Analysis
CAPACITY TEST:

TONTOU CPU Attack Tests Spectre Defenses On Linux Systems

Newsroom brief

Researchers showed a Time-of-Neutralization to Time-of-Use technique that can repollute branch prediction state after Spectre v2 mitigations and leak Linux kernel data in lab tests.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: BleepingComputer
TONTOU CPU Attack Tests Spectre Defenses On Linux Systems
Image source: BleepingComputer

A new CPU side-channel attack can bypass recent Spectre v2 mitigations on Linux systems and leak privileged data, including password hashes, after an attacker gains the ability to run unprivileged code on a target machine.

BleepingComputer reported that Daniël Trujillo, a PhD student, and associate professor Mengjia Yan of MIT CSAIL found a way to exploit the short interval between the moment a branch predictor is neutralized and the moment a protected victim branch uses it.

The researchers call that interval Time-of-Neutralization to Time-of-Use, or TONTOU.

Spectre v2, also known as Branch Target Injection, abuses a processor's indirect branch predictor so the CPU speculatively executes instructions along an attacker-influenced path.

Intel and AMD mitigations such as Intel eIBRS and AMD Safe RET are designed to sanitize or isolate branch-predictor state before sensitive control flow executes.

TONTOU targets the assumption that the cleaned state cannot be usefully repolluted before the victim branch runs.

The researchers introduced a primitive that lets an attacker poison CPU state after neutralization but before use.

"An attacker without any special access to read arbitrary memory from the system, including sensitive data such as hashed passwords," Trujillo told BleepingComputer.

The attack uses interrupt injection.

Unprivileged user programs can schedule timer interrupts during kernel execution, causing the kernel to enter an interrupt handler.

That handler can then be used to poison microarchitectural state inside the post-neutralization window.

The researchers found that interrupts during that window can poison the processor's indirect branch predictor and enable attacks against all types of indirect branches.

Exploitation still requires several difficult steps: redirecting kernel control flow, aligning interrupts precisely with the post-neutralization window, and poisoning the predictor entry tied to the target indirect branch.

In tests on an AMD Zen 2 system running Linux 6.14.0-37-generic with 16GB of RAM, Trujillo and Yan demonstrated arbitrary kernel memory leakage at 5.47 bytes per second with 91.97% accuracy.

The leaked data included contents of /etc/shadow, the Linux file that stores password hashes.

Across 10 runs, the attack located and extracted the file in five cases.

Each attempt took an average of 18 minutes.

The attack was also tested on Intel processors, though the researchers found that additional software requirements made exploitation more complex.

On AMD systems, they combined interrupt injection with Inception, a previously disclosed attack that Trujillo helped develop, because passive Return Stack Buffer pollution was less reliable.

AMD published an advisory saying the interrupt-injection issue "appears to be associated" with how Linux implements the Safe RET mitigation against possible information disclosure attacks.

Trujillo and Yan presented the findings at Black Hat USA.

They are also scheduled to share details at USENIX Security 2026, which runs from October 27 to October 29.

Share this article
inXf

Related articles

More
Defcon Badge Makes Open Security Chip Inspectable As Hardware Token
Cybersecurity

Defcon Badge Makes Open Security Chip Inspectable As Hardware Token

WIRED via Ars Technica reported that Defcon's 2026 badge uses Andrew Huang's Baochip-1x, a mostly open source microcontroller with a removable module that works as a hardware security token and exposes the silicon for infrared inspection.

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion
Cybersecurity

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion

Hugging Face said an autonomous AI agent system drove an intrusion into part of its production infrastructure, reaching internal datasets and service credentials. The company said public models, datasets and Spaces were not tampered with, while its assessment of partner or customer data remains unfinished.

China Opens Security Review Of Palo Alto Networks Products
Cybersecurity

China Opens Security Review Of Palo Alto Networks Products

China's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.

Rails Fixes Critical Active Storage File-Read Vulnerability
Cybersecurity

Rails Fixes Critical Active Storage File-Read Vulnerability

BleepingComputer reported that Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw tied to libvips image processing and possible file exposure in vulnerable applications.

G42 Joins Nvidia Open AI Alliance As Security Debate Widens
AI

G42 Joins Nvidia Open AI Alliance As Security Debate Widens

The National reported that Abu Dhabi's G42 has joined Nvidia's Open Secure AI Alliance, putting a Gulf AI company inside a 38-member push to defend open-weight models after the Hugging Face incident sharpened security scrutiny.

Malaysia AI Agency Launch Leaves Sovereign Cloud Question Unassigned
Capital & Policy

Malaysia AI Agency Launch Leaves Sovereign Cloud Question Unassigned

Tech Wire Asia reported that Prime Minister Anwar Ibrahim launched AI Malaysia while raising unresolved sovereign cloud, US CLOUD Act and cybersecurity questions around the country’s AI governance plan.

Keep Reading

More Stories

Latest
Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.AI Patch Study Keeps Humans In Vulnerability ReviewsCybersecurityAug 7, 2026AI Patch Study Keeps Humans In Vulnerability ReviewsThe Register reported that 1Password Off-by-1 Labs tested 6,080 AI-generated patches across six CVEs and found clean autonomous fixes in 26.0 percent of cases, leaving security teams with a supervision problem rather than a replacement for vulnerability review.DOJ Trade-Fraud Unit Raises Payment Compliance ExposureFintech & Digital PaymentsAug 7, 2026DOJ Trade-Fraud Unit Raises Payment Compliance ExposurePYMNTS reported that a new U.S. Justice Department trade-fraud section and more than $1 billion in recent task-force recoveries are pushing banks to compare payment flows with customs and supply-chain records.Target-Locked Malware Narrows Central Asia Cyber Espionage RiskCybersecurityAug 7, 2026Target-Locked Malware Narrows Central Asia Cyber Espionage RiskBackend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare and research bodies in Central Asia and Syria.