Intel Says No New Mitigations Required for Indirector CPU Attack

July 3, 2024 at 06:24AM Researchers at the University of California San Diego have detailed a new attack method, Indirector, targeting high-end Intel CPUs. The method exploits the Indirect Branch Predictor and Branch Target Buffer, allowing attackers to bypass existing defenses and compromise CPU security. Intel maintains that previously issued mitigations should effectively address the … Read more

New Intel CPU Vulnerability ‘Indirector’ Exposes Sensitive Data

July 2, 2024 at 07:07AM Modern Intel CPUs like Raptor Lake and Alder Lake are vulnerable to a new side-channel attack named “Indirector.” The attack exploits weaknesses in Indirect Branch Predictor (IBP) and Branch Target Buffer (BTB) to leak sensitive information. Mitigations include using Indirect Branch Predictor Barrier (IBPB) more aggressively and hardening the Branch … Read more

Future Intel, AMD and Arm CPUs Vulnerable to New ‘SLAM’ Attack: Researchers

December 7, 2023 at 07:48AM Upcoming CPUs from Intel, AMD, and Arm may be susceptible to a new type of ‘SLAM’ attack despite planned security enhancements, researchers warn. Key Takeaways from Meeting: – Major CPU vendors, which include Intel, AMD, and Arm, are planning to integrate new security features into their future products. – There … Read more

New SLAM attack steals sensitive data from AMD, future Intel CPUs

December 6, 2023 at 07:57PM Researchers at VUSec discovered “SLAM,” a side-channel attack exploiting memory features in future CPUs from Intel, AMD, and Arm, to leak sensitive information like root password hashes. Despite the intended security improvements, these features inadvertently enable SLAM by not checking address canonicality, creating micro-architectural race conditions. Existing defenses are deemed … Read more

Reptar: New Intel CPU Vulnerability Impacts Multi-Tenant Virtualized Environments

November 15, 2023 at 02:57AM Intel has released fixes for a high-severity flaw called Reptar that affects its desktop, mobile, and server CPUs. The vulnerability, tracked as CVE-2023-23583, allows for privilege escalation, information disclosure, denial of service, and bypassing of security boundaries. Intel has published updated microcode for all affected processors and there is currently … Read more