New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Summary

Researchers have discovered a new CPU attack called TONTOU that can bypass existing Spectre v2 mitigations. This attack has been successfully demonstrated to leak sensitive information, including Linux password hashes, from affected machines.

IFF Assessment

FOE

This attack represents a significant threat to system security by circumventing previously implemented protections, allowing attackers to exfiltrate critical data.

Defender Context

This discovery highlights the ongoing challenges in defending against sophisticated side-channel attacks, even after patches have been applied. Defenders should stay vigilant for vendor updates and be prepared to implement additional hardening measures beyond standard mitigations.

Read Full Story →