Skip to main content
  1. Home
  2. Computing
  3. News

If you own a Lenovo PC, you need to update it immediately

Add as a preferred source on Google

Lenovo, one of the most popular computer manufacturers in the world, just announced that many of its laptops and desktops need immediate BIOS updates to secure them from serious security vulnerabilities. Six flaws have been found; however, none have been reported as being actively exploited thus far.

Lenovo lists the affected models, which range from desktops and all-in-ones to laptops and even servers. Models include several IdeaCentre, ThinkCentre, ThinkStation, ThinkSystem, Legion, M-series, V-series, and Yoga desktops and all-in-ones. A large number of laptops are affected as well, including IdeaPad, ThinkPad, ThinkBook, Legion, Yoga, and Flex models.

lenovo legion laptops
Lenovo

There are hundreds of computer models affected and everyone that owns a Lenovo laptop, desktop, or server should check if their model is on the list.

Recommended Videos

The vulnerabilities could lead to elevated privileges for attackers, unauthorized access to data, denial of service, and even arbitrary code execution. Not every model is affected by every bug listed but Lenovo didn’t itemize by model. The full CVE list shows 5 vulnerabilities: CVE-2021-28216, CVE-2022-40134, CVE-2022-40135, CVE-2022-40136, and CVE-2022-40137. American Megatrends released security enhancements for its AMI BIOS, which is used by Lenovo, but there isn’t a CVE available for this vulnerability.

Lenovo provided links to download the required updates. For Lenovo Products, search for your model on Lenovo’s support page, and for IBM-branded products, search IBM’s Fix Central page. Lenovo also has a tutorial page with specific instructions for each model if you need further help.

BleepingComputer first spotted Lenovo’s important BIOS update. Make sure to check if your Lenovo laptop, computer, or server is affected and update as soon as possible to keep your data, network, and computer secure.

Alan Truly
Alan Truly is a Writer at Digital Trends, covering computers, laptops, hardware, software, and accessories that stand out as…
OpenAI is investigating more incidents of AI agents going rogue days after hack
OpenAI logo on Microsoft surface

It appears that the "AI agents going rogue" tale has more to it than what AI giants have revealed publicly so far. Merely days after OpenAI announced that its AI agents went rogue and hacked Hugging Face, Anthropic dropped a similar bombshell. Soon, it was discovered that not just one, but multiple services were compromised. Well, it seems there are even more layers to it.

Reuters reports that OpenAI has found more incidents of AI agents escaping their software containment environment during research. Citing sources with knowledge of the incident, the outlet notes that the AI agents didn't go beyond OpenAI's software environment and affect any external service.

Read more
AI is finding Apple security flaws faster than Apple can sort through them
Apple has limited how many bug reports researchers can keep open as AI tools produce both genuine Mac vulnerabilities and a flood of questionable submissions
Lighting, Architecture, Building

Apple has capped the number of security reports researchers can keep open at once after AI bug hunting put its review process under pressure, according to the Financial Times.

Some submissions describe hallucinated or purely theoretical risks. Others uncover vulnerabilities serious enough to require patches. Bynario told the FT that it found more than 50 possible macOS flaws in three weeks, including a privilege-escalation chain that could give an attacker full control of a Mac.

Read more
Anthropic is paying $1.5 billion over pirated books, but it can still legally cut up purchased ones
The settlement addressed unauthorized ebook downloads, not the destructive scanning of lawfully bought physical copies, a distinction now alarming booksellers
Book, Publication, Indoors

A federal judge has approved Anthropic’s $1.5 billion settlement over nearly half a million pirated books. The same litigation also protected a more physical method of feeding its AI systems. Anthropic bought print books, removed their bindings, scanned every page and destroyed the originals.

The legal divide came down to acquisition. The settlement covers books downloaded from LibGen and PiLiMi, while the court treated Anthropic’s one-for-one conversion of purchased books into private digital files as fair use. Training AI models on lawfully acquired material was also considered transformative.

Read more