CTS Labs Speaks: Why It Blindsided AMD With Ryzenfall And Other Vulnerabilities

Researchers often reveal new vulnerabilities with flashy websites, clever branding, and a concerted effort to make sure the problems are covered by media outlets (like this one). The newly announced flaws in AMD's Ryzen and EPYC processors are no exception to this rule--in fact, their revelation was even more focused on garnering attention from the public than many other disclosures. It was just missing one thing: time for AMD to respond.

Latest Videos FromTom's Hardware
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • Math Geek
    sounds to to me like this new CTS Labs needed a way to get their name on the map. so when the chance came they made as big of a splash as they could despite the norms that exist for this sort of thing.

    they only have to do it this way once, now everyone knows who they are so mission accomplished. now they can follow the standards and enjoy the fact people actually know who they are now.

    that is unless they just decide to be unethical and push things into the public eye faster than it should be.
    Reply
  • philipemaciel
    Fishy.
    Reply
  • plateLunch
    If it's any consolation to anyone, it doesn't look like the big stock traders are taking the CTS report very seriously. Outside of the short squeeze yesterday, price action looks pretty normal. My guess is Viceroy and the gang haven't gotten anywhere close to the reaction they wanted.
    Reply
  • Garrek99
    Ego and pride seem to be the motivating factors here.
    What kind of reasoning is "well, they wouldn't be able to fix it in months so we are going to drop a bomb now".
    It's stupid and irresponsible. Now everyone is going to be looking for ways to exploit the vulnerabilities and we all will stand to be victims of cyber attacks.
    Thanks CTS!
    Reply
  • tm.arduino
    @Math Geek
    Which name? "Flexigard", "Catenoid" or "CTS Labs"?
    They had to change their name after being outed as the authors of the "CrowdScores" adware/virus.

    https://imgur.com/a/2cV3k
    Reply
  • bjameson
    I think the author forgot that these are flaws rather than vulnerabilities. The attacker must already have admin access or signed digital certificated before being able to hack the server.

    Like in the analogy provided everywhere, you gave the burglar your keys, then the burglar set-up a web cam inside your house. The burglar could have already taken everthing inside the house and run but CTS Labs focused on the burglar setting up the web cams to monitor what is going on inside the house.
    Reply
  • lucamanliodelisi
    I think the press should stop talking about this hoax. How can you claim something is a vulnerability when you have to physically be in contact with the machine in order to make it happen? Or even have to flash a custom BIOS? LOL guys, I am guilty as well of writing about it (but views are views) but let these clowns fall into oblivion: the place that they truly deserve. It was just a bad move in order to try and bank in with stock prices.
    Reply
  • redgarl
    Why is toms giving credibility to a firm with absolutely none whatsoever, true or not. These guys needs to be sued.
    Reply
  • danaj525
    The fact that Tom's hardware doesn't even reshearch this is pretty sad. First and foremost these flaws are the same flaws we've had since the 90s which you can find on Twitter by tech bits I believe. Oh and the fact that the guy you talked to is a CEO of a f-ing hedge fund company. So if any of you would like to give me your admin rights so I can have your system fill free to do so because that's what it take.

    Shame on you Tom's hardware!
    Reply
  • abundantcores
    Toms Hardware: your conclusion, i quote.

    "Altogether, it seems that AMD customers may be justified in worrying about these vulnerabilities. If CTS Labs' description of them is accurate, they are remotely exploitable flaws that could allow attackers to install persistent malware in the deepest recesses of a system. That puts consumers at risk, and it could also undermine businesses' secure networks simply because they rely on Ryzen or EPYC processors"

    Are you crazy? did you even bother to look at how CTS Labs hacked into these system before you made that insane conclusion? they flashed a hacked BIOS onto the system to disable the CPU's security features, if you allow some one to flash a dodgy BIOS onto your PC then the fault is with you, not AMD, good grief what is wrong with you people? is this the quality of your journalism because its absolutely atrocious. this site is nothing more than a low brow click farm.
    Reply