Meltdown and Spectre Information Page

January 4, 2018 | Alerts

Issue

Recently-published research articles have demonstrated a new class of vulnerabilities (dubbed “Meltdown” and “Spectre”) that exist in most modern computer processors. At best, the vulnerabilities could be leveraged by malware and hackers to more easily exploit other security bugs.  At worst, they could be abused by programs and logged-in users to read the contents of your computer’s memory (such as passwords).

You should be aware of these attacks because your computer is probably affected, but there is no need for alarm. This is a technical issue that will be addressed as software and operating system providers release updates which can then be installed on your computer.

Recommendations

The best protection from the new vulnerabilities is continuing to maintain good security practices – especially to ensure your operating system, browser, and antivirus software are kept up to date with the latest vendor software patches.

Specifically:

Summary Articles and Useful Links

Alerts

Critical MacOS and iOS Patches 04/2023

Apple has released critical patches for iPhones, iPads, and Macs to address zero-day flaws being actively exploited that can result in complete device compromise and data breach. Details of the vulnerabilities are tracked as CVE-2023-28206 and CVE-2023-28205. Please...

Critical Microsoft Outlook Vulnerability 03/2023

There is a critical Microsoft Outlook vulnerability for Windows (CVE-2023-23397) that allows hackers to remotely steal hashed passwords by simply receiving an email, and is actively being exploited. Please ensure system and application updates are initiated and...

News & Announcements

Data Disposal Day – October 23, 2024

Date: Wednesday, October 23, 2024 Time: 8:00 AM- 12:00 PM (or until truck hits full capacity) Location: Parking Lot 12A near the Natural Sciences buildings Each of us is responsible for the security of information assets with which we work. Properly...

DMARC Email Security Compliance

Major email providers have announced that they have started enforcing DMARC/DKIM/SPF email security standards in order to send email to them. What that means to us is that external email providers will increasingly block or mark as spam email coming from UCI unless...