Skip to content

ESET 發現著名手提電腦品牌內含 UEFI 漏洞

國際資安大廠 ESET 發現 Lenovo(聯想)手提電腦的韌體存在 3 項 UEFI 漏洞,這三個漏洞是於去年(2021)由研究人員發現,並於該年 10 月通報給原廠;含有這三個漏洞的手提電腦款式甚多,包括 Lenovo IdeaPad 3、Legion 5 Pro-16ACH6 H、Yoga Slim 9-14IYL05 等系列,全球使用者人數可能多達數百萬人。

三個漏洞中,有兩個(CVE-2021-3971 和 CVE-2021-3972)漏洞,可讓黑客關閉針對 SPI 快閃記憶體的機制,而 SPI 快閃記憶體係用以儲存 UEFI 韌體程式碼;這樣黑客即可在電腦啟動(boot)期間執行非由原始製造廠(Original Equipment Manufacturer, OEM)提供簽署的程式碼。

另一個漏洞 CVE-2021-3970 則可讓本地端的黑客,利用此漏洞提升執行權限,並且於本土端執行任意程式碼。

Lenovo(聯想)已提供新版韌體,修復上述三個漏洞外,也在官網提供所有含有上述漏洞的手提電腦型號清單;ESET 資安專家建議所有使用 Lenovo 品牌筆記型電腦的用戶,應立即核對自己使用的產品是否列名於清單內,同時立即升級至最新版本韌體,以免遭黑客利用這三種已知漏洞發動攻擊。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

有關 ESET 產品名稱更新

隨著新一代產品推出,ESET 將為各規模的公司企業,提供更完整和靈活的網絡防護解決方案。為進一步整合產品線,部分產品名稱將作出修改:
Product Name New Product Name
ESET Enterprise Inspector ESET Inspect
ESET Dynamic Threat Defense ESET LiveGuard Advanced
ESET Dynamic Threat Defense for Mail Security ESET LiveGuard Advanced for Mail Security
ESET Dynamic Threat Defense for Endpoint Security + Server Security ESET LiveGuard Advanced for Endpoint Security + Server Security
ESET Dynamic Threat Defense for Cloud Office Security ESET LiveGuard Advanced for Cloud Office Security
ESET Enterprise Inspector and Endpoint Security ESET Inspect and Endpoint Security
ESET PROTECT Essential Plus On-Prem (ESET Dynamic Endpoint Protection – Antivirus Level) ESET PROTECT Essential Plus On-Prem
ESET PROTECT Essential On-Prem (ESET Endpoint Protection Standard) ESET PROTECT Essential On-Prem
ESET PROTECT Entry On-Prem (ESET Endpoint Protection Advanced) ESET PROTECT Entry On-Prem
ESET PROTECT Advanced On-Prem (ESET Dynamic Endpoint Protection) ESET PROTECT Advanced On-Prem
ESET PROTECT Enterprise On-Prem (ESET Targeted Attack Protection) ESET PROTECT Enterprise On-Prem
ESET PROTECT Essential (ESET Endpoint Protection Standard Cloud) ESET PROTECT Essential
ESET PROTECT Entry (ESET Endpoint Protection Advanced Cloud) ESET PROTECT Entry
ESET PROTECT Advanced (ESET Remote Workforce Offer) ESET PROTECT Advanced
ESET Server Security (ESET File Security) for Terminal Server ESET Server Security for Terminal Server
ESET Server Security (ESET File Security) ESET Server Security
ESET Server Security for Linux (ESET File Security for Linux) ESET Server Security for Linux
ESET Server Security for Microsoft Windows Server (ESET File Security for Microsoft Windows Server) ESET Server Security for Microsoft Windows Server
ESET Endpoint Antivirus + ESET Server Security (ESET File Security) ESET Endpoint Antivirus + ESET Server Security
ESET Endpoint Security + ESET Server Security (ESET File Security) ESET Endpoint Security + ESET Server Security

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

Why ESET is a leader for managed service providers serving SMBs

Michal Jankech, ESET Vice President of SMB and MSP Segment

In a unique report put out by Analysys Mason in 2021, ESET scored among the leaders for small- and medium-sized business (SMB) endpoint security vendors. The reason for this placement is clear: backed by a strong managed service provider (MSP) program tailored to the needs of SMBs, ESET has shown consistent financial growth in serving the SMB market around the world.)

Similarly, in 2022, Canalys published a unique report called the MSP Tech Stack, which layers five core MSP technologies positioning cybersecurity at the bottom. Although ESET did not feature among the cybersecurity vendors in this report, ESET is poised to reach a milestone in product development where it will meet the two entry criteria:

1.    Over 10% of revenue sourced via MSPs.
2.    A strong detection and response capability ready for MSPs.

The first criterion on revenue source is a mark already hit by ESET. The second criterion is on track to be met with the release of ESET Inspect Cloud – ESET’s XDR-enabling technology, which was already released for businesses in March 2022 – into ESET’s MSP program later this year.

The Canalys MSP Tech Stack serves as an insightful lens into the MSP world because it reveals the delicate balance between trust and freedom sought by MSPs: the trust to select any one vendor as a long-term, stable partner committed to its MSP program, and the freedom to mix and match several trusted vendors from the tech stack to access the best technologies available.

Finding a trusted security partner

Many events cause MSPs concern, like unwanted changes to partner programs, acquisitions between vendors serving the MSP community, or the widespread blocking of sales in the wake of the Ukraine invasion followed by the breaking and forging of many partnerships. In addition to this tumultuous time for service chains around the world, the concerns about cyberthreats remain ever present with governments simultaneously advising the solicitation of help from security experts and caution about the security posture of third-party vendors.

For many MSPs trudging through this complexity, turning to ESET as an EU-headquartered security provider may be a perfect fit, to put it boldly. Since its origins 35 years ago, ESET has been proud to be a privately owned company not beholden to stockholders and thus free to engage with partners to design an MSP program built on their feedback and the actual needs of SMBs. This means that ESET can offer partners a stable relationship set to last for many years.

But to be stable is not to be stagnant. ESET continually strives to enhance its MSP portfolio and improve the quality of its security products along with their integrations and features for MSPs. The key examples demonstrating this commitment are ESET PROTECT and ESET Inspect.

Prevent, detect, and respond from the cloud

ESET PROTECT represents ESET’s tiered approach to providing businesses with subscriptions for scalable protection centered around a management console. When this move was made in 2021, a key feature was the release of a cloud-based version of ESET PROTECT. This new foray to the cloud was not an isolated event but a paradigm shift of becoming cloud first in the way ESET plans to serve businesses and MSPs in the future.

Of course, ESET was already leveraging the power of the cloud to provide increased protection for many years. But the birth of ESET PROTECT was a new way for MSPs to scale their efforts and focus their time now unencumbered by on-premises concerns. This was followed in 2021 by the genesis of yet another cloud product – ESET Cloud Office Security – which directly protects cloud-based tools, chiefly Microsoft 365.

Yet, after having traversed all this ground to the cloud, the appetite of MSPs for cloud-provisioned protection has only been sharpened. And the succulent steak for this meal, ESET Inspect Cloud, is the detection and response module laying the foundation of ESET’s pursuit of XDR.

Interested in partnering via ESET’s MSP program? Read more here.

Apart from ESET Inspect, other plans are in store for MSPs. To give only a few hints now, ESET has long-term plans to offer multifactor authentication from the cloud, to build a vulnerability and patch management solution, and to launch a unified license management solution capable of serving the needs of all partners’ distribution model types.


Further reading:

  1. MSPs must master cybersecurity II
  2. Criminal hacking hits managed service providers: Reasons and responses
  3. No-cost ESET plugins for MSPs streamline security via low-effort dashboard
  4. With more businesses moving to the cloud and adopting SaaS, ESET Cloud Office Security provides easily managed security to MSPs and their Microsoft 365 clients
  5. A new business offering for a new business world
  6. Bringing cloud-based management to the managed service providers’ tool kit with ESET PROTECT Cloud

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

When NFT Is the Creative Limit

Imagine this: It’s a nice spring afternoon and you decide to visit an art gallery. You get dressed up, grab your keys and face mask (depending on COVID restrictions in your area) and leave your house. You walk through the city to your favorite gallery, feeling the light breeze on your cheeks. You pay for a ticket and start walking around. You can see the art, almost touch it. You might meet a few people who are also admiring paintings and sculptures. You wave and smile with your eyes.

Now imagine none of it is true. There is no need to physically go to the gallery and view art. We’ve arrived in an era when virtual galleries are becoming a reality. Digital art is gaining popularity, and Non-Fungible Tokens (NFTs) are making it that much more profitable for artists.

By now, we’re so used to sharing and viewing content online for free that it is second nature. But what if an art piece was enriched by a unique feature—an NFT?

We have been hearing so much about NFTs over the past few months. But what exactly are they? Non-Fungible Tokens. That’s it. It’s a piece of digital data, embedded in a file that is unique for that piece and that piece only. Just like a physical piece of art, a digital piece with an NFT is non-replicable. There is only one of its kind. And that is what gives it its value. These pieces cannot be exchanged or substituted with similar items of the same value. Just like physical art cannot be swapped by a similar piece with the same value.

NFTs have been around since 2015, but have recently gained in popularity. Many thanks to the National Basketball Association (NBA) in the US, which started selling “NBA Top Shots” in 2020—non-fungible short clips of basketball shots, similar to formerly popular basketball cards. Each is unique, has its own value and cannot be substituted by another.

This new development has the potential to revolutionize the art world. NFTs act as a digital certificate of ownership of an art piece. After an NFT art piece is created, it is tokenized on a Blockchain (cryptocurrency service). This proves the artist’s legal ownership of the piece they created. And since a blockchain is secure and is hard to hack, tracking ownership is pretty easy. This helps the artist gain popularity and get their art out into the world. Anyone online can view their piece, even share and copy it. You may think that this kind of defeats the purpose. If you can freely access it, view it and share it, why pay for the ownership? The trick is, unless you purchase the NFT, you can’t fake ownership. Just like with physical art, you can take a photo of it, or even make a copy. But unless you own the original piece with a certificate, your copy/photo is not of the same value as the original.

When you buy an NFT, it becomes your property and you can do with it as you please. However, the buyer does not possess any Intellectual Property Rights, such as the right of adaptation or reproduction. This is an exclusive right of the creator.

Creating digital art breaks bounds artists have been bound by. Artists can now work more freely and independently. They have the right to sell their piece at a price they believe it deserves, set conditions before selling and much more. They also have the authority to rent and display their art as they please. It makes it also easier for them to distribute their art globally without limitations of their location.

It all sounds great, but every digital advancement comes with its risks. NFTs are sold on digital trading platforms. Those operate similar to online shops. Vulnerabilities in these platforms are often caused by insufficient security considerations during the development phases. These oversights become the criminals’ target, once uncovered. They might either upload an artwork containing malicious code, steal people’s accounts or trade NFTs at a low price and resell them for profit.

According to HKCERT, there have been several cases of cybersecurity breaches in the NFT area. One of the latest occurred in February 2022 via a phishing attack on OpenSea (an NFT trading platform). A cybercriminal sent out an email social engineering users into signing a contract and sending crypto assets to his wallet. The total amount stolen was $1.7 million.

It seems that most of the attacks are of a phishing nature. But there has also been a security vulnerability found in one of the trading platforms, OpenSea. It is one of the biggest and most popular of its kind. The vulnerability allowed NFT art pieces to be sold for less than 1% of the price floor, which caused problems to creators.

There are no limits to innovation and creativity. NFTs and digital art are proving that progress cannot be stopped. And it should not be. Progress is here to stay and develop. But where there is progress there are risks. ESET has been protecting progress and development since its establishment over 30 years ago. Security of digital users is priority number one; this means making sure that the progress we as humans have made is protected so we can safely step into the future.

Where technology enables progress, ESET is here to protect it.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

New Windows on ARM64 device? ESET protects both at work and at play

 

After the successful launch of its business-oriented siblings, ESET has extended its latest technology to home users/consumers and stands ready to protect their Windows on Arm-based devices with our award-wining full-featured products. Our development teams put a lot of effort into reengineering ESET’s already mature security technology for ARM-powered devices, which are increasingly used in both business and home applications.

Thanks to its multilayered approach to protection, ESET Smart Security® Premium, ESET Internet Security and ESET NOD32 Antivirus products for Windows on ARM offer a slew of prevention and detection technologies. A key contribution to extending these functionalities was the invaluable feedback of the ARM64 beta products’ home testers. Their insights mean you will enjoy our well-regarded user experience and the same award-winning protection ESET customers are used to.

Just like the award-wining Windows-based product, the version for ARM64 also includes ESET LiveGuard, which provides an additional proactive layer of protection against never-before-seen types of threats, protecting users before the malware has a chance to execute its action. Another feature is the addition of Password Manager, which has been completely redesigned for improved security and an even more user-friendly experience.

Underlying these key improvements is the ESET Home platform, which is designed for on-the-go security management. The platform enables users to add, manage and share licenses with family and friends, and to manage Anti-Theft, Parental Control, and Password Manager via a web portal. ESET Home directly supports ARM64 users who’ve opted to protect the progress enabled by mobile-centric “always on” devices.

With so many of us experiencing crossover use of our work and personal devices in the current work from home/hybrid work regime, ESET technologies now better reflect the extra protection that highly mobile users and their computing needs demand. Whether moving between multiple public and private networks, or managing devices visiting your home network, our new products recognize that “Always On” also risks “always” being vulnerable. The risks are backed up by considerable research showing that threats targeting employees working remotely from home have vastly increased. And, via customer research conducted by ESET showing that households often have a single person who takes care of IT security for everyone, having a solution that provides easy-to-use security management at the home admin’s fingertips is crucial.

Hence, a critical part of your move to ARM should undoubtedly be security provided by a mature consumer security solution. To find out more about the new features and improvements in the latest version of our consumer offering, head to www.eset.com.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×