Security News

Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
2024-10-18 14:48

The latest generations of Intel processors, including Xeon chips, and AMD's older Zen 1, Zen 1+, and Zen 2 microarchitectures on Linux are vulnerable to new speculative execution attacks that...

GhostWrite: New T-Head CPU Bugs Expose Devices to Unrestricted Attacks
2024-08-13 14:02

A team of researchers from the CISPA Helmholtz Center for Information Security in Germany has disclosed an architectural bug impacting Chinese chip company T-Head's XuanTie C910 and C920 RISC-V...

AMD won’t patch Sinkclose security bug on older Zen CPUs
2024-08-13 03:14

The bug allows malicious software and rogue privileged users with access to the operating system kernel to run code in System Management Mode, a highly privileged execution environment present in x86 processors from Intel and AMD. SinkClose is unique to AMD. SMM sits below the kernel and hypervisor, as well as applications, in that the management mode has unrestricted access to and control of the machine. ZenHammer comes down on AMD Zen 2 and 3 systems Apple, AMD, Qualcomm GPU security hole lets miscreants snoop on AI training and chats What's going on with AMD funding a CUDA translation layer, then nuking it? AMD's latest desktop CPUs feature lower prices yet again as Intel readies a fightback.

Raptor Lake microcode limits Intel chips to a mere 1.55 volts to prevent CPU destruction
2024-08-09 19:16

Intel has divulged more details on its Raptor Lake family of 13th and 14th Gen Core processor failures and the 0x129 microcode that's supposed to prevent further damage from occurring. The chipmaker previously disclosed that the so-called instability issue plaguing many Raptor Lake chips stems from an elevated operating voltage set by the processor itself.

Faulty instructions in Alibaba's T-Head C910 RISC-V CPUs blow away all security
2024-08-07 17:00

Black Hat Computer security researchers at the CISPA Helmholtz Center for Information Security in Germany have found serious security flaws in some of Alibaba subsidiary T-Head Semiconductor's RISC-V processors. Thus the security issues here with the C910 lie with T-Head's own implementation of the ISA, specifically its non-standard implementation of the vector extension, and not the specs themselves nor other RISC-V chips.

New Intel CPU Vulnerability 'Indirector' Exposes Sensitive Data
2024-07-02 10:28

Modern CPUs from Intel, including Raptor Lake and Alder Lake, have been found vulnerable to a new side-channel attack that could be exploited to leak sensitive information from the processors. The...

Latest Intel CPUs impacted by new Indirector side-channel attack
2024-07-01 14:24

Modern Intel processors, including chips from the Raptor Lake and the Alder Lake generations are susceptible to a new type of a high-precision Branch Target Injection attack dubbed 'Indirector,' which could be used to steal sensitive information from the CPU. Indirector exploits flaws in Indirect Branch Predictor and Branch Target Buffer, two hardware components found in modern Intel CPUs, to manipulate speculative execution for data extraction. The Indirect Branch Predictor is designed to predict the target addresses of indirect branches using historical execution information, while the Branch Target Buffer predicts the target addresses of direct branches using a set-associative cache structure.

Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs
2024-06-20 14:22

Cybersecurity researchers have disclosed details of a now-patched security flaw in Phoenix SecureCore UEFI firmware that affects multiple families of Intel Core desktop and mobile processors....

New Spectre-Style 'Pathfinder' Attack Targets Intel CPU, Leak Encryption Keys and Data
2024-05-08 14:17

Researchers have discovered two novel attack methods targeting high-performance Intel CPUs that could be exploited to stage a key recovery attack against the Advanced Encryption Standard (AES)...

New Spectre v2 attack impacts Linux systems on Intel CPUs
2024-04-10 17:19

Researchers have demonstrated the "First native Spectre v2 exploit" for a new speculative execution side-channel flaw that impacts Linux systems running on many modern Intel processors. Spectre V2 is a new variant of the original Spectre attack discovered by a team of researchers at the VUSec group from VU Amsterdam.