Security flaws pile up in support applications installed by PC manufacturers
A group of attackers uses the Gorynych botnet to deploy point-of-sale malware and steal payment card data
The problematic Dell Foundation Services tool might have updated itself on systems bought before August
The keys were hard-coded by manufacturers and can be used by attackers to launch man-in-the-middle attacks
The vulnerabilities could allow attackers with access to limited user accounts to gain administrator privileges
The Dell System Detect application also installs a self-signed root certificate on computers
The full scope of the incident is still unclear, but there's a removal tool available
Attackers could generate rogue certificates to spy on Dell customers' encrypted Web traffic
The program turns digital code signatures against anti-malware products
A large scale security test of firmware images for embedded devices easily found thousands of vulnerabilities