INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Spectre-v2 Variant Exposes Multiple CPU Architectures to Data Leaks

| 2026-09-29 17:00 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A new Spectre-v2 vulnerability, codenamed Branch Target Reuse (BTR), has been discovered that can leak arbitrary kernel memory from Intel- and AMD-based Linux systems. Researchers at VUSec have found a proof-of-concept exploit that can recover the root password hash within minutes from a fully patched system with default protections enabled. The disclosure comes nearly two months after MIT CSAIL researchers disclosed a speculative execution attack technique called Interrupt Injection, which bypasses Spectre v2 defenses and leaks arbitrary kernel memory. This vulnerability affects multiple CPU vendors, including Intel and AMD, as well as web browsers, language runtimes, and the operating system kernel. Mitigations have been released and merged into the Linux kernel for CVE-2026-64507 and CVE-2026-64508.
Technical Mitigations AI-generated
• Implementing a branch target table (BTB) to invalidate stale indirect branch prediction entries and prevent the reuse of obsolete offsets. • Using a cache invalidation mechanism, such as flushing or invalidating the TLB, after self-modification operations in JIT engines to reduce the window for exploitation. • Enforcing strict memory protection policies, including address space layout randomization (ASLR) and data execution prevention (DEP), to limit an attacker's ability to infer sensitive information through cache timing side channels.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-64507CVE-2026-64507 CVE-2026-64508CVE-2026-64508
Target & Sectors
BENELUX BENELUX
Incident Timeline
‎Sep 29, 2026
Threat actors exploited a Spectre v2 vulnerability in various CPU architectures to execute side-channel attacks, exposing sensitive data.
‎2026/09/29
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed a new variant of the Spectre v2 attack, codenamed Branch Target Reuse (BTR), that affects systems powered by Intel, AMD, and Arm CPUs.
organisation VUSec
organisation Intel
organisation CPU
organisation Vulnerability /
infrastructure Linux
organisation IBT
organisation Oracle’s
organisation SpiderMonkey
organisation WebAssembly
organisation BPF
organisation Mozilla Firefox
organisation BTR
organisation AMD
organisation MIT
organisation Daniël Trujillo
organisation Variant Exposes Intel
organisation Data Leaks
organisation Branch Target Reuse
organisation Seccomp
organisation Mozilla
organisation Arm’s BTI
organisation Lion Cove
data_breach 8 bytes
organisation Cristiano Giuffrida
organisation SMC
organisation JIT
organisation BTB
organisation Indirect Branch Predictor
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
data_breach
8
Bytes
Intelligence Sources