ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Cloudflare Workers Spectre attack extracts JWT at 12 bits per second

Source headline: Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Threat level High
Signal strength 65/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Researchers disclosed a remote Spectre attack that targets Cloudflare Workers. The attack leaked a JSON Web Token (JWT) from a co-located Worker. The leaked data was obtained at up to 12 bits per second in the researchers’ end-to-end experiment. The researchers used an attacker Worker and a victim Worker they controlled in the production environment. The reported leakage rate is 360 times higher than an earlier 2021 demonstration. Cloudflare Workers users should review isolation and side-channel risk guidance and follow any mitigations recommended in response to this disclosure.

Recommended Action

Inventory where Cloudflare Workers runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#cloudflare #side-channel #cloudflare-workers #jwt #spectre
Original reporting The Hacker News Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Open original source