Telegram Group & Telegram Channel
英特尔CPU曝新漏洞"分支特权注入" 可窃取内核敏感数据

苏黎世联邦理工学院研究人员发现英特尔现代CPU存在名为"分支特权注入"(CVE-2024-45332)的硬件级漏洞,攻击者可利用分支预测器(BTB/IBP)更新与指令执行不同步的缺陷,在权限切换时突破用户态与内核态隔离,以99.8%准确率窃取密码、加密密钥等特权内存数据。该漏洞影响第9代(Coffee Lake)及后续所有英特尔处理器,实测在Ubuntu 24.04系统上能以5.6KB/秒速率读取受保护的/etc/shadow文件。英特尔已发布微代码更新修复,但会导致最高8.3%性能损耗。研究团队将于USENIX Security 2025会议公布完整技术细节。

来源:Bleeping Computer



tg-me.com/DNSPODT/9615
Create:
Last Update:

英特尔CPU曝新漏洞"分支特权注入" 可窃取内核敏感数据

苏黎世联邦理工学院研究人员发现英特尔现代CPU存在名为"分支特权注入"(CVE-2024-45332)的硬件级漏洞,攻击者可利用分支预测器(BTB/IBP)更新与指令执行不同步的缺陷,在权限切换时突破用户态与内核态隔离,以99.8%准确率窃取密码、加密密钥等特权内存数据。该漏洞影响第9代(Coffee Lake)及后续所有英特尔处理器,实测在Ubuntu 24.04系统上能以5.6KB/秒速率读取受保护的/etc/shadow文件。英特尔已发布微代码更新修复,但会导致最高8.3%性能损耗。研究团队将于USENIX Security 2025会议公布完整技术细节。

来源:Bleeping Computer

BY LoopDNS资讯播报




Share with your friend now:
tg-me.com/DNSPODT/9615

View MORE
Open in Telegram


LoopDNS资讯播报 Telegram | DID YOU KNOW?

Date: |

The STAR Market, as is implied by the name, is heavily geared toward smaller innovative tech companies, in particular those engaged in strategically important fields, such as biopharmaceuticals, 5G technology, semiconductors, and new energy. The STAR Market currently has 340 listed securities. The STAR Market is seen as important for China’s high-tech and emerging industries, providing a space for smaller companies to raise capital in China. This is especially significant for technology companies that may be viewed with suspicion on overseas stock exchanges.

Telegram auto-delete message, expiring invites, and more

elegram is updating its messaging app with options for auto-deleting messages, expiring invite links, and new unlimited groups, the company shared in a blog post. Much like Signal, Telegram received a burst of new users in the confusion over WhatsApp’s privacy policy and now the company is adopting features that were already part of its competitors’ apps, features which offer more security and privacy. Auto-deleting messages were already possible in Telegram’s encrypted Secret Chats, but this new update for iOS and Android adds the option to make messages disappear in any kind of chat. Auto-delete can be enabled inside of chats, and set to delete either 24 hours or seven days after messages are sent. Auto-delete won’t remove every message though; if a message was sent before the feature was turned on, it’ll stick around. Telegram’s competitors have had similar features: WhatsApp introduced a feature in 2020 and Signal has had disappearing messages since at least 2016.

LoopDNS资讯播报 from us


Telegram LoopDNS资讯播报
FROM USA