New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
5 Articles
5 Articles
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]
Researchers have developed a method to avoid current protective measures against the Spectre v2 security vulnerability in Intel and AMD processors. Spectre v2, also known as Branch Target Injection, uses the leap prediction of modern processors to move the processor to speculative execution of commands at a location chosen by the attacker and thus reveal actually protected Linux data. Current countermeasures such as Intel's eIBRS or AMD's Safe R…
Spectre has plagued the processor industry for over eight years and is now arguably one of those security issues that no one seriously wants to call "resolved." On August 6, 2026, AMD responded with AMD-SB-7061 to a new attack technique that can exploit a vulnerability in the Linux countermeasure Safe RET. The attack, dubbed TONTOU, was developed by Daniël Trujillo and Mengjia Yan of MIT CSAIL. The researchers demonstrate that a very small windo…
Researchers at the Massachusetts Institute of Technology (MIT) Computer Science and Artificial Intelligence Laboratory (CSAIL) have announced a new attack method called "TONTOU" that bypasses existing countermeasures against "Spectre v2," which exploits speculative execution of CPUs. The research team has demonstrated that TONTOU can be used to read Linux kernel memory and retrieve the contents of "/etc/shadow," where password hashes are stored.…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








