/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher: PCs with Thunderbolt ports have an unpatchable flaw letting hackers with physical access circumvent data safeguards; some new PCs are not affected

The so-called Thunderspy attack takes less than five minutes to pull off with physical access to a device, and affects any PC manufactured before 2019.

Wired Andy Greenberg

Context & Ripple Effects

Thunderspy is the third act in a decade-long Thunderbolt firmware saga. Back in 2015, a researcher showed he could rewrite Mac firmware over Thunderbolt, flagging most Intel Thunderbolt Macs as exposed, and by 2017 researchers found an alarming number of Macs still vulnerable to stealthy hacks because of outdated EFI firmware — with Windows and Linux machines likely at risk too.

What changed today is scope and finality: the flaw now named Thunderspy affects any PC manufactured before 2019, needs under five minutes of physical access, and cannot be patched — while some newer PCs ship unaffected. That turns a long-running research thread into a concrete procurement and device-retirement problem.

First-order effects

  • Owners and enterprises running pre-2019 Thunderbolt-equipped PCs have no patch to deploy; their only mitigations are physical-access controls and treating any device that leaves their sight as potentially compromised.
  • PC makers whose current models are unaffected gain an immediate security differentiator they can market against the installed base of vulnerable older machines.

Second-order effects

  • Corporate IT refresh cycles get a security justification: fleets bought before 2019 now carry a documented, unfixable exposure, pressuring buyers toward replacement rather than extended lifecycles.
  • Intel and the Thunderbolt ecosystem face renewed scrutiny over why the same port-to-firmware attack class has resurfaced since 2015, pushing demand for verifiable, signed firmware updates on future hardware.

Third-order effects

  • If the pattern holds — firmware flaws in peripheral ports disclosed in 2015, 2017, and now 2020 — hardware-level firmware verification and attestation stop being optional hardening and become a baseline procurement requirement for laptops.
  • Physical access moves up the threat-model hierarchy for enterprises: an unpatchable five-minute attack makes device custody policies, not just software patching, part of the security perimeter.

The trend: Peripheral-interface firmware is proving to be a persistent, decade-spanning attack surface that software patches cannot reach, shifting the security burden toward hardware-verified firmware in future PC designs.

Discussion

  • @campuscodi Catalin Cimpanu on x
    Oh, look. Some disclosure drama https://twitter.com/...
  • @abacjourn Arif Bacchus on x
    This is why Microsoft was right. Thunderbolt is indeed a security risk. https://www.digitaltrends.com/ ... https://twitter.com/...
  • @paulmillr Paul Miller on x
    This looks bad. An attacker could read your encrypted drive & contents of a RAM, even when the laptop is sleeping. All it takes is inserting a device into USB/Thunderbolt port. All macbooks are affected, even with Linuxes. Can't be fixed in software. https://thunderspy.io/
  • @a_greenberg Andy Greenberg on x
    Intel says computers that have Kernel Direct Memory Access Protection enabled are safe, but that feature is only available in some PCs sold since 2019. @0Xiphorus has released a tool to see if your computer is vulnerable here: https://thunderspy.io/
  • @backchnnl Backchannel on x
    The so-called Thunderspy attack takes less than five minutes to pull off with physical access to a device, and affects any PC manufactured before 2019. https://www.wired.com/...
  • @campuscodi Catalin Cimpanu on x
    Thunderspy works even if you follow best security practices by locking or suspending your computer when leaving briefly, and if your system administrator has set up the device with Secure Boot, strong BIOS and operating system account passwords, and enabled full disk encryption.
  • @nicolasmagand Nicolas Magand on x
    Say what you will about the VGA port but it had never let us down like this. Thunderbolt, more like Thunderdolt. via @Techmeme https://www.wired.com/...
  • @0xiphorus Bjrn Ruytenberg on x
    This has been a long time coming. Today we release Thunderspy. Find full details at https://thunderspy.io/. Thanks to @a_greenberg for reporting. #Thunderspy #Intel #Thunderbolt https://twitter.com/...
  • @devindra Devindra Hardawar on x
    So I guess that Surface engineer was right? https://twitter.com/...
  • @mattiasgeniar Mattias Geniar on x
    “If your computer has a Thunderbolt port, an attacker who gets brief physical access to it can read and copy all your data, even if your drive is encrypted and your computer is locked or set to sleep.” tl;dr: stop using computers. ¯\_(ツ)_/¯ https://thunderspy.io/
  • @brianfagioli Brian Fagioli on x
    @Techmeme @a_greenberg AMD PCs aren't affected then.
  • @kennwhite Kenn White on x
    “Thunderspy [Intel exploit] enables creating arbitrary Thunderbolt device identities and cloning user-authorized Thunderbolt devices, even in the presence of Security Levels pre-boot protection and cryptographic device authentication” https://twitter.com/...
  • @0xiphorus Bjrn Ruytenberg on x
    @wdormann @a_greenberg Sadly, no. Intel's Kernel DMA protection requires hardware and BIOS support that weren't shipped prior to 2019. It also requires OS support but that is much easier to fix. See https://thunderspy.io/... for details.
  • @z3rotrust @z3rotrust on x
    “All the evil maid needs to do is unscrew the backplate, attach a device momentarily, reprogram the firmware, reattach the backplate, and the evil maid gets full access to the laptop,” https://www.wired.com/... via @wired
  • @joeressington Joe Ressington on x
    I don't understand how a person can find a vulnerability with Thunderbolt, go to the trouble of making a website about it, and NOT call it Thunderstruck. Once again they've really missed a trick here. https://thunderspy.io/
  • @stevesi Steven Sinofsky on x
    Thunderbolt Flaws Expose Millions of PCs to Hands-On Hacking https://www.wired.com/... @wired // Thunderbolt was always risky. Windows has 1st party thunderbolt because if Microsoft didn't do it then there would have been worse vulnerabilities due to uneven support by OEMs/Intel.
  • @wired @wired on x
    A newly-found vulnerability in thunderbolt ports could leave any PC built before 2019 open to hacking—even if the machine is asleep or locked. https://www.wired.com/...
  • @a_greenberg Andy Greenberg on x
    Dutch researcher @0Xiphorushas has detailed a new physical access technique that could let hackers break into any of millions of PCs via their Thunderbolt ports. The good news is it requires unscrewing the case briefly. The bad news is it's unpatchable. https://www.wired.com/...