Report Claims AMD Ryzen, EPYC CPUs Contain 13 Security Flaws (Updated)

Latest Videos FromTom's Hardware
Paul Alcorn
Editor-in-Chief

Paul Alcorn is the Editor-in-Chief for Tom's Hardware US. He also writes news and reviews on CPUs, storage, and enterprise hardware.

  • bit_user
    CTS-Labs provided AMD with only a 24-hour notice.
    This is extremely shady. What could be the purpose of making such an announcement, except to spread FUD in the market and put the brakes on AMDs sales momentum?

    These guys are most likely funded by Intel or individuals with a strong financial stake in Intel.
    Reply
  • fball922
    I thought the same thing... Hit piece. Intel is so full of sh*t I would not be surprised one bit if they funded this.
    Reply
  • madmatt30
    Covered themselves with that disclaimer big time.

    Whilst thats sensible for a firm like cts (nier a necessity) I would say the whole thing has very very suspicious undertones.

    I hope they have good lawyers if theyre wrong , bringing asus into the mix by name/brand aswell is a very risky decision.
    Reply
  • theunnerd
    The lack of comprehensive tech detail of these flaws compared to Spectre and Meltdown, even in the white paper, plus the lack of notice to AMD to look into the claim of flaws, sounds fishy to me. It was not released in good faith and the disclaimer of "Although we have a good faith belief in our analysis and believe it to be objective and unbiased, you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports." speaks for itself. Economic interest. They likely have friends trading the stock and pushing conveniently for a short situation, seems like manipulation. Walks like fake news, talks like fake news...What is it?
    Reply
  • JoeNM84
    Sounds like a rumor if there has been no evidence or sources listed. And given the short 24 hour notice it makes the whole thing a bit shady. Possibly to manipulate stock prices? Hopefully it's all false, or the vulnerabilities are easy/quick to fix.
    Reply
  • bit_user
    There's already a lot out there on debunking these overblown claims.

    Interestingly, they registered the domain 19 days ago, so they surely could have started informing AMD of some of the issues back then.

    One conjecture I've read is that it could be a simple stock market play - bet on AMD's share price to drop, then release a bunch of bad news.

    I hope AMD has some grounds to sue them on the basis of misleading statements.
    Reply
  • rwinches
    Shame on Tom's for not having a huge, bold type, disclaimer at the top of this stating there is no real data to back this up.
    Not even their tired 'grain of salt'
    Reply
  • Finstar
    "an Israel-based security company"
    Aaaand that's more than i need to tell this is bs.
    Reply
  • techy1966
    I was like LMAO at this crap....This is pure fud at it's best. All they or who ever is paying them to do this wants is AMD stocks to fall and sales drop off as well seems a bit timely that this happens just before AMD's new CPU launch/ refresh of Ryzen in April. I am thinking Intel or someone that has a stake in Intel is behind this. Problem is the damage is already done because all news sites and tubers will cover this like it is the Holy Gospel and plat the seed of fud into everyone's minds. By the way if this was true they would have been forced to give AMD the proper amount of time to get their crap together not this 24 hour crapola...I really hope who ever is behind this get sued big time and go to jail.
    Reply
  • tslot05qsljgo9ed
    Quote: Possibly to manipulate stock prices?

    That is exactly what it was and from todays headlines for AMD and initial sell off you can see that it worked for a while. But then common sense and analysis showed that this was purely a figment of CTS-Labs imagination.

    The 24 hour notice along with the amdflaws.com web site clearly shows the skeeviness of CTS-Labs.
    Reply