Thunderclap: Apple Macs at risk from malicious Thunderbolt peripherals

Researchers have revealed how malicious Thunderbolt and PCI Express (PCIe) peripherals could be used to compromise computers running macOS, Windows, Linux and FreeBSD. Continue reading Thunderclap: Apple Macs at risk from malicious Thunderbolt peripherals

‘Thunderclap’ collection of hardware vulnerabilities affects Mac, Windows, Linux systems

Many modern computers running Mac, Windows or Linux operating systems are vulnerable to a number of security flaws that could exploit a machine’s connection to its network cards, keyboard, computer charger or other essential peripheral devices, according to research published this week from a team of computer scientists. The vulnerabilities, which require physical access to a computer, are known collectively as “Thunderclap.” They leverage operating system design flaws in what’s known as a Thunderbolt interface, a common piece of hardware that allows outside devices to connect to a machine. Researchers revealed this week at the NDSS 2019 security conference that “all Apple laptops and desktops produced since 2011 are vulnerable, with the exception of the 12-inch MacBacBook. Many laptops, and some desktops, designed to run Windows or Linux produced since 2016 are also affected[.]” The Thunderclap vulnerability could allow an attacker with access to a machine to execute commands at […]

The post ‘Thunderclap’ collection of hardware vulnerabilities affects Mac, Windows, Linux systems appeared first on CyberScoop.

Continue reading ‘Thunderclap’ collection of hardware vulnerabilities affects Mac, Windows, Linux systems

Many computers are vulnerable to hacking through common plug-in devices

Attackers can compromise an unattended machine in a matter of seconds through devices such as chargers and docking stations. Vulnerabilities were found in computers with Thunderbolt ports running Windows, macOS, Linux and FreeBSD. Many modern laptops a… Continue reading Many computers are vulnerable to hacking through common plug-in devices