ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

TONTOU CPU side-channel bypasses Spectre v2 fixes to extract Linux hashes

Source headline: New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A CPU side-channel technique dubbed TONTOU can bypass Spectre v2 mitigations intended to reduce speculative-execution leaks. Security researchers demonstrated how the approach can be used to read sensitive data from Linux systems. The proof-of-concept focuses on leaking Linux password hashes, which can enable offline credential cracking. The issue impacts environments where Spectre v2 defenses are deployed but where the new bypass path still applies. Organizations running Linux on affected CPUs should review mitigations, update microcode/software where applicable, and assess exposure to speculative-execution attacks.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#linux #side-channel #spectre-v2 #cpu-attack #mitigations-bypass #password-hashes
Original reporting BleepingComputer New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Open original source