Most of you reading this article probably already know that most devices connected to the Internet are not secure. Any computer, any server, any device can be hacked and reconfigured for malicious purposes, often without the owner's knowledge. So USB sticks are no exception.
Some time ago we published that security researchers discovered a way to rewrite the firmware of USB sticks, making them malicious for their owners. This particular vulnerability is not detected by any security software.
According to Wired, the researchers decided to act. At the moment the hack that rewrites the firmware of a USB stick is being distributed freely on the internet. The code leaked directly from the security researchers who believe that by publishing the information they will force companies to fix the vulnerability.
High-level services, such as the NSA, may already have access to this code and thus will be able to exploit the vulnerability. However, now that everyone knows the hack, companies are forced to take action.
But what can happen with a hacked USB stick? Is the issue that serious?
Connecting a “hacked” USB stick to a PC the scammers can copy all your keystrokes, hide malicious software on your computer, or execute injections that could potentially spread the malicious code to other USB devices.
As we mentioned earlier, infected USB devices are almost undetectable and cannot be repaired with a format.
