DHS, Apple push back on Bloomberg supply chain story

U.S. and British security agencies have backed statements by Apple and Amazon Web Services disputing an explosive news report claiming that Chinese intelligence agents planted malicious computer chips in equipment used by the tech giants. “[A]t this time we have no reason to doubt the statements from the companies named in the story,” the Department Homeland Security said on Saturday. That echoed a Friday statement from Britain’s National Cyber Security Centre, which said the agency had “no reason to doubt the detailed assessments made by AWS and Apple.” The blockbuster story from Bloomberg Businessweek claims that Chinese spies placed the tiny chips on server motherboards supplied by Super Micro Computing Inc., setting up a backdoor to some 30 companies, including Apple and AWS. Such a compromise would represent an espionage operation of staggering proportions. Apple, AWS, and Supermicro all responded with vigorous, detailed denials of key elements of the story. “At […]

The post DHS, Apple push back on Bloomberg supply chain story appeared first on Cyberscoop.

Continue reading DHS, Apple push back on Bloomberg supply chain story

IBM’s new Power9 chip was built for AI and machine learning

 In a world that requires increasing amounts of compute power to handle the resource-intensive demands of workloads like artificial intelligence and machine learning, IBM enters the fray with its latest generation Power chip, the Power9. The compa… Continue reading IBM’s new Power9 chip was built for AI and machine learning

Intel chip vulnerability gets quick patch in some products, longer timeline in others

Manufacturers of the millions of business PCs, laptops and servers using Intel chips with a newly discovered critical security vulnerability say they are working as fast as they can to distribute the fix to customers. But only two companies so far issued a timetable for rolling out patches, and the schedule already stretches deep into June, meaning many users will have to wait more than a month for a fix. In a statement sent Friday to CyberScoop, Intel said, “We have implemented and validated a firmware update to address the problem and we are collaborating with computer-makers to facilitate a rapid and smooth integration with their software.” The vulnerability, which the company reported May 1, allows an attacker to bypass the password protection on Intel’s special remote-administration firmware, known as Advanced Management Technology. AMT is firmware, meaning it runs on the microprocessor chip itself, beneath the operating system, completely bypassing any security precautions or software. Unless manufacturers ship products with […]

The post Intel chip vulnerability gets quick patch in some products, longer timeline in others appeared first on Cyberscoop.

Continue reading Intel chip vulnerability gets quick patch in some products, longer timeline in others

New DARPA program seeks cybersecurity through hardware design

Pentagon scientists say they could stop 40 percent of current cyberattacks by producing secure computer chips, and Friday they explain how to a closed-door meeting of government contractors. The System Security Integrated Through Hardware and firmware, or SSITH, program aims “to develop hardware design tools that provide security against hardware vulnerabilities that are exploited through software in [Defense Department] and commercial electronic systems,” according to a procurement announcement, called a BAA, from the Defense Advanced Research Projects Agency. The DARPA program seeks only paradigm-shifting research: “Innovative approaches that enable revolutionary advances in science, devices, or systems. Specifically excluded is research that primarily results in evolutionary improvements to the existing state of practice,” reads the BAA. The idea is to break what SSITH program manager Linton Salmon derisively refers to as the “patch and pray” cycle of fixing vulnerabilities through software updates, even when what’s ultimately being exploited is a security weakness in the hardware. “This […]

The post New DARPA program seeks cybersecurity through hardware design appeared first on Cyberscoop.

Continue reading New DARPA program seeks cybersecurity through hardware design

Cisco to acquire Leaba Semiconductor for $320 million as buying spree continues

Woman working on circuit board at factory. Cisco continued its buying spree today as it announced its intention to acquire Israeli chip designer Leaba Semiconductor for $320 million. Cisco sees this acquisition as a way to bolster its hardware catalog with highly advanced chip technology. “By combining Leaba’s semiconductor expertise with the Cisco engineering team, we will accelerate our plans for Cisco’s… Read More Continue reading Cisco to acquire Leaba Semiconductor for $320 million as buying spree continues