New Spectre v2 attack variant leaks Linux root password hash in minutes
Summary
A new Branch Target Reuse (BTR) attack variant has been discovered that can extract Linux root password hashes from Intel-based computers. The attack can reportedly recover these hashes within 3-5 minutes on average.
IFF Assessment
FOE
This is bad news for defenders as it represents a new, potentially efficient method for attackers to compromise sensitive credentials.
Defender Context
This new BTR attack highlights ongoing risks associated with speculative execution vulnerabilities in Intel processors. Defenders should be aware of potential exploitation vectors targeting sensitive credentials like root password hashes, and ensure systems are patched against known variants of these side-channel attacks.