Feeds.4Sysops New TONTOU Attack Exploits Spectre v2 Defenses on Intel and AMD CPUs
Article Content
- •TONTOU attack bypasses Spectre v2 defenses on Intel and AMD CPUs.
- •The attack allows unprivileged code to leak sensitive data, including Linux password hashes.
- •An AMD kernel fix is available, but many systems are still at risk until updated.
MIT researchers have unveiled a new speculative execution attack named TONTOU, which bypasses mitigations against Spectre v2 on Intel and AMD processors. The attack exploits a timing vulnerability in the post-neutralization window of branch predictors, allowing unprivileged code to re-poison these predictors and leak sensitive data, such as Linux password hashes. The researchers demonstrated the attack on AMD Zen 2 and Intel Cascade Lake Refresh processors. The method involves scheduling high-frequency timer interrupts to redirect control flow during critical execution phases. An AMD kernel fix is available, but many systems remain vulnerable until updates are applied. The attack highlights weaknesses in existing Spectre mitigations and poses a significant risk to Linux systems. The researchers will present their findings at DEF CON 34.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track AMD in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…