LIVE · cybersecurity feed
Live wire

intel

spectrehigh

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

Researchers have developed a new speculative execution attack called TONTOU, which can bypass existing Spectre defenses on both Intel and AMD processors. The attack exploits a timing window after security mitigations are applied, using precisely timed interrupts to re-poison the branch predictor. This allows attackers to divert control flow and leak sensitive kernel data, demonstrated by a successful exploit against AMD Zen 2 that bypassed KASLR and leaked password hashes.