Foreshadow Attacks — 3 New Intel CPU Side-Channel Flaws Discovered

2018 has been quite a tough year for Intel.

While the chip-maker giant is still dealing with Meltdown and Spectre processor vulnerabilities, yet another major speculative execution flaw has been revealed in Intel’s Core and Xeon lines of processors th… Continue reading Foreshadow Attacks — 3 New Intel CPU Side-Channel Flaws Discovered

NetSpectre — New Remote Spectre Attack Steals Data Over the Network

A team of security researchers has discovered a new Spectre attack that can be launched over the network, unlike all other Spectre variants that require some form of local code execution on the target system.

Dubbed “NetSpectre,” the new remote side-c… Continue reading NetSpectre — New Remote Spectre Attack Steals Data Over the Network

Two New Spectre-Class CPU Flaws Discovered—Intel Pays $100K Bounty

Intel has paid out a $100,000 bug bounty for new processor vulnerabilities that are related to Spectre variant one (CVE-2017-5753).

The new Spectre-class variants are tracked as Spectre 1.1 (CVE-2018-3693) and Spectre 1.2, of which Spectre 1.1 describ… Continue reading Two New Spectre-Class CPU Flaws Discovered—Intel Pays $100K Bounty

New ‘Lazy FP State Restore’ Vulnerability Found in All Modern Intel CPUs

Hell Yeah! Another security vulnerability has been discovered in Intel chips that affects the processor’s speculative execution technology—like Specter and Meltdown—and could potentially be exploited to access sensitive information, including encryptio… Continue reading New ‘Lazy FP State Restore’ Vulnerability Found in All Modern Intel CPUs

Microsoft’s Meltdown Patch Made Windows 7 PCs More Insecure

Meltdown CPU vulnerability was bad, and Microsoft somehow made the flaw even worse on its Windows 7, allowing any unprivileged, user-level application to read content from and even write data to the operating system’s kernel memory.

For those unaware,… Continue reading Microsoft’s Meltdown Patch Made Windows 7 PCs More Insecure

Meltdown/Specter-based Malware Coming Soon to Devices Near You, Are You Ready?

It has been few weeks since the details of the Spectre, and Meltdown processor vulnerabilities came out in public and researchers have discovered more than 130 malware samples trying to exploit these chip flaws.

Spectre and Meltdown are security vulne… Continue reading Meltdown/Specter-based Malware Coming Soon to Devices Near You, Are You Ready?

Intel Warns Users Not to Install Its ‘Faulty’ Meltdown and Spectre Patches

Don’t install Intel’s patches for Spectre and Meltdown chip vulnerabilities.

Intel on Monday warned that you should stop deploying its current versions of Spectre/Meltdown patches, which Linux creator Linus Torvalds calls ‘complete and utter garbage.’… Continue reading Intel Warns Users Not to Install Its ‘Faulty’ Meltdown and Spectre Patches

New Intel AMT Security Issue Lets Hackers Gain Full Control of Laptops in 30 Seconds

It’s been a terrible new-year-starting for Intel.

Researchers warn of a new attack which can be carried out in less than 30 seconds and potentially affects millions of laptops globally.

As Intel was rushing to roll out patches for Meltdown and Spectr… Continue reading New Intel AMT Security Issue Lets Hackers Gain Full Control of Laptops in 30 Seconds

Google’s CPU Patch Builds Software ‘Trampolines’ that ‘Negligibly’ Impact Performance

Following the recent discovery of vulnerabilities in Intel, AMD and ARM CPUs, Google engineers developed a new chip-level patch that specifically addresses one of the three issues, namely the “Branch target injection” that’s also refe… Continue reading Google’s CPU Patch Builds Software ‘Trampolines’ that ‘Negligibly’ Impact Performance