Security News

CacheOut/L1DES: New Speculative Execution Attack Affecting Intel CPUs
2020-01-28 12:32

Intel on Monday informed customers that researchers have identified yet another speculative execution attack method that can be launched against systems that use its processors. The disclosure of the Meltdown and Spectre vulnerabilities back in January 2018 paved the way for the discovery of several speculative execution side-channel attack methods impacting modern processors.

New 'CacheOut' Attack Leaks Data from Intel CPUs, VMs and SGX Enclave
2020-01-28 08:36

If your computer is running any modern Intel CPU built before October 2018, it's likely vulnerable to a newly discovered hardware issue that could allow attackers to leak sensitive data from the OS kernel, co-resident virtual machines, and even from Intel's secured SGX enclave. Dubbed CacheOut a.k.a. L1 Data Eviction Sampling and assigned CVE-2020-0549, the new microarchitectural attack allows an attacker to choose which data to leak from the CPU's L1 Cache, unlike previously demonstrated MDS attacks where attackers need to wait for the targeted data to be available.

Oracle's January 2020 CPU Delivers 334 New Patches
2020-01-15 13:28

Oracle has released its first Critical Patch Update for 2020, which includes a total of 334 new security patches across multiple product families. The company notes that 40 of the new patches address critical issues.

Microsoft movie tried to Azure Ignite attendees about CPU side-channel flaws, but biz wouldn't be drawn on details
2019-12-12 10:00

'Sir, they're about to disclose the vulns!' 'Damn it. Accelerate the rollout!' How does Microsoft mitigate the risk of speculative-execution bugs on its Azure platform? The US goliath is unwilling...

Modern Intel CPUs Plagued By Plundervolt Attack
2019-12-11 16:01

The Intel attack uses a similar technique that gamers commonly use to overclock their CPUs.

New PlunderVolt Attack Targets Intel SGX Enclaves by Tweaking CPU Voltage
2019-12-11 01:32

A team of cybersecurity researchers demonstrated a novel yet another technique to hijack Intel SGX, a hardware-isolated trusted space on modern Intel CPUs that encrypts extremely sensitive data to...

New ZombieLoad v2 Attack Affects Intel's Latest Cascade Lake CPUs
2019-11-13 15:48

Zombieload is back. This time a new variant (v2) of the data-leaking side-channel vulnerability also affects the most recent Intel CPUs, including the latest Cascade Lake, which are otherwise...

Newer Intel CPUs Vulnerable to Variant 2 of ZombieLoad Attack
2019-11-13 12:49

Researchers have disclosed a new variant of the attack method dubbed ZombieLoad, which appears to also impact Intel CPUs that are not affected by the first variant of ZombieLoad. read more

Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack
2019-09-11 14:24

A new attack on Intel server-grade CPUs could allow the leakage of SSH passwords - but luckily it's not easy to exploit.

NetCAT: New Attack Lets Hackers Remotely Steal Data From Intel CPUs
2019-09-11 13:18

Unlike previous side-channel vulnerabilities disclosed in Intel CPUs, researchers have discovered a new flaw that can be exploited remotely over the network without requiring an attacker to have...