Skip to main content
  1. Home
  2. Computing
  3. News

Security flaw on modern PCs could leave your encrypted data exposed

Add as a preferred source on Google
MacBook Pro 15
Malarie Gokey/Digital Trends

A vulnerability on most modern PCs and Macs could leave your data exposed. Cybersecurity researchers at F-Secure discovered a weakness in the firmware of most modern computers could allow hackers access to encryption keys and other sensitive data.

Access to sensitive data is gained through a 2008-style cold boot attack, where the hacker forces a computer to restart without going through the normal shutdown process. The computer’s data is briefly accessible in the RAM after power is lost, but many modern devices overwrite the RAM to prevent unauthorized access to data during this type of attack. Researchers discovered that there is a way to disable the overwrite process, essentially reviving the decade-old method of attack.

Recommended Videos

“The attack exploits the fact that the firmware settings governing the behavior of the boot process are not protected against manipulation by a physical attacker,” F-Secure wrote in a blog post. “Using a simple hardware tool, an attacker can rewrite the non-volatile memory chip that contains these settings, disable memory overwriting, and enable booting from external devices. The cold boot attack can then be carried out by booting a special program off a USB stick.”

Despite the seriousness of the findings, the vulnerability may not be as damaging given that to carry out this exploit, hackers would need physical access to your device. If a hacker has physical access, the exploit can be conducted in approximately five minutes, researchers cautioned.

F-Secure shared its findings with Microsoft, Apple, and Intel, but given that physical device access is required for this type of attack, it doesn’t appear that a fix may be coming soon. Newer Mac systems with a T2 chip aren’t affected by this attack, and Microsoft claims that enabling pre-boot authentication with a PIN or startup key with BitLocker could help mitigate these risks. These more advanced security tactics, however, aren’t available to general consumers who run Windows 10 Home edition.

“Unfortunately, there is nothing Microsoft can do, since we are using flaws in PC hardware vendors’ firmware,” F-Secure principal security consultant Olle Segerdahl told TechCrunch. “Intel can only do so much, their position in the ecosystem is providing a reference platform for the vendors to extend and build their new models on.”

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
AI browsers like Perplexity Comet can be tricked into spilling your password through BioShocking exploit
Six AI browsers were found leaking saved passwords and many of them haven't fixed it yet.
MacBook Air in hand, Comet browser loaded—let’s see what Perplexity’s AI can really do

Security researchers just found a strange way to trick AI browsers into handing over your passwords. They managed to trick AI browser agents into exposing sensitive data like saved passwords, session cookies, and private tokens by disguising the theft as part of a harmless "game."

The technique is called BioShocking, named after the popular video game BioShock, where a brainwashed character is manipulated into believing a false reality. Once an AI browser falls for the same trick, it stops following its own safety rules entirely.

Read more
Google Play’s latest speed boost goes way beyond the phone
Play Store v52.1 targets app install performance across Android devices, including cars, TVs, watches, tablets, and phones.
Google Play Store Photo

Google is rolling out Play Store v52.1 with changes built around a practical Android problem, getting apps installed more smoothly on very different kinds of hardware.

The update focuses on Play Store infrastructure, with Google pointing to stability, performance, and better memory use while a device adds an app. That install path now has to work on phones, tablets, Wear OS watches, Google TV, Android TV, Android Auto, and cars running Android Automotive.

Read more
Peacock Premium Plus joins YouTube as the streaming bundle battle gets messier
The $16.99 subscription brings Peacock’s sports-heavy catalog into YouTube, with account details still unclear.
Adult, Female, Person

Peacock Premium Plus is now available through YouTube Primetime Channels, giving viewers a new way to add a major streaming service inside YouTube.

The $16.99-per-month subscription brings Peacock’s live sports, NBC and Bravo shows, originals, Universal movies, Telemundo programming, and Spanish-language FIFA World Cup 2026 coverage into YouTube’s channel marketplace.

Read more