home.social

#speculativeexecution — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #speculativeexecution, aggregated by home.social.

fetched live
  1. @lobingera
    That’s exactly my point. Mastery doesn’t mean perfection. It means pushing an idea so far that it starts creating entirely new categories of problems. #SpeculativeExecution did. #AgileCheese does, too. That’s where the #cheese begins. 🧀

  2. @lobingera
    That’s exactly my point. Mastery doesn’t mean perfection. It means pushing an idea so far that it starts creating entirely new categories of problems. #SpeculativeExecution did. #AgileCheese does, too. That’s where the #cheese begins. 🧀

  3. @lobingera
    That’s exactly my point. Mastery doesn’t mean perfection. It means pushing an idea so far that it starts creating entirely new categories of problems. #SpeculativeExecution did. #AgileCheese does, too. That’s where the #cheese begins. 🧀

  4. @lobingera
    That’s exactly my point. Mastery doesn’t mean perfection. It means pushing an idea so far that it starts creating entirely new categories of problems. #SpeculativeExecution did. #AgileCheese does, too. That’s where the #cheese begins. 🧀

  5. @lobingera
    That’s exactly my point. Mastery doesn’t mean perfection. It means pushing an idea so far that it starts creating entirely new categories of problems. #SpeculativeExecution did. #AgileCheese does, too. That’s where the #cheese begins. 🧀

  6. Apple chips can be hacked to leak secrets from Gmail, iCloud, and more - Apple-designed chips powering Macs, iPhones, and iPads contain two newly d... - arstechnica.com/security/2025/ #speculativeexecution #a-serieschips #m-serieschips #sidechannels #security #biz#apple

  7. Apple chips can be hacked to leak secrets from Gmail, iCloud, and more - Apple-designed chips powering Macs, iPhones, and iPads contain two newly d... - arstechnica.com/security/2025/ #speculativeexecution #a-serieschips #m-serieschips #sidechannels #security #biz#apple

  8. Apple chips can be hacked to leak secrets from Gmail, iCloud, and more - Apple-designed chips powering Macs, iPhones, and iPads contain two newly d... - arstechnica.com/security/2025/ #speculativeexecution #a-serieschips #m-serieschips #sidechannels #security #biz#apple

  9. Apple chips can be hacked to leak secrets from Gmail, iCloud, and more - Apple-designed chips powering Macs, iPhones, and iPads contain two newly d... - arstechnica.com/security/2025/ #speculativeexecution #a-serieschips #m-serieschips #sidechannels #security #biz#apple

  10. Apple chips can be hacked to leak secrets from Gmail, iCloud, and more - Apple-designed chips powering Macs, iPhones, and iPads contain two newly d... - arstechnica.com/security/2025/ #speculativeexecution #a-serieschips #m-serieschips #sidechannels #security #biz#apple

  11. #Intel, #AMD #CPU on #Linux impacted by newly disclosed #Spectre bypass
    The #vulnerabilities impact Intel's 12th, 13th, and 14th chip generations for consumers and the 5th and 6th generation of #Xeon processors for servers, along with AMD's older Zen 1, Zen 1+, and Zen 2 processors. The attacks undermine the Indirect Branch Predictor Barrier (#IBPB) on #x86 processors, a core defense mechanism against #speculativeexecution attacks.
    bleepingcomputer.com/news/secu

  12. #Intel, #AMD #CPU on #Linux impacted by newly disclosed #Spectre bypass
    The #vulnerabilities impact Intel's 12th, 13th, and 14th chip generations for consumers and the 5th and 6th generation of #Xeon processors for servers, along with AMD's older Zen 1, Zen 1+, and Zen 2 processors. The attacks undermine the Indirect Branch Predictor Barrier (#IBPB) on #x86 processors, a core defense mechanism against #speculativeexecution attacks.
    bleepingcomputer.com/news/secu

  13. , on impacted by newly disclosed bypass
    The impact Intel's 12th, 13th, and 14th chip generations for consumers and the 5th and 6th generation of processors for servers, along with AMD's older Zen 1, Zen 1+, and Zen 2 processors. The attacks undermine the Indirect Branch Predictor Barrier (#IBPB) on processors, a core defense mechanism against attacks.
    bleepingcomputer.com/news/secu

  14. #Intel, #AMD #CPU on #Linux impacted by newly disclosed #Spectre bypass
    The #vulnerabilities impact Intel's 12th, 13th, and 14th chip generations for consumers and the 5th and 6th generation of #Xeon processors for servers, along with AMD's older Zen 1, Zen 1+, and Zen 2 processors. The attacks undermine the Indirect Branch Predictor Barrier (#IBPB) on #x86 processors, a core defense mechanism against #speculativeexecution attacks.
    bleepingcomputer.com/news/secu

  15. #Intel, #AMD #CPU on #Linux impacted by newly disclosed #Spectre bypass
    The #vulnerabilities impact Intel's 12th, 13th, and 14th chip generations for consumers and the 5th and 6th generation of #Xeon processors for servers, along with AMD's older Zen 1, Zen 1+, and Zen 2 processors. The attacks undermine the Indirect Branch Predictor Barrier (#IBPB) on #x86 processors, a core defense mechanism against #speculativeexecution attacks.
    bleepingcomputer.com/news/secu

  16. Speculative execution and other microarchitectural attacks never went away, and the research just keeps getting smarter.

    Pathfinder introduces new tools and two new types of speculative execution, affecting Intel and AMD CPUs.

    #Spectre #SpeculativeExecution #CyberSec #AppSec #VU157097

    pathfinder.cpusec.org/

  17. Speculative execution and other microarchitectural attacks never went away, and the research just keeps getting smarter.

    Pathfinder introduces new tools and two new types of speculative execution, affecting Intel and AMD CPUs.

    pathfinder.cpusec.org/

  18. Speculative execution and other microarchitectural attacks never went away, and the research just keeps getting smarter.

    Pathfinder introduces new tools and two new types of speculative execution, affecting Intel and AMD CPUs.

    #Spectre #SpeculativeExecution #CyberSec #AppSec #VU157097

    pathfinder.cpusec.org/

  19. Speculative execution and other microarchitectural attacks never went away, and the research just keeps getting smarter.

    Pathfinder introduces new tools and two new types of speculative execution, affecting Intel and AMD CPUs.

    #Spectre #SpeculativeExecution #CyberSec #AppSec #VU157097

    pathfinder.cpusec.org/

  20. Speculative execution and other microarchitectural attacks never went away, and the research just keeps getting smarter.

    Pathfinder introduces new tools and two new types of speculative execution, affecting Intel and AMD CPUs.

    #Spectre #SpeculativeExecution #CyberSec #AppSec #VU157097

    pathfinder.cpusec.org/

  21. New #SpectreV2 attack impacts #Linux systems on #Intel #CPU
    Researchers have demonstrated the "first native #Spectre v2 #exploit" for a new #speculativeexecution side-channel flaw that impacts Linux systems running on many modern Intel processors.
    Current mitigations are designed around isolating exploitable gadgets to remove the attack surface. Researchers, through custom 'InSpectre Gadget' analysis tool, demonstrated that exploitable gadgets in the Linux kernel remain.
    bleepingcomputer.com/news/secu

  22. New #SpectreV2 attack impacts #Linux systems on #Intel #CPU
    Researchers have demonstrated the "first native #Spectre v2 #exploit" for a new #speculativeexecution side-channel flaw that impacts Linux systems running on many modern Intel processors.
    Current mitigations are designed around isolating exploitable gadgets to remove the attack surface. Researchers, through custom 'InSpectre Gadget' analysis tool, demonstrated that exploitable gadgets in the Linux kernel remain.
    bleepingcomputer.com/news/secu

  23. New attack impacts systems on
    Researchers have demonstrated the "first native v2 " for a new side-channel flaw that impacts Linux systems running on many modern Intel processors.
    Current mitigations are designed around isolating exploitable gadgets to remove the attack surface. Researchers, through custom 'InSpectre Gadget' analysis tool, demonstrated that exploitable gadgets in the Linux kernel remain.
    bleepingcomputer.com/news/secu

  24. New #SpectreV2 attack impacts #Linux systems on #Intel #CPU
    Researchers have demonstrated the "first native #Spectre v2 #exploit" for a new #speculativeexecution side-channel flaw that impacts Linux systems running on many modern Intel processors.
    Current mitigations are designed around isolating exploitable gadgets to remove the attack surface. Researchers, through custom 'InSpectre Gadget' analysis tool, demonstrated that exploitable gadgets in the Linux kernel remain.
    bleepingcomputer.com/news/secu

  25. New #SpectreV2 attack impacts #Linux systems on #Intel #CPU
    Researchers have demonstrated the "first native #Spectre v2 #exploit" for a new #speculativeexecution side-channel flaw that impacts Linux systems running on many modern Intel processors.
    Current mitigations are designed around isolating exploitable gadgets to remove the attack surface. Researchers, through custom 'InSpectre Gadget' analysis tool, demonstrated that exploitable gadgets in the Linux kernel remain.
    bleepingcomputer.com/news/secu

  26. Attack: Theft of Sensitive Data from ’s
    What happens in iLeakage attacks is that the is tricked into of code that reads sensitive data from memory. hackread.com/ileakage-attack-s attack

  27. "🚨 iLeakage: Safari's Side Channel Vulnerability Exposed! 🍎🔓"

    Researchers have unveiled a new attack, dubbed "iLeakage", that exploits a side channel vulnerability in Apple's A- and M-series CPUs. This attack forces Apple’s Safari browser on iOS and macOS devices to reveal passwords, Gmail content, and more. The exploit is practical and doesn't require vast resources but demands in-depth reverse-engineering of Apple hardware. The side channel exploited is speculative execution, a feature in modern CPUs that has been the foundation for numerous attacks recently. The iLeakage attack, when executed, can recover YouTube viewing history, Gmail inbox content, and even passwords autofilled by credential managers. Apple is aware and plans to address this in an upcoming software release. 🚀🔍

    Source: Ars Technica

    Author: Dan Goodin - Senior Security Editor at Ars Technica. Profile

    Tags: #iLeakage #Apple #Safari #SideChannel #Vulnerability #CyberSecurity #iOS #macOS #SpeculativeExecution 🌐🔐🍏

  28. "🚨 iLeakage: Safari's Side Channel Vulnerability Exposed! 🍎🔓"

    Researchers have unveiled a new attack, dubbed "iLeakage", that exploits a side channel vulnerability in Apple's A- and M-series CPUs. This attack forces Apple’s Safari browser on iOS and macOS devices to reveal passwords, Gmail content, and more. The exploit is practical and doesn't require vast resources but demands in-depth reverse-engineering of Apple hardware. The side channel exploited is speculative execution, a feature in modern CPUs that has been the foundation for numerous attacks recently. The iLeakage attack, when executed, can recover YouTube viewing history, Gmail inbox content, and even passwords autofilled by credential managers. Apple is aware and plans to address this in an upcoming software release. 🚀🔍

    Source: Ars Technica

    Author: Dan Goodin - Senior Security Editor at Ars Technica. Profile

    Tags: #iLeakage #Apple #Safari #SideChannel #Vulnerability #CyberSecurity #iOS #macOS #SpeculativeExecution 🌐🔐🍏

  29. "🚨 iLeakage: Safari's Side Channel Vulnerability Exposed! 🍎🔓"

    Researchers have unveiled a new attack, dubbed "iLeakage", that exploits a side channel vulnerability in Apple's A- and M-series CPUs. This attack forces Apple’s Safari browser on iOS and macOS devices to reveal passwords, Gmail content, and more. The exploit is practical and doesn't require vast resources but demands in-depth reverse-engineering of Apple hardware. The side channel exploited is speculative execution, a feature in modern CPUs that has been the foundation for numerous attacks recently. The iLeakage attack, when executed, can recover YouTube viewing history, Gmail inbox content, and even passwords autofilled by credential managers. Apple is aware and plans to address this in an upcoming software release. 🚀🔍

    Source: Ars Technica

    Author: Dan Goodin - Senior Security Editor at Ars Technica. Profile

    Tags: #iLeakage #Apple #Safari #SideChannel #Vulnerability #CyberSecurity #iOS #macOS #SpeculativeExecution 🌐🔐🍏

  30. "🚨 iLeakage: Safari's Side Channel Vulnerability Exposed! 🍎🔓"

    Researchers have unveiled a new attack, dubbed "iLeakage", that exploits a side channel vulnerability in Apple's A- and M-series CPUs. This attack forces Apple’s Safari browser on iOS and macOS devices to reveal passwords, Gmail content, and more. The exploit is practical and doesn't require vast resources but demands in-depth reverse-engineering of Apple hardware. The side channel exploited is speculative execution, a feature in modern CPUs that has been the foundation for numerous attacks recently. The iLeakage attack, when executed, can recover YouTube viewing history, Gmail inbox content, and even passwords autofilled by credential managers. Apple is aware and plans to address this in an upcoming software release. 🚀🔍

    Source: Ars Technica

    Author: Dan Goodin - Senior Security Editor at Ars Technica. Profile

    Tags: #iLeakage #Apple #Safari #SideChannel #Vulnerability #CyberSecurity #iOS #macOS #SpeculativeExecution 🌐🔐🍏

  31. "🚨 iLeakage: Safari's Side Channel Vulnerability Exposed! 🍎🔓"

    Researchers have unveiled a new attack, dubbed "iLeakage", that exploits a side channel vulnerability in Apple's A- and M-series CPUs. This attack forces Apple’s Safari browser on iOS and macOS devices to reveal passwords, Gmail content, and more. The exploit is practical and doesn't require vast resources but demands in-depth reverse-engineering of Apple hardware. The side channel exploited is speculative execution, a feature in modern CPUs that has been the foundation for numerous attacks recently. The iLeakage attack, when executed, can recover YouTube viewing history, Gmail inbox content, and even passwords autofilled by credential managers. Apple is aware and plans to address this in an upcoming software release. 🚀🔍

    Source: Ars Technica

    Author: Dan Goodin - Senior Security Editor at Ars Technica. Profile

    Tags: #iLeakage #Apple #Safari #SideChannel #Vulnerability #CyberSecurity #iOS #macOS #SpeculativeExecution 🌐🔐🍏

  32. Hackers can force #iOS and #macOS browsers to divulge passwords and much more
    Researchers devised an attack that forces #Apple’s #Safari browser to divulge #passwords, Gmail message content, and other secrets by exploiting a side channel #vulnerability in A- and M-series CPU running modern iOS and macOS devices dubbed #iLeakage. The side channel in this case is #speculativeexecution, a performance enhancement feature in modern #CPU that formed the basis of many attacks arstechnica.com/security/2023/

  33. Hackers can force #iOS and #macOS browsers to divulge passwords and much more
    Researchers devised an attack that forces #Apple’s #Safari browser to divulge #passwords, Gmail message content, and other secrets by exploiting a side channel #vulnerability in A- and M-series CPU running modern iOS and macOS devices dubbed #iLeakage. The side channel in this case is #speculativeexecution, a performance enhancement feature in modern #CPU that formed the basis of many attacks arstechnica.com/security/2023/

  34. Hackers can force and browsers to divulge passwords and much more
    Researchers devised an attack that forces ’s browser to divulge , Gmail message content, and other secrets by exploiting a side channel in A- and M-series CPU running modern iOS and macOS devices dubbed . The side channel in this case is , a performance enhancement feature in modern that formed the basis of many attacks arstechnica.com/security/2023/

  35. Hackers can force #iOS and #macOS browsers to divulge passwords and much more
    Researchers devised an attack that forces #Apple’s #Safari browser to divulge #passwords, Gmail message content, and other secrets by exploiting a side channel #vulnerability in A- and M-series CPU running modern iOS and macOS devices dubbed #iLeakage. The side channel in this case is #speculativeexecution, a performance enhancement feature in modern #CPU that formed the basis of many attacks arstechnica.com/security/2023/

  36. Hackers can force #iOS and #macOS browsers to divulge passwords and much more
    Researchers devised an attack that forces #Apple’s #Safari browser to divulge #passwords, Gmail message content, and other secrets by exploiting a side channel #vulnerability in A- and M-series CPU running modern iOS and macOS devices dubbed #iLeakage. The side channel in this case is #speculativeexecution, a performance enhancement feature in modern #CPU that formed the basis of many attacks arstechnica.com/security/2023/

  37. CW: Moar speculative execution attacks

    You might by now have heard of "Downfall"¹, yet another speculative execution attack on Intel processors.

    The mitigations are going to cost another 50% performance on "selected workloads" which, by Murphy's, will inevitably be yours.

    I quote something I find really rather irritating:

    "
    [Q] Can I disable the mitigation if my workload does not use Gather?

    [A] This is a bad idea. Even if your workload does not use vector instructions, modern CPUs rely on vector registers to optimize common operations, such as copying memory and switching register content, which leaks data to untrusted code exploiting Gather.
    "

    No, you can freely decide to ignore microcode mitigations if you know what you are doing. There are thousands of reasons why you should not continue piling up Intel's microcode fixes on your machines and performance is indeed one of them.

    This attack is based on the "gather" part of the "scatter-gather" SIMD algorithms, these are pretty ubiquitous if you have ever done HPC and, well, if your HPC machine is one telnet away from the Internet then you have a bigger problem than microcode².

    Now, please understand, perhaps "for once and for all", that these attacks have a very simple "root cause": in the 1990s pretty much every processor manufacturer on the planet decided that performance trumped everything else and, therefore, went down (unprotected) speculative execution³.

    This means that it cannot be fixed within current architectures.

    #SpeculativeExecution #NamedVulnerabilities #Downfall #Hype #MitigationsDoneWrong

    __
    ¹ downfall.page
    ² I used to manage an HPC network in the 1990s, I was hacked by, of all places, Intel in Israel (Haifa), no I cannot discuss this further, yes, I detected them.
    ³ If you read the literature you will discover that even IBM mainframe processors went down that route (hint, hint).

  38. CW: Moar speculative execution attacks

    You might by now have heard of "Downfall"¹, yet another speculative execution attack on Intel processors.

    The mitigations are going to cost another 50% performance on "selected workloads" which, by Murphy's, will inevitably be yours.

    I quote something I find really rather irritating:

    "
    [Q] Can I disable the mitigation if my workload does not use Gather?

    [A] This is a bad idea. Even if your workload does not use vector instructions, modern CPUs rely on vector registers to optimize common operations, such as copying memory and switching register content, which leaks data to untrusted code exploiting Gather.
    "

    No, you can freely decide to ignore microcode mitigations if you know what you are doing. There are thousands of reasons why you should not continue piling up Intel's microcode fixes on your machines and performance is indeed one of them.

    This attack is based on the "gather" part of the "scatter-gather" SIMD algorithms, these are pretty ubiquitous if you have ever done HPC and, well, if your HPC machine is one telnet away from the Internet then you have a bigger problem than microcode².

    Now, please understand, perhaps "for once and for all", that these attacks have a very simple "root cause": in the 1990s pretty much every processor manufacturer on the planet decided that performance trumped everything else and, therefore, went down (unprotected) speculative execution³.

    This means that it cannot be fixed within current architectures.

    #SpeculativeExecution #NamedVulnerabilities #Downfall #Hype #MitigationsDoneWrong

    __
    ¹ downfall.page
    ² I used to manage an HPC network in the 1990s, I was hacked by, of all places, Intel in Israel (Haifa), no I cannot discuss this further, yes, I detected them.
    ³ If you read the literature you will discover that even IBM mainframe processors went down that route (hint, hint).

  39. CW: Moar speculative execution attacks

    You might by now have heard of "Downfall"¹, yet another speculative execution attack on Intel processors.

    The mitigations are going to cost another 50% performance on "selected workloads" which, by Murphy's, will inevitably be yours.

    I quote something I find really rather irritating:

    "
    [Q] Can I disable the mitigation if my workload does not use Gather?

    [A] This is a bad idea. Even if your workload does not use vector instructions, modern CPUs rely on vector registers to optimize common operations, such as copying memory and switching register content, which leaks data to untrusted code exploiting Gather.
    "

    No, you can freely decide to ignore microcode mitigations if you know what you are doing. There are thousands of reasons why you should not continue piling up Intel's microcode fixes on your machines and performance is indeed one of them.

    This attack is based on the "gather" part of the "scatter-gather" SIMD algorithms, these are pretty ubiquitous if you have ever done HPC and, well, if your HPC machine is one telnet away from the Internet then you have a bigger problem than microcode².

    Now, please understand, perhaps "for once and for all", that these attacks have a very simple "root cause": in the 1990s pretty much every processor manufacturer on the planet decided that performance trumped everything else and, therefore, went down (unprotected) speculative execution³.

    This means that it cannot be fixed within current architectures.

    #SpeculativeExecution #NamedVulnerabilities #Downfall #Hype #MitigationsDoneWrong

    __
    ¹ downfall.page
    ² I used to manage an HPC network in the 1990s, I was hacked by, of all places, Intel in Israel (Haifa), no I cannot discuss this further, yes, I detected them.
    ³ If you read the literature you will discover that even IBM mainframe processors went down that route (hint, hint).

  40. CW: Moar speculative execution attacks

    You might by now have heard of "Downfall"¹, yet another speculative execution attack on Intel processors.

    The mitigations are going to cost another 50% performance on "selected workloads" which, by Murphy's, will inevitably be yours.

    I quote something I find really rather irritating:

    "
    [Q] Can I disable the mitigation if my workload does not use Gather?

    [A] This is a bad idea. Even if your workload does not use vector instructions, modern CPUs rely on vector registers to optimize common operations, such as copying memory and switching register content, which leaks data to untrusted code exploiting Gather.
    "

    No, you can freely decide to ignore microcode mitigations if you know what you are doing. There are thousands of reasons why you should not continue piling up Intel's microcode fixes on your machines and performance is indeed one of them.

    This attack is based on the "gather" part of the "scatter-gather" SIMD algorithms, these are pretty ubiquitous if you have ever done HPC and, well, if your HPC machine is one telnet away from the Internet then you have a bigger problem than microcode².

    Now, please understand, perhaps "for once and for all", that these attacks have a very simple "root cause": in the 1990s pretty much every processor manufacturer on the planet decided that performance trumped everything else and, therefore, went down (unprotected) speculative execution³.

    This means that it cannot be fixed within current architectures.

    #SpeculativeExecution #NamedVulnerabilities #Downfall #Hype #MitigationsDoneWrong

    __
    ¹ downfall.page
    ² I used to manage an HPC network in the 1990s, I was hacked by, of all places, Intel in Israel (Haifa), no I cannot discuss this further, yes, I detected them.
    ³ If you read the literature you will discover that even IBM mainframe processors went down that route (hint, hint).

  41. CW: Moar speculative execution attacks

    You might by now have heard of "Downfall"¹, yet another speculative execution attack on Intel processors.

    The mitigations are going to cost another 50% performance on "selected workloads" which, by Murphy's, will inevitably be yours.

    I quote something I find really rather irritating:

    "
    [Q] Can I disable the mitigation if my workload does not use Gather?

    [A] This is a bad idea. Even if your workload does not use vector instructions, modern CPUs rely on vector registers to optimize common operations, such as copying memory and switching register content, which leaks data to untrusted code exploiting Gather.
    "

    No, you can freely decide to ignore microcode mitigations if you know what you are doing. There are thousands of reasons why you should not continue piling up Intel's microcode fixes on your machines and performance is indeed one of them.

    This attack is based on the "gather" part of the "scatter-gather" SIMD algorithms, these are pretty ubiquitous if you have ever done HPC and, well, if your HPC machine is one telnet away from the Internet then you have a bigger problem than microcode².

    Now, please understand, perhaps "for once and for all", that these attacks have a very simple "root cause": in the 1990s pretty much every processor manufacturer on the planet decided that performance trumped everything else and, therefore, went down (unprotected) speculative execution³.

    This means that it cannot be fixed within current architectures.

    #SpeculativeExecution #NamedVulnerabilities #Downfall #Hype #MitigationsDoneWrong

    __
    ¹ downfall.page
    ² I used to manage an HPC network in the 1990s, I was hacked by, of all places, Intel in Israel (Haifa), no I cannot discuss this further, yes, I detected them.
    ³ If you read the literature you will discover that even IBM mainframe processors went down that route (hint, hint).

  42. During this year's #BlackHat conference, security researcher Daniel Moghimi is set to present "Downfall", a new speculative execution vulnerability found in Intel processors from 2014-2023.

    This new speculative execution vulnerability if exploited could allow attackers steal encryption keys & passwords.

    Intel noted that they haven't seen this vulnerability being exploited in the wild and that detection is difficult.

    Moghimi stated that exploiting was relatively easy, he goes on to say:

    When I discovered this vulnerability, it took me maybe a couple of weeks to come up with attacks that work. I was just a one-person researcher without any resources, you can imagine if you have a team of black hat hackers, you can probably do a lot more with it.
    While the flaw exists in hardware, Intel has provided microcode updates & the #Linux kernel maintainers have published mitigations for this flaw in today's kernel release.

    #infosec #cybersecurity #DOWNFALL #speculativeexecution #Intel #CPUBug

    -
    https://cyberscoop.com/downfall-intel-cpu-vulnerability/
    -
    https://www.bleepingcomputer.com/news/security/new-downfall-attacks-on-intel-cpus-steal-encryption-keys-data/

  43. During this year's #BlackHat conference, security researcher Daniel Moghimi is set to present "Downfall", a new speculative execution vulnerability found in Intel processors from 2014-2023.

    This new speculative execution vulnerability if exploited could allow attackers steal encryption keys & passwords.

    Intel noted that they haven't seen this vulnerability being exploited in the wild and that detection is difficult.

    Moghimi stated that exploiting was relatively easy, he goes on to say:

    When I discovered this vulnerability, it took me maybe a couple of weeks to come up with attacks that work. I was just a one-person researcher without any resources, you can imagine if you have a team of black hat hackers, you can probably do a lot more with it.
    While the flaw exists in hardware, Intel has provided microcode updates & the #Linux kernel maintainers have published mitigations for this flaw in today's kernel release.

    #infosec #cybersecurity #DOWNFALL #speculativeexecution #Intel #CPUBug

    -
    https://cyberscoop.com/downfall-intel-cpu-vulnerability/
    -
    https://www.bleepingcomputer.com/news/security/new-downfall-attacks-on-intel-cpus-steal-encryption-keys-data/