Skip to main content

If you have a Gigabyte motherboard, your PC might stealthily download malware

Yet another motherboard manufacturer seems to be in trouble — or rather, the people who own those motherboards might be. According to security researchers, countless Gigabyte boards might be vulnerable to dangerous cyberattacks.

If you want to be extra safe, there are a couple of things you can do to protect your PC. Here’s what we know.

A Gigabyte Aorus Extreme motherboard.
Gigabyte

According to a report published by security company Eclypsium, many Gigabyte motherboards are at risk. Eclypsium published a full list of the models that are affected by the vulnerability, and that list alone encompasses over 270 different entries. That means that if you own a Gigabyte board, chances are that you’re affected by this too. Both AMD and Intel platforms might be compromised.

Recommended Videos

To give you a quick recap on what’s going on, Eclypsium has found a vulnerability within the firmware of those Gigabyte motherboards. Gigabyte’s own software automatically updates the firmware without further prompts, and because of that, it opens the door to potential attacks.

The list of risks is huge, but individual users are in less danger than organizations that run multiple computers equipped with Gigabyte boards. This is because the attacker would have to be using the same network as you in order to divert the software updater to download a harmful payload instead of a new firmware update. Still, this could be dangerous and awfully difficult to get rid of. To make matters worse, out of the three possible download locations for Gigabyte’s firmware, one of them is only using a plain HTTP address instead of HTTPS, further lowering the security of the downloading process.

While this is a quite sophisticated and situational hack, if a threat actor or hacker group manages to carry out the attack, the consequences could be disastrous. Let’s go over them quickly.

For one, hackers could exploit vulnerable software built into a computer’s firmware in order to pose as a legitimate feature. From there, they could gain full access to the affected PC and network. UEFI rootkits and implants, which are a type of malware, also pose a great threat because they’re executed before your system even starts up. As such, not even reinstalling the operating system and wiping your drives clean would be enough to get rid of them.

Perhaps the worst thing of all is that the firmware download occurs during system start-up, so you’d likely be none the wiser until it would be too late. Eclypsium goes into a lot of detail in its report as to what the dangers of this vulnerability are, so make sure to read it here if you’re interested.

How to protect yourself

The front of a Project Stealth PC.
Gigabyte

Gigabyte is working with Eclypsium in order to fix this issue. The company released an official statement, saying that its engineers have already addressed the potential risks in the latest beta version of the BIOS. This means that owners of Intel 700/600 or AMD 500/400 boards could go ahead and download the update and stay safe, but using a beta version of the BIOS comes with some risks of its own. It’s unclear whether using it would affect the board warranty at this point.

Fortunately, Eclypsium has also provided a couple of fixes that can tide you over until Gigabyte clears everything up. You’ll first have to enter the BIOS. This is most commonly done by tapping the F2 or Del key over and over during the time when your PC is starting up, but if that doesn’t work, check out our guide on how to use the BIOS to see if there are any other keys you might need to mash here.

Once you’re on the options screen, navigate to the App Center Download & Install feature and disable it. This turns off automatic updates. We also recommend setting a BIOS password to add an extra layer of security.

Motherboards, in general, have had their share of troubles lately. As Gigabyte is battling this problem, Asus also finds itself in the crossfire following a huge AMD Ryzen 7000 controversy. Instead of a cybersecurity threat, users with Asus boards have found their PCs at risk of burning up.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
We might have an answer to Intel’s crashing crisis
Intel's 14900K CPU socketed in a motherboard.

Intel is facing some big problems with its 13th-gen and 14th-gen CPUs. As we reported on last week, gamers are returning high-end Intel CPUs in droves because of inexplicable crashes when playing the latest games. Now, we might have a solution, at least until Intel can tackle the problem properly.

The guidance comes from Falcon Northwest, which is a Portland-based system builder that received a rare perfect score from Digital Trends (read our Falcon Northwest Tiki review for more on that). Kelt Reeves, president of Falcon Northwest, said that the team has had "many long days of testing on many different CPUs that had developed issues here in our production and in the field from our clients." The result of that testing is a list of BIOS settings that should fix the problem.

Read more
AMD’s GPUs had a bigger year in 2023 than you might realize
AMD's RX 7700 XT in a test bench.

It's safe to say that 2023 turned out to be a good year for the discrete graphics cards market. According to the latest data, both AMD and Nvidia saw an increase in add-in board (AIB) GPU shipments in the final quarter of 2023, and the year-to-year gains are also massive. While Nvidia still dominates the market, AMD's share is climbing steadily, and Intel remains in the shadows.

Today's round of market insights comes from Jon Peddie Research (JPR), and it's all about discrete GPUs. According to the analyst firm, discrete GPU shipments increased by 6.8% over the fourth quarter of 2023 compared to the previous quarter. This is above the less-than-impressive 10-year average of -0.6%. The year-to-year gains are even more impressive, though, as JPR notes a 32% increase compared to the final quarter of 2022, with a total of 9.5 million GPUs shipped (as opposed to 8.9 million units at the end of 2022).

Read more
Everything you need to know about buying a power supply for your PC
Gigabyte Aorus P1200W power supply.

Picking out a PC power supply is a lot more challenging than it might seem at a glance. While there are always plenty of reviews of the best processors and top graphics cards, Power supply units (PSUs) tend to be a little overlooked. Still, the power supply should never be an afterthought when you're building a PC or buying a new one.

There are a few important rules to follow when you're picking out your PSU, ranging from making sure it fits your build to ensuring that it can handle power spikes and future upgrades. Here's everything you need to know when shopping for a power supply.
The importance of the PSU

Read more