Connect with us

Published

on

MORE FUN WITH FIRMWARE — Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack UEFIs booting Windows and Linux devices can be hacked by malicious logo images.

Dan Goodin – Dec 6, 2023 3:02 pm UTC EnlargeGetty Images reader comments 195

Hundreds of Windows and Linux computer models from virtually all hardware makers are vulnerable to a new attack that executes malicious firmware early in the boot-up sequence, a feat that allows infections that are nearly impossible to detect or remove using current defense mechanisms.

The attackdubbed LogoFAIL by the researchers who devised itis notable for the relative ease in carrying it out, the breadth of both consumer- and enterprise-grade models that are susceptible, and the high level of control it gains over them. In many cases, LogoFAIL can be remotely executed in post-exploit situations using techniques that cant be spotted by traditional endpoint security products. And because exploits run during the earliest stages of the boot process, they are able to bypass a host of defenses, including the industry-wide Secure Boot, Intels Secure Boot, and similar protections from other companies that are devised to prevent so-called bootkit infections. Game over for platform security

LogoFAIL is a constellation of two dozen newly discovered vulnerabilities that have lurked for years, if not decades, in Unified Extensible Firmware Interfaces responsible for booting modern devices that run Windows or Linux. The vulnerabilities are the product of almost a years worth of work by Binarly, a firm that helps customers identify and secure vulnerable firmware.

The vulnerabilities are the subject of a coordinated mass disclosure released Wednesday. The participating companies comprise nearly the entirety of the x64 and ARM CPU ecosystem, starting with UEFI suppliers AMI, Insyde, and Phoenix (sometimes still called IBVs or independent BIOS vendors); device manufacturers such as Lenovo, Dell, and HP; and the makers of the CPUs that go inside the devices, usually Intel, AMD or designers of ARM CPUs. The researchers unveiled the attack on Wednesday at the Black Hat Security Conference in London. Advertisement

The affected parties are releasing advisories that disclose which of their products are vulnerable and where to obtain security patches. Links to advisories and a list of vulnerability designations appears at the end of this article.

As its name suggests, LogoFAIL involves logos, specifically those of the hardware seller that are displayed on the device screen early in the boot process, while the UEFI is still running. Image parsers in UEFIs from all three major IBVs are riddled with roughly a dozen critical vulnerabilities that have gone unnoticed until now. By replacing the legitimate logo images with identical-looking ones that have been specially crafted to exploit these bugs, LogoFAIL makes it possible to execute malicious code at the most sensitive stage of the boot process, which is known as DXE, short for Driver Execution Environment.

Once arbitrary code execution is achieved during the DXE phase, its game over for platform security, researchers from Binarly, the security firm that discovered the vulnerabilities, wrote in a whitepaper. From this stage, we have full control over the memory and the disk of the target device, thus including the operating system that will be started.

From there, LogoFAIL can deliver a second-stage payload that drops an executable onto the hard drive before the main OS has even started. The following video demonstrates a proof-of-concept exploit created by the researchers. The infected devicea Gen 2 Lenovo ThinkCentre M70s running an 11th-Gen Intel Core with a UEFI released in Juneruns standard firmware defenses, including Secure Boot and Intel Boot Guard. LogoFAIL.

In an email, Binarly founder and CEO Alex Matrosov wrote:

LogoFAIL is a newly discovered set of high-impact security vulnerabilities affecting different image parsing libraries used in the system firmware by various vendors during the device boot process. These vulnerabilities are present in most cases inside reference code, impacting not a single vendor but the entire ecosystem across this code and device vendors where it is used. This attack can give a threat actor an advantage in bypassing most endpoint security solutions and delivering a stealth firmware bootkit that will persist in a firmware capsule with a modified logo image. Page: 1 2 3 4 Next → reader comments 195 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars

Continue Reading

Entertainment

Snoop Dogg becomes co-owner and investor of Swansea football club saying it’s ‘an underdog just like me’

Published

on

By

Snoop Dogg becomes co-owner and investor of Swansea football club saying it's 'an underdog just like me'

Snoop Dogg has become a co-owner and investor of Swansea, with the US rapper hailing the Welsh football club as “an underdog that bites back, just like me”.

The former Premier League club, which plays in the English second tier, confirmed the US rapper and producer plans to use his own money to invest in it, Sky Sports reports, although it didn’t disclose financial details.

“My love of football is well known, but it feels special to me that I make my move into club ownership with Swansea City,” the music icon said in the announcement.

“The story of the club and the area really struck a chord with me,” he added. “This is a proud, working class city and club.

“An underdog that bites back, just like me.

“I’m proud to be part of Swansea City. I am going to do all I can to help the club.”

Swansea’s American owners, led by Brett Cravatt and Jason Cohen, are trying to grow the Championship club’s global brand and increase commercial revenue.

Snoop Dogg, 53, who has 89m followers on Instagram and more than 20m on X, helped launch the team’s 2025-26 home shirt last weekend.

More on Snoop Dogg

Read more from Sky News:
One child dies after coach crashes on way back from school trip
Antarctica’s oldest ice arrives in UK for analysis on climate shifts

The club ownership group said: “To borrow a phrase from Snoop’s back catalogue, this announcement is the next episode for Swansea City as we seek to create new opportunities to boost the club’s reach and profile.”

Luka Modric, who recently signed with AC Milan from Real Madrid, joined Swansea’s ownership group in April.

Continue Reading

Politics

Diane Abbott suspended from Labour Party

Published

on

By

Diane Abbott suspended from Labour Party

Diane Abbott has been suspended from the Labour Party pending an investigation.

A party spokesperson confirmed the decision to Sky News but did not give a reason why.

Politics Live: The Starmtroopers are coming for the Corbynites

It comes after the veteran MP defended previous comments about racism which sparked an antisemitism row and led to a year-long suspension.

She apologised at the time and was readmitted back into the party before the 2024 general election.

A Labour Party spokesperson said: “Diane Abbott has been administratively suspended from the Labour Party, pending an investigation. We cannot comment further while this investigation is ongoing.”

Sky News understands that the suspension is not related to the four rebels who lost the whip on Wednesday for “repeated breaches” of party discipline, including voting against the government’s welfare cuts.

More from Politics

The action has been taken because of an interview in which she doubled down on her claim Jewish people experience racism differently to black people, which previously sparked a huge controversy.

abbott
Image:
Diane Abbott

In a letter to The Observer in 2023, Ms Abbott argued that people of colour experienced racism “all their lives” and said that was different to the “prejudice” experienced by Jewish people, Irish people and Travellers.

Shortly after it was published, she issued a statement in which she said she wished to “wholly and unreservedly withdraw my remarks and disassociate myself from them”.

However in a new interview with BBC Radio 4’s Reflections programme this week, she said she did not look back on the incident with regret.

Ms Abbott said: “Clearly, there must be a difference between racism which is about colour and other types of racism because you can see a Traveller or a Jewish person walking down the street, you don’t know.

“But if you see a black person walking down the street, you see straight away that they’re black. They are different types of racism.”

She added: “I just think that it’s silly to try and claim that racism which is about skin colour is the same as other types of racism.

“I don’t know why people would say that.”

Commenting on the suspension, Ms Abbott told Sky News: “It’s obvious this Labour leadership wants me out. My comments in the interview with James Naughtie were factually correct, as any fair-minded person would accept.”

The clip of the interview was re-posted by Brian Leishman, one of the MPs suspended on Wednesday, who said: “Diane Abbott has fought against racism her entire life.”

Bell Riberio-Addy, who lost her role as trade envoy in yesterday’s purge, also came to Ms Abbott’s defence, saying: “Before condemning her based on headlines, I would listen to her clip and note she discussed the different forms that racism takes and condemned all forms of racism.”

Former shadow chancellor John McDonnell made similar comments, saying that in the interview his colleague “forthrightly condemns antisemitism & discusses the different forms of racism”.

But Labour MP David Taylor told Sky News he has “long thought Diane Abbott shouldn’t be a member of our party due to her appalling positions on everything from Bosnia to Syria”.

He added: “As the Jewish Labour Movement have said, antisemitism targets Jews regardless of how they look, and many in the community are visibly Jewish and suffer racism for it.”

In the interview, Ms Abbott said she “of course” condemns antisemitic behaviour in the same way she would condemn racist behaviour because of the colour of someone’s skin, adding: “I do get a bit weary of people trying to pin the antisemitic label on me because I spent a lifetime facing racism of all kinds.”

Ms Abbott made history when she was elected as Britain’s first black female MP for Labour in 1987.

She is the longest-serving female MP in the Commons, giving her the title “Mother of the House”.

As an MP on the left of the party she has often clashed with the leadership throughout her career – bar her time serving in Jeremy Corbyn’s shadow cabinet.

Read more from Sky News:
Sixteen and 17-year-olds will be able to vote in next general election
Five reasons to be confused by Starmer’s MP suspensions

Many MPs rallied in support of Ms Abbott last year when it was not clear if she would be reinstated in time for the general election, or allowed to stand.

She went on to retain her seat of Hackney North and Stoke Newington with a majority of over 15,000.

Deputy Prime Minister Angela Rayner hinted action could be taken against Ms Abbott when she told The Guardian earlier on Thursday that she was “disappointed” in her colleague’s remarks.

“There’s no place for antisemitism in the Labour Party, and obviously the Labour Party has processes for that,” she said.

A source close to the decision to suspend her told Sky News there is a “very slim chance” she will be allowed back in, given she did antisemitism training and apologised last time.

It raises questions about whether Ms Abbott could join the new party being formed by Mr Corbyn and former Labour MP Zarah Sultana.

For the time being, Ms Abbott will sit in the Commons as an independent MP.

Adnan Hussain, who was elected as the independent MP for Blackburn last year, said on X: “We’d be honoured to have a giant like Diane join us, she [should] come to the side that would really appreciate her for the legend she is.”

Continue Reading

UK

Child who died in Minehead school coach crash was 10-year-old boy, police say

Published

on

By

Child who died in Minehead school coach crash was 10-year-old boy, police say

The child who died in a school coach crash in Somerset on Thursday was a 10-year-old boy, Avon and Somerset Police have said.

A specially trained officer is supporting the child’s family, the force said, adding that two children taken to Bristol Royal Hospital for Children by air ambulance remain there as of Friday.

Four children and three adults also remain in hospital in Somerset.

There were between 60 to 70 people on board when the incident happened near Minehead, just before 3pm on Thursday.

The coach was heading to Minehead Middle School when it crashed on the A396 between Wheddon Cross and Timbercombe.

Flowers outside school
Image:
Pic: PA

Police said that 21 people were taken to hospital, including two children who were taken via air ambulance.

Gavin Ellis, chief fire officer for Devon and Somerset, said the coach “overturned onto its roof and slid approximately 20ft down an embankment”.

Rachel Gilmour, MP for Tiverton and Minehead, said the road where it happened is “very difficult to manoeuvre”.

“You have a very difficult crossing at Wheddon Cross, and as you come out to dip down into Timbercombe, the road is really windy and there are very steep dips on either side,” she told Sky’s Anna Botting.

Please use Chrome browser for a more accessible video player

Tearful MP reacts to coach crash

It comes after a teacher at Minehead Middle School praised the “incredibly brave” pupils for supporting each other after the coach crash.

Read more on Sky News:
Amber warning for thunderstorms for southeast England
No further action over Kneecap at Glastonbury, police say

“You have looked after each [other] in what was a life-changing event, we will get through this together,” they wrote on Facebook.

“I feel so lucky to be your teacher. I am so grateful to my wonderful colleagues during this time who were also fighting to help as many people as we could.”

Continue Reading

Trending