However, there is no need to panic. OpenSSL, a widely used encrypted library on the Internet (more than 60%) has just released a patch to prevent access via this direct method. They also said the general patch will soon be released, but security researchers say the hardware or BIOS also needs to take action.
They announced the vulnerability to Intel on October 1, but Intel did not agree, saying that encrypted libraries such as OpenSSL must prevent these security flaws themselves. AMD is considering its role in this regard.
On GitHub, there is also PoC if you want to try using PortSmash, it can steal the private key P-384 OpenSSL from TLS server running OpenSSl software which has not been upgraded to version 1.1.1
See more:
Updating Windows 10 in the future will help the machine run faster by patching Specter
Foreshadow - the fifth most serious security hole in the CPU in 2018
multi-factor authentication (mfa) elevates cybersecurity standards by requiring users to prove their identity in multiple ways before accessing the network.
although microsoft releases patches for windows vulnerabilities on a monthly basis, there are still security issues that remain. recently, the us cybersecurity and infrastructure agency (cisa) reported a critical vulnerability in the windows print spooler system.
the venom vulnerability affects all major cpu vendors, including intel, amd, and arm. venom allows malicious actors to read the contents of a computer's memory and potentially execute code remotely.
how to exploit a critical zero-day vulnerability in the java-based apache log4j logging library has just been posted on the internet. this leaves users and businesses as well as organizations vulnerable to remote code execution attacks.
security researchers have found a vulnerability in the microsoft windows platform binary table (wpbt). this vulnerability can be exploited by hackers to install rootkits on all windows computers shipped from 2012 to the present.
when downloading large files, it is worth using a download manager like persepolis. with multi-threaded support, persepolis allows you to download files at the maximum speed that the connection allows.
spring has just released an urgent update to patch the spring4shell remote code execution zero-day vulnerability. information about this vulnerability was leaked on the internet before the patch was released.
the ryzen 5 3600x lacks integrated graphics, but in return it is multithreaded and overclockable, two features that some intel competitors lack. this is a great option for a gaming pc.
if you've been following recent windows security news, you may have heard of printnightmare. this is a vulnerability that allows hackers to exploit your system and run malicious code on it.