Spectre is a vulnerability tracked across 7 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity June 2, 2026.
Spectre is a class of microarchitectural vulnerabilities that exploit speculative execution to leak sensitive data across process or virtual machine boundaries via side channels such as caches and branch predictors. It affects a wide range of CPUs from major vendors (Intel, AMD, ARM) and remains difficult to fully remediate, requiring ongoing hardware, firmware, and software mitigations with potential performance costs. Its significance lies in breaking fundamental trust boundaries in computing, impacting devices, clouds, and software supply chains alike.
Google and Apple released urgent security updates to address zero-day vulnerabilities affecting their platforms. The vulnerabilities were exploited in a sophisticated attack targeting specific users, with one bug…
A new phishing campaign is leveraging SVG files to bypass email security measures, as reported by SANS. These SVG files contain obfuscated JavaScript that executes upon opening, redirecting users to…
Researchers from Calif, a Palo Alto-based cybersecurity startup, successfully exploited Apple's Memory Integrity Enforcement (MIE) on the M5 chip within a week using Anthropic's AI model, Claude Mythos. The exploit…
The anonymous security researcher known as Nightmare-Eclipse has been banned from both GitHub and GitLab due to the release of multiple unpatched Windows vulnerabilities. GitHub terminated the account on May 25, 2026,…
MIT researchers have identified critical security flaws in Apple's M1 chip, previously thought secure. The team created a custom operating system named Fractal to investigate the chip's architecture. They discovered a…
Microsoft researchers reported that a side-channel attack can enable unauthorized parties to infer topics discussed in large language models (LLMs). Models from providers such as Anthropic, AWS, DeepSeek, and Google…
Microsoft researchers reported that a side-channel attack can enable unauthorized parties to infer the topics being discussed with large language models (LLMs). Models from providers such as Anthropic, AWS, DeepSeek,…