Meltdown and Spectre Vulnerabilities Still Haunting Computers
In 2018, computer researchers found out that the main chip in most computers—the CPU—has a hardware bug. According to Geekblog, "defects can originate during chip design, manufacturing, or even develop later due to aging or environmental factors." It's really a design flaw in the hardware that could have been there for years. This is a big deal because it affects almost every computer worldwide, including all workstations and servers. This hardware bug allows malicious programs to steal data that is being processed in your computer memory. Normally, applications are not able to do that because they are isolated from each other and the operating system.
This hardware bug breaks that isolation.
So, if the bad guys are able to get malicious software running on your computer, they can get access to your passwords stored in a password manager or browser, your emails, instant messages and even business-critical documents. Not good. While Meltdown and Spectre were first disclosed in 2018, Spectre alone is estimated to affect virtually all pre-2019 processors that use speculative execution, highlighting just how widespread these hardware vulnerabilities have been. To prevent this, you need a trusted IT partner who can quickly patch vulnerable systems, monitor emerging threats, and replace older machines that can’t be secured.
This article covers:
What you should do now?
Be extra vigilant, with security top of mind and “Think Before You Click” as Phishing through email is still the most common vector for malware to compromise your systems.
For our Managed and Hosted Services customers, we have already begun the process of updating and patching all PCs and servers that we manage. This is going to take some time, as patches for some devices are not even available yet. We also may recommend that you replace some older mission-critical computers to fix this as there are no patches for these older systems and none are planned. For some of these legacy systems, this may be your only alternative.
Best Practices
- If it looks suspicious...
- Don't CLICK it
- Don't OPEN it
- Don't ALLOW ACCESS
- Maintain a strong password policy
- Keep business networks secure
- Anti-Virus installed on all machines
- Anti-Spam solution implemented and utilized
- Maintain regular backups
- Save key data to shares or offline backups, not locally
-
Update/Patch your Operating Systems regularly (This includes all devices, computers, servers, network equipment, phones, medical devices, etc.)
Centre's Secure Managed Services (SMS) provides a layered cybersecurity approach that helps protect your business from today's evolving threats. By combining advanced security technologies, 24x7 monitoring, and expert management, SMS safeguards your users, devices, and data. This includes Employee Security Awareness Training to help staff recognize and avoid cyber threats, Endpoint Detection and Response (EDR) to detect and contain suspicious activity on endpoints, and a range of additional security solutions designed to strengthen your overall security posture, reduce risk, and improve resilience against cyberattacks.