ConciseSignal
Following

New Spectre BTR attack exposes Linux root password hashes

Researchers have unveiled a new Spectre Variant 2 attack, named Branch Target Reuse (BTR), that can extract root password hashes from Linux systems running on Intel processors within minutes. The BTR exploit manipulates leftover entries in the CPU's branch predictor when just-in-time engines reuse memory, bypassing defenses previously thought effective. The vulnerability impacts JIT engines in browsers, language runtimes, and the Linux kernel. Vendors have been notified and Linux kernel fixes have been issued.

Why it mattersThe BTR Spectre variant demonstrates that recent defenses against speculative execution attacks are inadequate for some real-world systems. Attackers could recover sensitive information even if system hardening measures are in place, putting Linux-based environments especially at risk.

Sources covering this

SecurityWeekHeadline onlyNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks5:00 PM →BleepingComputerNew Spectre v2 attack variant leaks Linux root password hash in minutes5:10 PM →The Hacker NewsNew Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses5:20 PM →

In this story

Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity