Alder Lake BIOS Source Code

Chipmaker Intel has confirmed that proprietary source code
related to its Alder Lake CPUs has been leaked, following its
release by an unknown third-party on 4chan and GitHub last
week.

The published content contains Unified Extensible Firmware
Interface (UEFI[1]) code for Alder
Lake
[2], the company’s 12th
generation processors that was originally launched in November
2021.

In a statement shared with Tom’s Hardware, Intel said[3]
the leak doesn’t expose “any new security vulnerabilities as we do
not rely on obfuscation of information as a security measure.”

CyberSecurity

It’s also encouraging the broader security research community to
report any potential issues through its bug bounty
program
[4], adding it’s reaching
out to customers to notify them of the matter.

Besides the UEFI code, the leaked data dump includes a plethora
of files and tools, some of which appear to come from firmware
vendor Insyde Software.

BIOS Source Code

Exact details surrounding the nature of the hack, including its
provenance, are unclear. The GitHub
repository
[5] has since been taken
down, although it remains accessible via other replicated
versions.

CyberSecurity

That said, indications are that the repository had been created[6]
by an employee of LC Future Center[7], a Chinese manufacturer
of computers and laptops.

Earlier this February, the LAPSUS$ extortionist group breached NVIDIA[8], siphoning 1TB of
sensitive data. The threat actor later claimed that the company had
launched a retaliatory ransomware strike to prevent the release of
the stolen data.

References

  1. ^
    UEFI
    (en.wikipedia.org)
  2. ^
    Alder
    Lake
    (en.wikipedia.org)
  3. ^
    said
    (www.tomshardware.com)
  4. ^
    bug
    bounty program

    (www.projectcircuitbreaker.com)
  5. ^
    GitHub
    repository
    (github.com)
  6. ^
    created
    (twitter.com)
  7. ^
    LC Future Center
    (www.lcfc.com.cn)
  8. ^
    breached
    NVIDIA
    (thehackernews.com)

Read more