The Spectre of a Meltdown? How to Avoid the Latest Cybersecurity Threats

January 9, 2018

With names reminiscent of those of movie villains, the "Meltdown" and "Spectre" computer flaws pose dire real-world risks to computers, devices and networks worldwide.

"Meltdown" is a flaw that affects only computers and server equipment that use Intel chips or processors. It essentially offers hackers a "back door" to access a computer's memory and anything saved in that memory, including passwords saved in Web browsers for frequently visited websites.

The "Spectre" flaw affects chips in smartphones and tablets, in addition to Intel's computer chips and those from Advanced Micro Devices, Inc. Spectre allows hackers to manipulate apps to cause them to leak sensitive information. While researchers suggest that Spectre may be less dangerous than Meltdown, because of the number of devices affected across multiple platforms, Spectre may prove more difficult to patch. The only known device that may be immune to the Spectre flaw is the Apple Watch.

There are no known breaches as a result of Meltdown or Spectre yet. Nonetheless, the risk is so serious that Microsoft, Apple and Linux have all issued security alerts, and have issued, or are issuing, security updates and patches to protect computers, servers and devices.

What can your company do to protect itself?

First, download immediately all security updates and/or patches that the manufacturers of your company's computers, equipment and networks offer. Do not wait.

Second, delete all saved passwords stored on your company's web browsers. Consider changing all employee passwords as soon as the security patches are installed.

While Meltdown and Spectre may increase your risk of external penetration, the greatest known risk to your company's cybersecurity is not external - it's your employees. Take the following measures to minimize the risks:

  • Remind your employees not to use their company passwords to log in to any other sites, not to share their passwords with anyone, and never to store or save their passwords on Internet browsers connected to your company.
  • Prohibit your employees from downloading or transferring files, software or other material from personal computers onto your company's computers or networks. This will prevent infected files from migrating onto your system.
  • Remind your employees not to click on links in, or open documents attached to, emails, without checking with your IT department first. Phishing remains the most common method for hackers to access computer systems.


Related Practices
Client Alert February 2, 2023
On December 15, 2022, the Environmental Protection Agency published a final rule recognizing ASTM E1527-21 as the new standard for performing a Phase I Environmental Site Assessment (“ESA”). With this final rule, the “-21 standard” will become the governing standard to satisf...
Press Release January 27, 2023
In collaboration with the University of Miami (UM), Bilzin Sumberg is pleased to announce the commencement of “Bilzin Sumberg University”. The inaugural 12-month leadership development program addresses competencies for Bilzin Sumberg partners to be successful today and in the future.
Press Release January 26, 2023
Bilzin Sumberg is proud to announce it has been awarded the 2023 Chief Justice’s Law Firm Commendation Pro Bono Service Award in recognition of the firm’s outstanding efforts in support of pro bono services in the state of Florida.