Security News

Thought you'd fixed those Linux Spectre issues? Guess again, and AMD users need to be especially on their toes
2020-06-09 19:39

In three posts marked urgent to the Linux kernel mailing list on Tuesday, Anthony Steinhauser points out problems with countermeasures put in place to block Spectre vulnerabilities in modern Intel and AMD x86 microprocessors that perform speculative execution. The Spectre family of flaws involve making a target system speculate - perform an operation it may not need - in order to expose confidential data so an attacker can obtain it through an unprotected side channel.

Google slings websites into Chrome's solitary confinement on Android to thwart Spectre-style data snooping
2019-10-18 04:53

Ignore the overhead, enjoy Site Isolation – a defense against side-channel attacks Last year, Google deployed Site Isolation in desktop versions of its Chrome browser as a defense against CPU...

New SWAPGS Side-Channel Attack Bypasses Spectre and Meltdown Defenses
2019-08-07 13:55

Researchers demonstrate a new side-channel attack that bypass mitigations against Spectre and Meltdown.

SWAPGS Attack: A new Spectre haunts machines with Intel CPUs
2019-08-06 23:10

Bitdefender researchers have uncovered yet another viable speculative execution side-channel attack that can be leveraged against Intel CPUs and the computers running on them. The SWAPGS Attack,...

Deja-wooo-oooh! Intel chips running Windows potentially vulnerable to scary Spectre variant
2019-08-06 23:01

SWAPGS can be abused to siphon sensitive secrets from kernel memory, patches already available Spectre – a family of data-leaking side-channel vulnerabilities arising from speculative execution...

Deja-woooo: Intel, AMD chips running Windows potentially vulnerable to scary Spectre variant
2019-08-06 23:01

SWAPGS attack can leak sensitive secrets from kernel memory, patches already available Spectre – a family of data-leaking side-channel vulnerabilities arising from speculative execution that was...

OpenSSH adds protection against Spectre, Meltdown, RAMBleed
2019-06-24 12:10

OpenSSH, a widely used suite of programs for secure (SSH protocol-based) remote login, has been equipped with protection against side-channel attacks that could allow attackers to extract private...

Behind the Naming of ZombieLoad and Other Intel Spectre-Like Flaws
2019-05-20 15:14

A lot of thought and meaning goes into the naming of infamous CPU side channel flaws, like ZombieLoad, Spectre and Meltdown.

Why MDS vulnerabilities present a threat as serious as Spectre and Meltdown
2019-05-15 18:00

Microarchitectural Data Sampling are CPU side-channel vulnerabilities that allow attackers to view in-flight data from CPU-internal buffers. Learn more about MDS attacks in this comprehensive guide.

Intel CPUs Impacted By New Class of Spectre-Like Attacks
2019-05-14 18:01

Intel has disclosed a new class of speculative execution side channel attacks.