Security Research Labs released exploit tools for a flaw in USB flash drive firmware last week. The tools were released two months after Berlin-based SRLabs demonstrated an attack on the vulnerability at the Black Hat security conference in Las Vegas. The vulnerability is in controllers designed by Phison Electronics, a Taiwanese company that sells the product to a very large number of USB thumb drive manufacturers. Experts say manufacturers should require signed firmware updates for USB controllers in order to prevent unauthorized modifications for unauthorized modifications. The other option is to disable the ability to change firmware once a device ships from the factory.”]

