Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
From frontier policy to boardroom action: how enterprises should gover...
How can APAC enterprises face AI governance questions deftly? Key ques...
China-linked cyber espionage group shifts focus to another brand of ro...
Cohesity Delivers New Managed Clean Room Capability to Enhance HCLTech...
Visa Launches Enhanced A2A Protect Innovations to Help Financial Insti...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Dealing with agentic AI governance and resilience challenges

      Dealing with agentic AI governance and resilience challenges

      Tuesday, September 1, 2026, 11:51 AM Asia/Singapore | Features
    • Featured

      How well do you know your agent?

      How well do you know your agent?

      Thursday, August 20, 2026, 3:21 PM Asia/Singapore | Features
    • Featured

      Bringing proof of identity to the digital economy

      Bringing proof of identity to the digital economy

      Wednesday, August 19, 2026, 10:50 AM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Researchers discover way to bypass CPU Spectre v2 protections to intercept sensitive data

By CybersecAsia editors | Friday, August 14, 2026, 12:25 PM Asia/Singapore

Researchers discover way to bypass CPU Spectre v2 protections to intercept sensitive data

Researchers detail Interrupt Injection side-channel on AMD and Intel processors, exposing /etc/shadow contents despite eIBRS and Safe RET mitigations

Researchers at MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) have unveiled findings on 6 August 2026, a new CPU side-channel technique that cuts straight through existing Spectre v2 defenses on both AMD and Intel chips, showing that it is possible to pull Linux password hashes out of kernel memory despite modern mitigations.

The work, described on their website, targets Spectre v2-style branch prediction protections that vendors have promoted as core safeguards against speculative execution attacks.

The attack primitive is named TONTOU (“Time-of-Neutralization to Time-of-Use”) and it focuses on a subtle timing gap in how processors handle branch predictor cleanup. Contemporary Spectre v2 countermeasures such as Intel’s Enhanced Indirect Branch Restricted Speculation (eIBRS) and AMD’s Safe RET mechanism, operate by flushing or compartmentalizing branch prediction state so it cannot be abused by speculative execution.

However, as PhD student Daniël Trujillo and associate professor Mengjia Yan discovered, there is an unavoidable window between the instant the branch predictor is sanitized and the point at which those sanitized predictions are actually consumed by the CPU. TONTOU weaponizes that tiny interval using what the researchers call “Interrupt Injection”.

Interrupt Injection explained

By carefully arranging for a hardware interrupt to arrive precisely inside that neutralized-to-use gap, an unprivileged user-space process can re-poison the branch predictor after the defense has already executed, but before the CPU relies on the supposedly safe prediction data.

In a conversation with security outlet BleepingComputer, Trujillo explained that this enables an attacker with no special privileges “to read arbitrary memory from the system, including sensitive data such as hashed passwords.” The result is that protection schemes previously thought to block speculative branch mispredictions can be sidestepped by extremely fine-grained timing control delivered purely from local code.

In 10 independent trials, the exploit succeeded in identifying and extracting the contents of the /etc/shadow file — which on Linux holds the system’s password hashes — in five cases. On average, each successful run took about 18 minutes to complete from start to finish, illustrating that the leak is slow but feasible in realistic time frames for a determined local adversary.

The researchers also confirmed that the same TONTOU concept applies to Intel processors that ship with Spectre v2 defenses like eIBRS. Nonetheless, they note that practical exploitation on Intel hardware is more complex because it depends on additional software conditions and configuration details, making the proof-of-concept attack harder to reproduce than on the tested AMD Zen 2 system. That nuance is important: both vendors’ CPUs are theoretically exposed, but the real-world barrier to exploitation differs per platform.

Official responses

AMD has responded to the disclosure by acknowledging that the problem “appears to be associated” with how the Linux kernel integrates the Safe RET mitigation rather than being purely a consequence of the microarchitecture itself. In other words, the interaction between the operating system’s implementation and the CPU’s protective feature is what opens the timing window that TONTOU can reach. MIT CSAIL notes that AMD has now issued a patch aimed at neutralizing the attack path, and that mitigation is being delivered to end users through standard operating system updates, including Linux distributions.

The group intend to publish more technical detail when they present at USENIX Security 2026 in October. Their research highlights a persistent reality in hardware and microarchitecture security: even carefully engineered Spectre v2 mitigations can still leave exploitable timing gaps that attackers with only unprivileged local code execution can surgically target. As speculative execution defenses grow more intricate, TONTOU serves as a reminder that defenders must consider not just what state is sanitized, but exactly when and how that sanitization intersects with real-world CPU behavior.

Share:

PreviousSUPCON and Certis Sign Strategic Cooperation Agreement to Advance Robotics in Security Operations
NextGeeLark Upgrades Browser Infrastructure with Version 150 and Team Password Management

Related Posts

Thank you REvil, for teaching the world how to buck up cybersecurity

Thank you REvil, for teaching the world how to buck up cybersecurity

Tuesday, August 17, 2021

Movie streaming fans under attack by cybercriminals

Movie streaming fans under attack by cybercriminals

Monday, July 20, 2020

Does APAC prioritize business profitability over security and fraud detection?

Does APAC prioritize business profitability over security and fraud detection?

Tuesday, June 1, 2021

APAC cybersecurity predictions 2023

APAC cybersecurity predictions 2023

Monday, December 12, 2022

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Cohesity Delivers New Managed Clean Room Capability to Enhance HCLTech VaultNXT

    Wednesday, September 2, 2026
    Cohesity Clean Room solution and …Read More »
  • Visa Launches Enhanced A2A Protect Innovations to Help Financial Institutions Stop Fraud Before Money Leaves Accounts

    Wednesday, September 2, 2026
    New unified fraud score is …Read More »
  • Malaysia’s Cybersecurity Leaders to Convene at the 34th Edition Cyber Security Summit Malaysia 2026

    Tuesday, September 1, 2026
    Summit to Bring Together More …Read More »
  • ICAC Commissioner in Vienna to meet new UNODC Chief to foster anti-corruption strategic collaboration and unveil ICAC’s AI enforcement system “Tianma” at UNODC’s anti-graft conference

    Tuesday, September 1, 2026
    VIENNA, Sept. 1, 2026 /PRNewswire/ …Read More »
  • Visa Expands Support for its Clients and the Industry as Organisations Navigate New AI Era of Cybersecurity

    Friday, August 28, 2026
    Latest Visa Vulnerability Agentic Harness release …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.