Spectre, Meltdown researchers unveil 7 more speculative execution attacks

Enlarge (credit: Aurich Lawson / Getty Images) Back at the start of the year, a set of attacks that leveraged the speculative execution capabilities of modern high-performance processors was revealed. The attacks were named Meltdown and Spectre. Since then, numerous variants of these attacks have been devised. In tandem, a range of mitigation techniques has […]

New Spectre attack enables secrets to be leaked over a network

Enlarge (credit: Pete) When the Spectre and Meltdown attacks were disclosed earlier this year, the initial exploits required an attacker to be able to run code of their choosing on a victim system. This made browsers vulnerable, as suitably crafted JavaScript could be used to perform Spectre attacks. Cloud hosts were susceptible, too. But outside […]

The most ambitious browser mitigation yet for Spectre attacks comes to Chrome

(credit: Google) Google’s Chrome browser is undergoing a major architectural change to enable a protection designed to blunt the threat of attacks related to the Spectre vulnerability in computer processors. If left unchecked by browsers or operating systems, such attacks may allow hackers to pluck passwords or other sensitive data out of computer memory when […]

Microsoft fixes more Meltdown and Spectre flaws in Windows

Microsoft has taken another step on its gargantuan journey to fortifying more than a billion PCs worldwide against Meltdown and Spectre vulnerabilities. This week’s Patch Tuesday release updates PCs running x86 versions of Windows 7 and 8.1 against Meltdown, meaning that all currently supported Windows releases now include defense against this vulnerability. The update also […]

Microsoft will soon start shipping the Intel Spectre microcode fixes

Intel Skylake die shot. (credit: Intel) Windows users running the latest version of Windows 10 on recent Intel processors will soon be receiving Intel’s microcode updates to address the Spectre variant 2 attack. Earlier this year, attacks that exploit the processor’s speculative execution were published with the names Meltdown and Spectre, prompting a reaction from […]

32 lawsuits filed against Intel over Spectre and Meltdown flaws

Enlarge / This may become the new default imagery for Spectre and Meltdown around Intel. (credit: Brian Turner / Flickr) In its annual SEC filing, Intel has revealed that it’s facing 32 lawsuits over the Spectre and Meltdown attacks on its processors. While the Spectre problem is a near-universal issue faced by modern processors, the […]

Researchers discover new ways to abuse Meltdown and Spectre flaws

Intel has already started looking for other Spectre-like flaws, but it won’t be able to move on from the Spectre/Meltdown CPU vulnerabilities anytime soon. A team of security researchers from NVIDIA and Princeton University have discovered new ways to exploit Meltdown and Spectre outside of those idenfitied in the past. The researchers developed a tool […]