) has acquired Symantec‘s (SYMC) enterprise security business for $10.7 billion in cash. The two firms consummated their hot-and-cold bromance M&A discussions in writing today (08/08/2018).

Symantec logoThe deal is expected to bring in over $2 billion in annual revenue for the San Jose, CA-base firm. Broadcom intends to fund the transaction with proceeds from new committed debt financing. The transaction is expected to close in Q1 of Broadcom’s fiscal year 2020.

Broadcom, historically a semiconductor business has been on an M&A tear in the past few years, buying its way into a broader market position. First, with the 2016 – $5.9 billion purchase of network equipment vendor Brocade. Next was the 2018 – $18.9 billion acquisition of CA Technologies. Followed by today’s $10.7 billion pick-up of Symantec. In the presser Broadcom CEO Hock Tan called the Symantec purchase, “... the next logical step in our strategy … expanding our footprint of mission-critical infrastructure software within our core Global 2000 customer base.

Broadcom logoRumors of the purchase first appeared in the press on July 03, 2019, with “advanced talks” happening on July 15th for purchase all of Symantec for $22 Billion, but by July 15, Symantec had reportedly walked away from the table. Reports (which appear to be true) at the time were that Broadcom was after just the enterprise-cybersecurity software business; leaving the consumer the business as an independent company or a spin-off to somebody else.

ChannelE2E says the potential deal makes sense on paper. Broadcom is known for acquiring struggling or slow-growth enterprise technology businesses, stripping out costs and boosting profitability. They explain that Broadcom’s secret to M&A success is clearly communicating staff reduction plans to acquired businesses, investors, and associated end customers. Broadcom is known for swift M&A staff cuts that include reasonable severance packages for employees — rather than long, drawn-out, torturous headcount reductions.

ChannelE2E also correctly predicted the Symantec team could face job cuts, layoffs, or potential business spin-offs as a result of the deal. Right on queue, Symantec announced layoffs of roughly 7% of its more than 11,000 employees during FY 2020. The company also plans to downsize, vacate or close certain facilities and data centers in connection with the restructuring plan.

The Symantec name will be sold to Broadcom as part of the transaction. Interim Symantec CEO Rick Hill said the remaining consumer business contributed 90% of the company’s total operating income, and the company expects to be able to continue to grow revenue for its Norton LifeLock business in the mid-single digits going forward. CEO Hill tried to spin the sale as a win in a presser.

This is a transformative transaction that should maximize immediate value to our shareholders while maintaining ownership in a pure play consumer cyber safety business with predictability, growth and strong consistent profitability.

Symantec SoldSymantec’s struggles in recent years which may have lead to the buy-out are chronicled by Channele2e. Former CEO Greg Clark resigned in May 2019 amid weak enterprise cybersecurity software revenues. Executive team departures over the past year have also included Symantec’s CFO, chief operating officer, chief marketing officer and the head of its go-to-market teams. Board member Rick Hill has been interim president and CEO of the company since that time.

Symantec was late to cloud-and mobile-centric cybersecurity services, and faced intense competition from next-generation endpoint protection providers, including:

rb-

Deja Vu All Over Again

Deja Vu All Over Again

The sense of deja-vu all over again you are experiencing is real. Intel and McAfee tried this nearly a decade ago. Intel purchased top Symantec competitor McAfee for $7.7 billion. The expected “synergies” (WTF that means) never materialized. Intel ended up spinning off McAfee to private equity firm TPG in a 2016 sale that valued the business at $4.2 billion.

Related Posts

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Holy Sell Out Batman

Batman is being used to pump 5GThe Caped Crusader has sold out. While the full benefits of next-generation wireless – 5G won’t be realized until at least mid-2020, Batman is being used to pimp 5G.  AT&T used The guardian of Gotham to create demand for mixed-reality at last month’s Mobile World Congress in Barcelona Spain. The mixed-reality experience featured DC Comics Batman and the Scarecrow battling it out on the MWC show floor.

Fierce Videoaugmented reality headset reports that AT&T (T), Ericsson (ERIC), Intel (INTC), and Warner Bros., with DC, are using 5G technology and edge computing to build a location-based mixed-reality experience. For the walk-in experience at MWC, visitors put on an augmented reality headset. There they witnessed a 2 to 3-minute experience.

Ade Kushimo, director of business development, IoT, and emerging business at Ericsson told Fierce Video, “The really cool part of the experience is going to be the fact that you have this virtual, digital content being embedded into your physical space. That gives you that mixed reality experience.

Sensorama (patented 1962) which was an arcade-style theatre cabinet that would stimulate all the senses, not just sight and sound.

Mixed reality experience with Batman

Doug Matheson, vice president of strategic business development at Ericsson, said the proof-of-concept experience demonstrated that 5G technology (both radio and core) could be combined with intellectual property to create a mixed reality experience that’s both mobile and untethered.

In order to create a good mixed-reality experience, image lag has to be kept to a minimum. Image lag will make you dizzy and ruin the experience. That means that compute power has to be pushed out to the edge of the network to reside closer to the end-user. The compute power needed to process a mixed reality experience can’t live in a centralized data center somewhere.

Cloud computingThe cloud and edge network architecture allows for heavy computing to be done away from the device. So, the goal is to shift processing to the cloud and transport it there using a 5G network. The Batman demo ran on a fully integrated 5G network using Ericsson radio base stations 5G network technology will help supply the lower latency and higher speeds and enabled by Intel Xeon processors and the Intel 5G mobile trial platform.

5G – What is it

rb-

Mobile Marketer says that 5G will have a huge impact on AT&T’s mobile network. Its data traffic has grown more than 470,000% since 2007, with video making up half of the mobile data. Video may expand its share of data traffic to more than 75% by 2022, according to the company’s estimates.

Batman now works for AT&T following its acquisition of Time Warner who owned Warner Brothers, which owned DC Comics, the home of Batman, Superman, Wonder Woman, Harley Quinn, the Joker, Lex Luthor, Oswald Cobblepot, and the Flash.

 

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Follow the Open Source Money

 Matt Asay at Infoworld recently pointed out some interesting data on who really contributes to open source. Wikipedia, the most well-known open-source project, defines open-source software as software whose source code is published and made available to the public, enabling anyone to copy, modify and redistribute the source code without paying royalties or fees. Open-source code can evolve through community cooperation. These communities include individual programmers as well as large companies.

Open sourceAdobe developer Fil Maj used the GitHub REST API to pull public profile information from GitHub users. The REST API is a low-bandwidth protocol used on the internet that allows two software programs to communicate with each other. Using the API, Mr. Maj collected the company field from all 2,060,011 GitHub user profiles who were active in 2017 (“active” meaning ten or more commits to public projects). Using that data, Mr. Maj was able to pull the total number of corporate contributors to GitHub, with results that might surprise you.

Here are the ranking of GitHub contributors, with their total number of employees actively contributing to open source projects on GitHub:

RankCompanyEmployees Contributing
1Microsoft4,550
2Google2,267
3Red Hat2,027
4IBM1,813
5Intel1,314
6Amazon.com881
7SAP747
8ThoughtWorks739
9Alibaba694
10GitHub676
11Facebook619
12Tencent605
13Pivotal591
14EPAM Systems585
15Baidu584
16Mozilla469
17Oracle455
18Unity Technologies414
19Uber388
20Yandex351
21Shopify345
22LinkedIn343
23Suse325
24ESRI324
25Apple292
26Salesforce.com291
27VMware271
28Adobe Systems270
29Andela259
30Cisco Systems233

The author points out, this is not a perfect measure, but it is a much richer, more accurate data set for figuring out total contributors for any company. Even with that caveat in mind, we end up with many more corporate open source contributors than previous data suggested.

Microsoft’s contributions to open source

Microsoft's contributions to open sourceThe new data shows Microsoft (MSFT) is the number 1 open source contributor. Redmond has twice the number of contributors compared to its next nearest competitor. Remember Steve Ballmer‘s developers! developers! developers! meltdown?  For those of us that were around when Mr. Ballmer, the Microsoft CEO called open source as a “cancer” and “anti-American,” this is a remarkable change of heart for MSFT.

Red Hat

Red Hat (RHT) Mr. Maj’s data puts the open source leader among the top contributors. Red Hat has dramatically fewer engineers on its payroll than Google (GOOG) or Microsoft. As such, it’s doubly impressive that Red Hat would place so highly. Pretty much every engineer in the company works on open-source projects.

Amazon

 

Amazon logoAmazon (AMZN) Often considered an open source ne’er-do-well, Amazon comes in at No. 6 in the rankings. AMZN has nearly 900 open source contributors on staff. The article points out that Amazon has perhaps not publicly led the open source effort in the same way as Google and Microsoft have, but it remains a strong contributor to the projects that feed its developer community.

China is a net consumer of open source

Chinese companies like Baidu, Tencent, and Alibaba, which have long been perceived to be net consumers of open source, actually contribute quite a bit according to the new data.

Legacy firms

Legacy firms like Intel (INTC), Oracle (ORCL), Adobe (ADBE), and Cisco (CSCO) rank among the top 30 open source contributors reports InfoWorld.

rb-

Color me suspicious, but have these firms really embraced open source. Have they just adapted their business model to usurp elements of open source to lay their proprietary code on top of it? This saves them the bother of writing new code and yet they can charge proprietary costs for software where they have reduced their development costs.

Tom Brady hanging high fiveAfter all, numbers don’t lie. Stats say that in 2014, half of the companies said they use open source in their product. Just one year later, the number grew to 78%. Consequently, as long as open source continues to enjoy its place in the sun, we should expect the Microsoft-open source bromance to continue.

Related article

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.