Skip to main content

Tag: side channel attack

3 articles

Computer processor on a laboratory bench with scientific instruments in the background.

Researchers Expose TONTOU Attack Bypassing Spectre v2 Fixes

Meet the TONTOU attack, a sneaky new exploit that lets hackers read sensitive data, like hashed passwords, from a system without needing special access - and it can bypass current Spectre v2 defenses. Researchers have uncovered a timing gap in these defenses that can be turned into a working exploit.

Analyst 207
Close-up of a computer processor on a lab bench surrounded by testing equipment.

Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel, AMD CPUs

Researchers have uncovered a shocking vulnerability that allows an unprivileged local program to bypass Spectre v2 defenses on Intel and AMD CPUs, leaking kernel memory with alarming speed and accuracy. On an AMD Zen 2 system, this exploit can siphon off sensitive data at a rate of 5.47 bytes per second with near 92% accuracy, making it possible to crack even highly secured files like /etc/shadow.

Analyst 207
Laptop on a desk with blurred webpage on screen, surrounded by office items.

FROST Attack Exploits SSD Timing to Track User Activity

Imagine a sneaky new technique that lets hackers track your online activity from afar, using just a web page and the timing of your SSD reads - no need to be physically on your device. This clever exploit, dubbed FROST, turns browser storage into a timing spy, revealing your browsing habits and even which native apps you open.

Analyst 207