Skip to content
SecurityTech

Spectre v2 Fixes Ghosted by New TONTOU Attack, Because CPUs Are Still Treasonous

Researchers have disclosed TONTOU, a new CPU side-channel attack that circumvents existing Spectre v2 mitigations to leak sensitive data such as Linux password hashes from kernel memory. The attack demonstrates that previous fixes for speculative execution vulnerabilities remain incomplete, leaving systems potentially exposed despite years of patching efforts. The findings underscore the ongoing challenge of securing modern processor architectures against increasingly sophisticated timing-based exploits.

Read full article →