In recent weeks, critical vulnerabilities in modern computer processors were disclosed that affect nearly every piece of computing hardware currently in use. These vulnerabilities, known as Meltdown and Spectre, could be used to allow an attacker to access sensitive information stored in the memory of programs running on your device.
Microsoft released a Windows Security Update on January 3, 2018 to address Meltdown and Spectre. However, Microsoft also “identified a compatibility issue with a small number of antivirus software products”, some of which are owned and operated by CTA members. This issue arises when antivirus applications make unsupported calls into Windows kernel memory, which may result in blue screen errors. Microsoft has asked antivirus vendors to add a registry key to their products to certify that the product works with the patch, and has noted that customers will not receive the January Microsoft software update, or subsequent updates, until the antivirus vendors make the change.
As part of our mission, CTA members are constantly working together for the greater good. To that end, CTA has compiled a set of links to our member companies regarding these vulnerabilities. These describe the actions our members are taking with respect to Meltdown and Spectre and they provide authoritative information from members describing the vulnerabilities themselves, which of their products (if any) are affected, and whether their products are compatible with the Microsoft update.
CTA members will continue to coordinate activity related to addressing these vulnerabilities, including actively searching for signs of exploitation attempts by malicious actors. We may be dealing with these vulnerabilities for quite some time, and CTA members will be working proactively to defend their customers.
Palo Alto Networks:
Author: Michael Daniel
Nonprofit Cyber Celebrates Its First Anniversary with Six New Members
BBB Institute for Marketplace Trust, Black Girls Hack, Building Cyber Security, Internet Safety Lab, the Global Anti Scam Alliance, and the Maritime Safety and Security Alliance have joined the coalition, adding to its diversity, equity and [...]
Collaboration is Key to Better Threat Intelligence
By Victor Acin (Blueliv Labs Manager) Where do you get your cybersecurity news from? If you are a cybersecurity vendor, your news feed is a great way to find outdated threat information, after an attack has already happened. But, if your mission is to defend the digital ecosystem, critical infrastructure, as well as [...]