Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Researchers discover way to bypass CPU Spectre v2 protections to inter...
SUPCON and Certis Sign Strategic Cooperation Agreement to Advance Robo...
Gunra ransomware RaaS prompts global warning from US security authorit...
AUTOCRYPT Wins DEF CON 34 Automotive Hacking Competition, Ranking Firs...
Blackpanda Wins Frost & Sullivan APAC Incident Response Company of...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Why APAC Teams Need to Stop Worshipping CVSS Scores

      Why APAC Teams Need to Stop Worshipping CVSS Scores

      Monday, August 3, 2026, 9:00 AM Asia/Singapore | Features, Newsletter, Sponsored, Tips
    • Featured

      Automated credential abuse and phishing in APAC

      Automated credential abuse and phishing in APAC

      Thursday, July 30, 2026, 11:37 AM Asia/Singapore | Features
    • Featured

      OpenAI autonomous agent escapes sandbox to hack Hugging Face

      OpenAI autonomous agent escapes sandbox to hack Hugging Face

      Friday, July 24, 2026, 11:02 AM Asia/Singapore | Features, News
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Researchers discover way to bypass CPU Spectre v2 protections to intercept sensitive data

By CybersecAsia editors | Friday, August 14, 2026, 12:25 PM Asia/Singapore

Researchers discover way to bypass CPU Spectre v2 protections to intercept sensitive data

Researchers detail Interrupt Injection side-channel on AMD and Intel processors, exposing /etc/shadow contents despite eIBRS and Safe RET mitigations

Researchers at MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) have unveiled findings on 6 August 2026, a new CPU side-channel technique that cuts straight through existing Spectre v2 defenses on both AMD and Intel chips, showing that it is possible to pull Linux password hashes out of kernel memory despite modern mitigations.

The work, described on their website, targets Spectre v2-style branch prediction protections that vendors have promoted as core safeguards against speculative execution attacks.

The attack primitive is named TONTOU (“Time-of-Neutralization to Time-of-Use”) and it focuses on a subtle timing gap in how processors handle branch predictor cleanup. Contemporary Spectre v2 countermeasures such as Intel’s Enhanced Indirect Branch Restricted Speculation (eIBRS) and AMD’s Safe RET mechanism, operate by flushing or compartmentalizing branch prediction state so it cannot be abused by speculative execution.

However, as PhD student Daniël Trujillo and associate professor Mengjia Yan discovered, there is an unavoidable window between the instant the branch predictor is sanitized and the point at which those sanitized predictions are actually consumed by the CPU. TONTOU weaponizes that tiny interval using what the researchers call “Interrupt Injection”.

Interrupt Injection explained

By carefully arranging for a hardware interrupt to arrive precisely inside that neutralized-to-use gap, an unprivileged user-space process can re-poison the branch predictor after the defense has already executed, but before the CPU relies on the supposedly safe prediction data.

In a conversation with security outlet BleepingComputer, Trujillo explained that this enables an attacker with no special privileges “to read arbitrary memory from the system, including sensitive data such as hashed passwords.” The result is that protection schemes previously thought to block speculative branch mispredictions can be sidestepped by extremely fine-grained timing control delivered purely from local code.

In 10 independent trials, the exploit succeeded in identifying and extracting the contents of the /etc/shadow file — which on Linux holds the system’s password hashes — in five cases. On average, each successful run took about 18 minutes to complete from start to finish, illustrating that the leak is slow but feasible in realistic time frames for a determined local adversary.

The researchers also confirmed that the same TONTOU concept applies to Intel processors that ship with Spectre v2 defenses like eIBRS. Nonetheless, they note that practical exploitation on Intel hardware is more complex because it depends on additional software conditions and configuration details, making the proof-of-concept attack harder to reproduce than on the tested AMD Zen 2 system. That nuance is important: both vendors’ CPUs are theoretically exposed, but the real-world barrier to exploitation differs per platform.

Official responses

AMD has responded to the disclosure by acknowledging that the problem “appears to be associated” with how the Linux kernel integrates the Safe RET mitigation rather than being purely a consequence of the microarchitecture itself. In other words, the interaction between the operating system’s implementation and the CPU’s protective feature is what opens the timing window that TONTOU can reach. MIT CSAIL notes that AMD has now issued a patch aimed at neutralizing the attack path, and that mitigation is being delivered to end users through standard operating system updates, including Linux distributions.

The group intend to publish more technical detail when they present at USENIX Security 2026 in October. Their research highlights a persistent reality in hardware and microarchitecture security: even carefully engineered Spectre v2 mitigations can still leave exploitable timing gaps that attackers with only unprivileged local code execution can surgically target. As speculative execution defenses grow more intricate, TONTOU serves as a reminder that defenders must consider not just what state is sanitized, but exactly when and how that sanitization intersects with real-world CPU behavior.

Share:

PreviousSUPCON and Certis Sign Strategic Cooperation Agreement to Advance Robotics in Security Operations

Related Posts

Popular mass vacation periods attracted more cyberattacks: study

Popular mass vacation periods attracted more cyberattacks: study

Tuesday, November 8, 2022

Protected Health Information are a hot commodity on the Dark Web

Protected Health Information are a hot commodity on the Dark Web

Friday, February 5, 2021

Major cloud platform hit by global DNS outage disrupting key services

Major cloud platform hit by global DNS outage disrupting key services

Wednesday, November 5, 2025

Real estate logistics provider GLP steps up to zero trust architecture

Real estate logistics provider GLP steps up to zero trust architecture

Friday, April 19, 2024

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • SUPCON and Certis Sign Strategic Cooperation Agreement to Advance Robotics in Security Operations

    Wednesday, August 12, 2026
    SINGAPORE, Aug. 12, 2026 /PRNewswire/ …Read More »
  • AUTOCRYPT Wins DEF CON 34 Automotive Hacking Competition, Ranking First Among 83 Teams

    Tuesday, August 11, 2026
    Claiming first championship following last …Read More »
  • Blackpanda Wins Frost & Sullivan APAC Incident Response Company of the Year for Third Straight Year

    Tuesday, August 11, 2026
    The 2026 recognition cites IR-1’s …Read More »
  • Newgen Software Recognized in The Digital Process Automation Software Landscape, Q3 2026

    Tuesday, August 11, 2026
    NOIDA, India, Aug. 10, 2026 …Read More »
  • SU Group Holdings Limited Announces Reverse Stock Split

    Tuesday, August 4, 2026
    Reverse Stock-Split to be effective …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.