Skip to main content

Tag: cpu vulnerabilities

4 articles

Computer chip on laboratory bench surrounded by scientific instruments.

New Spectre Variant BTR Exploits Linux Memory Despite Existing Defenses

Meet Branch Target Reuse (BTR), a new Spectre variant that cleverly exploits Linux memory, dodging existing defenses and leaving multiple JIT engines and the Linux kernel vulnerable. This sneaky attack uses a four-step sequence to tap into the CPU's indirect branch prediction structures.

Analyst 207
Researcher examines laptop screen in university lab setting.

MIT Researchers Expose TONTOU Attack Bypassing Spectre Defenses on Intel, AMD CPUs

MIT researchers have uncovered a clever new attack, dubbed TONTOU, that can bypass Spectre defenses on Intel and AMD CPUs, revealing a practical exploit on AMD Zen 2. This innovative technique, presented at DEF CON 34, challenges current security assumptions and opens up new avenues for exploration.

Analyst 207
Computer processor on a laboratory bench with scientific instruments in the background.

Researchers Expose TONTOU Attack Bypassing Spectre v2 Fixes

Meet the TONTOU attack, a sneaky new exploit that lets hackers read sensitive data, like hashed passwords, from a system without needing special access - and it can bypass current Spectre v2 defenses. Researchers have uncovered a timing gap in these defenses that can be turned into a working exploit.

Analyst 207
Close-up of a computer processor on a lab bench surrounded by testing equipment.

Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel, AMD CPUs

Researchers have uncovered a shocking vulnerability that allows an unprivileged local program to bypass Spectre v2 defenses on Intel and AMD CPUs, leaking kernel memory with alarming speed and accuracy. On an AMD Zen 2 system, this exploit can siphon off sensitive data at a rate of 5.47 bytes per second with near 92% accuracy, making it possible to crack even highly secured files like /etc/shadow.

Analyst 207