Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

ALERT: Meltdown/Spectre Hardware Vulnerability Requires Action

ALERT: Meltdown/Spectre Hardware Vulnerability Requires Action

Just a few months after finding themselves in a firmware fiasco, Intel is making news for all the wrong reasons. This issue had the potential to affect the CPU of a device, causing a severe dip in the performance of the device.

In a blog post by a user going by the name Python Sweetness, an issue was reported, describing “an embargoed security bug impacting apparently all contemporary CPU architectures that implement virtual memory, requiring hardware changes to fully resolve.” This means that, thanks to this bug, the interactions that different programs would have with the CPU would be affected.

Under normal circumstances, a CPU will have two modes that it operates under: kernel, which permits the user to make changes to the computer itself, and user, which is considered a ‘safe’ mode. Python Sweetness discovered a bug that blurred the distinction between the two modes. The bug allowed programs run in user mode to also access kernel mode, possibly allowing malware to access the computer’s hardware.

However, the circumstances have proven to be less dire than they originally appeared. The expectation was that this bug would cause entire processes to shift back and forth between user and kernel mode, hamstringing the speed at which the device would operate. There was also the expectation that this issue would not be able to be resolved without a hardware change.

For PCs with Windows 10 installed and an antivirus that supports the patch, the fix should already be in place. However, to confirm this, go to Settings > Update & Security to see if there are any updates waiting to be installed. If not, check your update history for Security Update for Windows (KB4056892) or check with your antivirus provider to find out when it will be supported, the patch will not install until it sees that the antivirus has been updated to a version that the vendor verifies supports this patch.

Android devices had an update pushed on January 5 to provide some mitigations, with more protections coming in later updates. These patches have already been pushed to Google-branded phones, like the Nexus and Pixel lines, and may have been on other Android devices. It doesn’t hurt to check, and if you haven’t been updated, go online and put pressure on your carrier on a public forum.

Google Chrome should be updated with similar mitigations on January 23, with other browsers updating soon after. To help protect yourself until then, have your IT team activate Site Isolation to minimize the chance of a malicious site accessing data from another browser tab.

Other devices (like NAS devices, smart appliances, networking equipment, media equipment, etc.) may also be at risk, as they are using similar hardware. It’s really important for business owners to have their entire infrastructure reviewed and audited.

These kinds of issues help to demonstrate the value of an MSP’s, or managed service provider’s, services. MSPs like Total Tech Care are sure to keep themselves informed on the latest developments in IT security and any resolutions they can pass on to businesses like yours, if they don’t implement them on your behalf.

As a result, you and the rest of your team can go about your business without having to concern yourself with solving issues like these, knowing that you can trust the team who is solving it for you. For more ways that an MSP can help keep your business security and operations optimized, reach out to Total Tech Care at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 30 April 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Business Google Network Security Microsoft Internet Email Malware Workplace Tips Backup Innovation Data User Tips Computer Mobile Devices Hardware IT Services Android VoIP Disaster Recovery communications Business Continuity IT Support Smartphones Communication Smartphone Miscellaneous Mobile Device Small Business Network Browser Productivity Collaboration Quick Tips Cybersecurity Business Management Users Managed IT Services Upgrade Phishing Windows Outsourced IT Data Backup Ransomware Windows 10 Office Server Save Money Data Recovery Cloud Computing Passwords Windows 10 Tech Term Saving Money Holiday Social Media Chrome Gadgets Virtualization Automation Microsoft Office Managed IT Services Managed Service Facebook Operating System Cybercrime Computers Artificial Intelligence BYOD Mobile Device Management Networking IT Support Hacking Internet of Things Health Wi-Fi Spam Covid-19 Office 365 Telephone Systems Managed Service Provider Information Technology Information Remote Alert Bandwidth Router Social Engineering Mobility BDR Recovery Employer-Employee Relationship Password Remote Monitoring Application Money Encryption Data Breach Applications App History Big Data Law Enforcement Human Resources Mobile Computing Data Storage Patch Management Mobile Office Apps Office Tips Training Government Blockchain VPN Paperless Office How To Private Cloud Managed IT Remote Computing Website HaaS Work/Life Balance Budget Vulnerability Windows 7 Word Servers Google Drive Wireless Data Security Gmail Avoiding Downtime Settings Flexibility Marketing Two-factor Authentication WiFi Infrastructure Voice over Internet Protocol Bring Your Own Device IT solutions Entertainment Mouse Data Management Cleaning Conferencing User Error USB Vendor Scam Managed Services Meetings Display End of Support Data Protection Education Physical Security Safety Risk Management Employee/Employer Relationship Vendor Management Hacker Sports HIPAA Redundancy RMM Keyboard The Internet of Things Lithium-ion battery Telephone System Staff Software as a Service Machine Learning Firewall Connectivity Remote Work Save Time Virtual Reality Apple Social Computing Infrastructure Going Green Managed Services Provider Augmented Reality Fraud Database Business Intelligence Remote Worker Audit Wearable Technology Battery Worker IT Consultant Remote Workers IT Management Cryptocurrency Retail Hard Drives Shadow IT Instant Messaging Processor Legal Robot Excel Humor Botnet IT Plan Internet Exlporer Comparison Biometrics Hard Drive Virtual Desktop Unsupported Software CES PDF DDoS Charger Computing Proactive IT Business Technology Content Management Compliance Access Control SharePoint OneNote Computer Care Best Practice YouTube Virtual Assistant Current Events Black Market Telephony Authentication Digital Signage Samsung Customer Service Environment Virus Unified Threat Management Document Management Value Fax Server Update Wireless Technology Computer Accessories Solid State Drive Spam Blocking How to Electronic Medical Records Downtime Procurement Net Neutrality SaaS Workplace Strategy Google Docs Hiring/Firing Identity Theft Data storage Help Desk Automobile Printing Printer Network Congestion eWaste Bluetooth Cryptomining Password Management Assessment Password Manager Point of Sale Tablets Personal Multi-Factor Security Entrepreneur Supply Chain Management Printer Server Windows Server 2008 Twitter Reputation Monitoring Streaming Media Batteries Tools Search Engine NIST Content Television Business Mangement Shortcut Windows 8.1 Tech Support Digitize Trending Cost Management Laptop Windows Server 2008 R2 Smart Tech Techology Addiction Amazon Social Networking Customers Customer relationships IT Assessment Manufacturing Audiobook Public Computer Recycling Email Best Practices Transportation Touchpad Regulations Wiring Practices Security Cameras Computer Fan Cache Running Cable Rootkit Amazon Web Services Computer Tips Managed IT Service OneDrive Biometric Security Safe Mode Politics Criminal Advertising Virtual CIO Memory Benefits Peripheral GDPR Workers Hosted Computing FENG Wireless Internet Online Shopping Digital Security Cameras Notifications Using Data Copiers Consultant 5G File Sharing IBM Smart Technology Specifications Quick Tip Analytics Flash Camera Inventory Smartwatch Wire Evernote Relocation Ergonomics Science Development Best Available OLED Software Tips Supercomputer Travel Video Games Millennials PCI DSS WIndows 7 Virtual Machine Sync Printers Emails Employee Smart Office Distributed Denial of Service Worker Commute Wireless Charging Customer Relationship Management 2FA Fiber Optics Messaging Cabling Experience Analyitcs Scalability Two Factor Authentication Workforce Programming Policy Hypervisor Virtual Private Network Netflix Root Cause Analysis Business Owner Cables Dark mode Trend Micro NarrowBand SMS Default App HBO Knowledge Music Nanotechnology Antivirus Search Telecommuting Procedure User Saving Time PowerPoint Skype Project Management Windows Media Player Google Search Data loss Cortana iPhone dark theme Windows 8 Shopping Troubleshooting AI IT Infrastructure Outlook Leadership Digital Signature IT service FinTech Managing Stress Start Menu Warranty Bing Screen Mirroring HVAC Loyalty Google Apps Files Tablet Social Network Books Chromecast Investment Cameras Frequently Asked Questions Analysis Domains Windows 10s Devices Employees Employee/Employer Relationships Mobile Administrator ISP Cast Enterprise Content Management IaaS Maintenance Colocation Windows 365 Uninterrupted Power Supply Emergency Bloatware Video Conferencing ROI Tip of the week MSP webinar Accountants Public Cloud Thought Leadership Employer Employee Relationship Credit Cards Monitor Sales Bitcoin Professional Services Microchip Shortcuts

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code