Researchers find uefi rootkit that is actively being abused

Published by

Click here to post a comment for Researchers find uefi rootkit that is actively being abused on our message forum
https://forums.guru3d.com/data/avatars/m/243/243189.jpg
I feel like this should be bigger news than it currently is. Will this also predispose those pc's to spectre type exploits?
https://forums.guru3d.com/data/avatars/m/242/242471.jpg
Like in article, every modern uefi mobo has secure boot, double check if it's enabled and you're good to go. My mobo has this option ( z87 chipset) and it's been enabled by default, although it's old now 2014, but I guess as long as it's enabled I'm good. Spectre is sw level in windows or by some just a small hw layer in bios not connected to secure boot.
https://forums.guru3d.com/data/avatars/m/243/243189.jpg
I was thinking more from the point of view of lots of government and health system computers being old and poorly maintained from a security and update point of view, and how malware might be used with these exploits (now having been revealed) to harvest some details and wreck havoc. Spectre came to mind because of variant 2 needing a firmware fix, and how this might undermine that, but I might be mistaken here.
https://forums.guru3d.com/data/avatars/m/258/258589.jpg
I've enabled it now, thanks for letting us know. This doesn't impact performance? From what I've seen on Google, it doesn't. It's not even in effect anymore after you're booted.
https://forums.guru3d.com/data/avatars/m/220/220188.jpg
why isnt there a mobo jumper to disable writing to fw, make that standard and off by default and this problem wont ever be mentioned again
https://forums.guru3d.com/data/avatars/m/272/272918.jpg
EspHack:

why isnt there a mobo jumper to disable writing to fw, make that standard and off by default and this problem wont ever be mentioned again
There are a lot of motherboards that already do have a write protect jumper