Meltdown & Spectre: Serious CPU bugs affect Desktops, Servers and Smartphones
Operating system vendors, cloud storage providers and other tech firms are scrambling to mitigate the affects of serious CPU vulnerabilities affecting servers, desktops and even mobile devices.
The hardware bugs have been dubbed Meltdown and Spectre. Meltdown is named for the metaphorical melting of security boundaries that are taken as a given because they are enforced by hardware itself. Spectre is named based on the root cause of the bug; speculative execution.
Both are very serious and are almost certain to affect you. Meltdown (CVE-2017-5754) breaks the isolation between user applications and the operating system. Applications that exploit the hardware bug can access the OS / System memory and the memory of other applications. In essence, this means a malicious (though seemingly benign) application can steal sensitive data from memory. Applied to cloud services, this brings up the possibility of sensitive information being stolen from other customers, though cloud providers have already addressed the issue for the most part.
Spectre (CVE-2017-5753 and CVE-2017-5715) breaks the expected isolation between different applications. If exploited, it allows a malicious application to trick error-free programs into leaking sensitive information. What makes it even worse is that the discoverers of Spectre say the safety checks of said best practices actually increase the attack surface and may make applications more susceptible to Spectre.

SpaceX is preparing to finally test its Falcon Heavy rocket later this month, and has released a video showing the powerful vehicle sitting on the pad.
The World Health Organization is set to class gaming addiction as a mental health condition for the first time.




