LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication

spectre news

3 stories
CVE-2026-64507high

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A new variant of the Spectre-v2 CPU vulnerability, termed Branch Target Reuse (BTR), has been reported by researchers. This attack reportedly enables the leakage of sensitive memory from Linux systems, even those equipped with existing Spectre-v2 mitigations. The vulnerability is said to specifically target Just-In-Time (JIT) engines, which are commonly found in web browsers, various runtimes,…

spectrehigh

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cybersecurity researchers have reportedly demonstrated a refined Spectre attack targeting Cloudflare Workers, successfully exfiltrating a JSON Web Token (JWT) from a co-located Worker. The attack achieved a data leakage rate of 12 bits per second, which is described as a significant improvement in speed over prior iterations of similar attacks.

spectrehigh

MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

Researchers from MIT have unveiled a new speculative execution attack, dubbed TONTOU (Time-of-Neutralization to Time-of-Use), that circumvents existing defenses against Spectre v2. The attack, developed by Daniël Trujillo and Mengjia Yan of MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL), exploits a brief window between when branch predictor states are neutralized and…