-
Update: No, Virginia, there are no Meltdown/Spectre exploits in the wild
A reassuring tweet from Kevin Beaumont.
As I understood it, malware has been found*, presumably in the wild, that includes the Meltdown PoC. But that still doesn't mean that they actually exploited the vulnerability in the wild.
* this is the real source: https://t.co/sjns6JUmnV— Martijn Grooten (@martijn_grooten@mastodon.social) (@martijn_grooten) February 1, 2018
The AV-Test red line graph shows that, yes, there are more and more samples being submitted to AV-Test — but, according to people who know these things, none of them are in the wild. They’re “Proof of Concept” test samples.
UPDATE: And AV-Test responds:
That's correct, we've tried to avoid using the term "malware", because the majority of the samples appear to be PoC, even if most anti-malware products added detection of these samples during the last few days. @martijn_grooten @EscInSecurity https://t.co/eNPf34Numb
— AV-TEST GmbH (@avtestorg) February 2, 2018