« All posts

New TONTOU CPU Attack Bypasses Spectre v2 Fixes, Leaks Linux Passwords

Researchers developed an exploit that bypasses Spectre v2 mitigations to leak password hashes from Linux systems.

Researchers have discovered a method to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks, successfully leaking sensitive data from Linux machines. This exploit targets the gap in neutralization-based mitigations on AMD and Intel processors.