spectre news
3 stories
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A new variant of the Spectre-v2 CPU vulnerability, termed Branch Target Reuse (BTR), has been reported by researchers. This attack reportedly enables the leakage of sensitive memory from Linux systems, even those equipped with existing Spectre-v2 mitigations. The vulnerability is said to specifically target Just-In-Time (JIT) engines, which are commonly found in web browsers, various runtimes,…

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cybersecurity researchers have reportedly demonstrated a refined Spectre attack targeting Cloudflare Workers, successfully exfiltrating a JSON Web Token (JWT) from a co-located Worker. The attack achieved a data leakage rate of 12 bits per second, which is described as a significant improvement in speed over prior iterations of similar attacks.

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
Researchers from MIT have unveiled a new speculative execution attack, dubbed TONTOU (Time-of-Neutralization to Time-of-Use), that circumvents existing defenses against Spectre v2. The attack, developed by Daniël Trujillo and Mengjia Yan of MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL), exploits a brief window between when branch predictor states are neutralized and…