Skip to main content

Tag: side channel attack

6 articles

Computer chip on laboratory bench surrounded by scientific instruments.

New Spectre Variant BTR Exploits Linux Memory Despite Existing Defenses

Meet Branch Target Reuse (BTR), a new Spectre variant that cleverly exploits Linux memory, dodging existing defenses and leaving multiple JIT engines and the Linux kernel vulnerable. This sneaky attack uses a four-step sequence to tap into the CPU's indirect branch prediction structures.

Analyst 207
Rows of computer servers and networking equipment in a dimly lit data center interior.

New Spectre v2 Variant Exploits Linux Systems, Leaks Root Password Hashes

Researchers have uncovered a new Spectre v2 variant, dubbed Branch Target Reuse (BTR), that can exploit Linux systems and leak sensitive data, including root password hashes, in a matter of minutes. This attack can be executed in as little as 3-5 minutes, leaving systems vulnerable to potential breaches.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room.

Cloudflare Workers Exposed to Remote Spectre Attack

Researchers have successfully demonstrated a remote Spectre attack on Cloudflare Workers, exfiltrating a secret JSON Web Token (JWT) at an alarming rate of 12 bits per second - roughly 360 times faster than previously shown. This chilling exploit could have devastating consequences in the wrong hands.

Analyst 207
Computer processor on a laboratory bench with scientific instruments in the background.

Researchers Expose TONTOU Attack Bypassing Spectre v2 Fixes

Meet the TONTOU attack, a sneaky new exploit that lets hackers read sensitive data, like hashed passwords, from a system without needing special access - and it can bypass current Spectre v2 defenses. Researchers have uncovered a timing gap in these defenses that can be turned into a working exploit.

Analyst 207
Close-up of a computer processor on a lab bench surrounded by testing equipment.

Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel, AMD CPUs

Researchers have uncovered a shocking vulnerability that allows an unprivileged local program to bypass Spectre v2 defenses on Intel and AMD CPUs, leaking kernel memory with alarming speed and accuracy. On an AMD Zen 2 system, this exploit can siphon off sensitive data at a rate of 5.47 bytes per second with near 92% accuracy, making it possible to crack even highly secured files like /etc/shadow.

Analyst 207
Laptop on a desk with blurred webpage on screen, surrounded by office items.

FROST Attack Exploits SSD Timing to Track User Activity

Imagine a sneaky new technique that lets hackers track your online activity from afar, using just a web page and the timing of your SSD reads - no need to be physically on your device. This clever exploit, dubbed FROST, turns browser storage into a timing spy, revealing your browsing habits and even which native apps you open.

Analyst 207