Tag: side channel attack
6 articles

New Spectre Variant BTR Exploits Linux Memory Despite Existing Defenses
Meet Branch Target Reuse (BTR), a new Spectre variant that cleverly exploits Linux memory, dodging existing defenses and leaving multiple JIT engines and the Linux kernel vulnerable. This sneaky attack uses a four-step sequence to tap into the CPU's indirect branch prediction structures.

New Spectre v2 Variant Exploits Linux Systems, Leaks Root Password Hashes
Researchers have uncovered a new Spectre v2 variant, dubbed Branch Target Reuse (BTR), that can exploit Linux systems and leak sensitive data, including root password hashes, in a matter of minutes. This attack can be executed in as little as 3-5 minutes, leaving systems vulnerable to potential breaches.

Cloudflare Workers Exposed to Remote Spectre Attack
Researchers have successfully demonstrated a remote Spectre attack on Cloudflare Workers, exfiltrating a secret JSON Web Token (JWT) at an alarming rate of 12 bits per second - roughly 360 times faster than previously shown. This chilling exploit could have devastating consequences in the wrong hands.

Researchers Expose TONTOU Attack Bypassing Spectre v2 Fixes
Meet the TONTOU attack, a sneaky new exploit that lets hackers read sensitive data, like hashed passwords, from a system without needing special access - and it can bypass current Spectre v2 defenses. Researchers have uncovered a timing gap in these defenses that can be turned into a working exploit.

Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel, AMD CPUs
Researchers have uncovered a shocking vulnerability that allows an unprivileged local program to bypass Spectre v2 defenses on Intel and AMD CPUs, leaking kernel memory with alarming speed and accuracy. On an AMD Zen 2 system, this exploit can siphon off sensitive data at a rate of 5.47 bytes per second with near 92% accuracy, making it possible to crack even highly secured files like /etc/shadow.

FROST Attack Exploits SSD Timing to Track User Activity
Imagine a sneaky new technique that lets hackers track your online activity from afar, using just a web page and the timing of your SSD reads - no need to be physically on your device. This clever exploit, dubbed FROST, turns browser storage into a timing spy, revealing your browsing habits and even which native apps you open.