Tag: side channel attack
3 articles

Researchers Expose TONTOU Attack Bypassing Spectre v2 Fixes
Meet the TONTOU attack, a sneaky new exploit that lets hackers read sensitive data, like hashed passwords, from a system without needing special access - and it can bypass current Spectre v2 defenses. Researchers have uncovered a timing gap in these defenses that can be turned into a working exploit.

Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel, AMD CPUs
Researchers have uncovered a shocking vulnerability that allows an unprivileged local program to bypass Spectre v2 defenses on Intel and AMD CPUs, leaking kernel memory with alarming speed and accuracy. On an AMD Zen 2 system, this exploit can siphon off sensitive data at a rate of 5.47 bytes per second with near 92% accuracy, making it possible to crack even highly secured files like /etc/shadow.

FROST Attack Exploits SSD Timing to Track User Activity
Imagine a sneaky new technique that lets hackers track your online activity from afar, using just a web page and the timing of your SSD reads - no need to be physically on your device. This clever exploit, dubbed FROST, turns browser storage into a timing spy, revealing your browsing habits and even which native apps you open.