Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
AI an existential risk – and what to do about it today
ASOCIO Digital & AI Summit 2026
Hackers phish for cloud accounts and payment passkeys using executive ...
Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA and ...
European Commission scrutinizing AI firm’s delayed incident report aft...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      The recovery-first approach to data resilience

      The recovery-first approach to data resilience

      Monday, September 7, 2026, 4:21 PM Asia/Singapore | Features
    • Featured

      Dealing with agentic AI governance and resilience challenges

      Dealing with agentic AI governance and resilience challenges

      Tuesday, September 1, 2026, 11:51 AM Asia/Singapore | Features
    • Featured

      How well do you know your agent?

      How well do you know your agent?

      Thursday, August 20, 2026, 3:21 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Researchers discover way to bypass CPU Spectre v2 protections to intercept sensitive data

By CybersecAsia editors | Friday, August 14, 2026, 12:25 PM Asia/Singapore

Researchers discover way to bypass CPU Spectre v2 protections to intercept sensitive data

Researchers detail Interrupt Injection side-channel on AMD and Intel processors, exposing /etc/shadow contents despite eIBRS and Safe RET mitigations

Researchers at MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) have unveiled findings on 6 August 2026, a new CPU side-channel technique that cuts straight through existing Spectre v2 defenses on both AMD and Intel chips, showing that it is possible to pull Linux password hashes out of kernel memory despite modern mitigations.

The work, described on their website, targets Spectre v2-style branch prediction protections that vendors have promoted as core safeguards against speculative execution attacks.

The attack primitive is named TONTOU (“Time-of-Neutralization to Time-of-Use”) and it focuses on a subtle timing gap in how processors handle branch predictor cleanup. Contemporary Spectre v2 countermeasures such as Intel’s Enhanced Indirect Branch Restricted Speculation (eIBRS) and AMD’s Safe RET mechanism, operate by flushing or compartmentalizing branch prediction state so it cannot be abused by speculative execution.

However, as PhD student Daniël Trujillo and associate professor Mengjia Yan discovered, there is an unavoidable window between the instant the branch predictor is sanitized and the point at which those sanitized predictions are actually consumed by the CPU. TONTOU weaponizes that tiny interval using what the researchers call “Interrupt Injection”.

Interrupt Injection explained

By carefully arranging for a hardware interrupt to arrive precisely inside that neutralized-to-use gap, an unprivileged user-space process can re-poison the branch predictor after the defense has already executed, but before the CPU relies on the supposedly safe prediction data.

In a conversation with security outlet BleepingComputer, Trujillo explained that this enables an attacker with no special privileges “to read arbitrary memory from the system, including sensitive data such as hashed passwords.” The result is that protection schemes previously thought to block speculative branch mispredictions can be sidestepped by extremely fine-grained timing control delivered purely from local code.

In 10 independent trials, the exploit succeeded in identifying and extracting the contents of the /etc/shadow file — which on Linux holds the system’s password hashes — in five cases. On average, each successful run took about 18 minutes to complete from start to finish, illustrating that the leak is slow but feasible in realistic time frames for a determined local adversary.

The researchers also confirmed that the same TONTOU concept applies to Intel processors that ship with Spectre v2 defenses like eIBRS. Nonetheless, they note that practical exploitation on Intel hardware is more complex because it depends on additional software conditions and configuration details, making the proof-of-concept attack harder to reproduce than on the tested AMD Zen 2 system. That nuance is important: both vendors’ CPUs are theoretically exposed, but the real-world barrier to exploitation differs per platform.

Official responses

AMD has responded to the disclosure by acknowledging that the problem “appears to be associated” with how the Linux kernel integrates the Safe RET mitigation rather than being purely a consequence of the microarchitecture itself. In other words, the interaction between the operating system’s implementation and the CPU’s protective feature is what opens the timing window that TONTOU can reach. MIT CSAIL notes that AMD has now issued a patch aimed at neutralizing the attack path, and that mitigation is being delivered to end users through standard operating system updates, including Linux distributions.

The group intend to publish more technical detail when they present at USENIX Security 2026 in October. Their research highlights a persistent reality in hardware and microarchitecture security: even carefully engineered Spectre v2 mitigations can still leave exploitable timing gaps that attackers with only unprivileged local code execution can surgically target. As speculative execution defenses grow more intricate, TONTOU serves as a reminder that defenders must consider not just what state is sanitized, but exactly when and how that sanitization intersects with real-world CPU behavior.

Share:

PreviousSUPCON and Certis Sign Strategic Cooperation Agreement to Advance Robotics in Security Operations
NextGeeLark Upgrades Browser Infrastructure with Version 150 and Team Password Management

Related Posts

Following Triton and Stuxnet, new ICS malware targets critical infrastructure

Following Triton and Stuxnet, new ICS malware targets critical infrastructure

Tuesday, April 19, 2022

Can your anti-phishing software detect these new URLO obfuscation techniques?

Can your anti-phishing software detect these new URLO obfuscation techniques?

Friday, September 12, 2025

Address machine identity risks, protect AI, and improve security strategies: survey

Address machine identity risks, protect AI, and improve security strategies: survey

Tuesday, March 25, 2025

Logistics giant was the most impersonated brand used in Q4 2021 phishing campaigns

Logistics giant was the most impersonated brand used in Q4 2021 phishing campaigns

Friday, February 4, 2022

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA and Fujitsu MONAKA Server for sovereign AI infrastructure

    Monday, September 14, 2026
    Achieving world-class AI inference performance …Read More »
  • Aitech Introduces New C165 Rugged Single Board Computer to Help Defense Programs Build and Modernize Fielded VME Systems

    Monday, September 14, 2026
    New 6U VME SBC Delivers …Read More »
  • CyberDSA 2026 Draws Global Cyber Leaders for High-Level Talks on AI, Digital Trust and Critical Infrastructure

    Friday, September 11, 2026
    Minister of Digital Malaysia YB …Read More »
  • The 3rd GTI Forum on Digital Intelligence, Hong Kong Advances Global Inclusive AI Development

    Thursday, September 10, 2026
    HONG KONG, Sept. 10, 2026 …Read More »
  • Nearly Half of Reported Scam Incidents Go Unresolved Across Southeast Asia, Undermining Digital Trust, New GSMA Findings Reveal

    Wednesday, September 9, 2026
    Two new GSMA reports launched …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.