Security News

Researchers Disclose Two New Attacks Against AMD CPUs
2020-03-09 14:51

Researchers have identified two new methods for attacking AMD processors, but they are not as dangerous as some of the previously disclosed CPU attacks. The Collide+Probe attack can also be launched remotely via a web browser without user interaction, which the experts have shown through an attack on ASLR. "We evaluated our new attack techniques in different scenarios. We established a high-speed covert channel and utilized it in a Spectre attack to leak secret data from the kernel," the researchers said.

9 Years of AMD Processors Vulnerable to 2 New Side-Channel Attacks
2020-03-09 07:20

AMD processors from as early as 2011 to 2019 carry previously undisclosed vulnerabilities that open them to two new different side-channel attacks, according to a freshly published research. Known as "Take A Way," the new potential attack vectors leverage the L1 data cache way predictor in AMD's Bulldozer microarchitecture to leak sensitive data from the processors and compromise the security by recovering the secret key used during encryption.

9 Years of AMD Processors Vulnerable to 2 New Side-Channel Attacks
2020-03-09 07:20

AMD processors from as early as 2011 to 2019 carry previously undisclosed vulnerabilities that open them to two new different side-channel attacks, according to a freshly published research. Known as "Take A Way," the new potential attack vectors leverage the L1 data cache way predictor in AMD's Bulldozer microarchitecture to leak sensitive data from the processors and compromise the security by recovering the secret key used during encryption.

Multiple Vulnerabilities Found in AMD ATI Radeon Graphics Cards
2020-01-22 22:04

Security vulnerabilities in some AMD ATI Radeon graphics cards could allow attackers to remotely execute code or cause a denial of service condition, researchers from Cisco Talos have warned. A total of four security flaws were disclosed, all of them impacting the AMD ATIDXX64.

IGEL integrates the AMD Secure Processor on IGEL UD7 endpoints
2019-12-05 00:15

IGEL, provider of the next-gen edge OS for cloud workspaces, announced that it has integrated the AMD Secure Processor on IGEL UD7 endpoints, effectively creating a dedicated ‘chain of trust’...

A Broken Random Number Generator in AMD Microcode
2019-10-31 11:24

Interesting story. I always recommend using a random number generator like Fortuna, even if you're using a hardware random source. It's just safer....

How to break out of a hypervisor: Abuse Qemu-KVM on-Linux pre-5.3 – or VMware with an AMD driver
2019-09-18 10:27

Pair of bug reports show how VM escapes put servers at risk A pair of newly disclosed security flaws could allow malicious virtual machine guests to break out of their hypervisor's walled gardens...

AMD Radeon Graphics Cards Open VMware Workstations to Attack
2019-09-17 17:03

Bug impacts VMware Workstation 15 running 64-bit versions of Windows 10 as the guest VM.

AMD Radeon Driver Flaw Leads to VM Escape
2019-09-17 13:37

A vulnerability in the AMD ATI Radeon ATIDXX64.DLL driver could be triggered from within a VMware guest to execute code on the host, Cisco Talos warns. read more

Deja-woooo: Intel, AMD chips running Windows potentially vulnerable to scary Spectre variant
2019-08-06 23:01

SWAPGS attack can leak sensitive secrets from kernel memory, patches already available Spectre – a family of data-leaking side-channel vulnerabilities arising from speculative execution that was...