INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Spectre-v2 Variant Exposes Multiple CPU Architectures to Data Leaks
| 2026-09-29 17:00 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A new Spectre-v2 vulnerability, codenamed Branch Target Reuse (BTR), has been discovered that can leak arbitrary kernel memory from Intel- and AMD-based Linux systems. Researchers at VUSec have found a proof-of-concept exploit that can recover the root password hash within minutes from a fully patched system with default protections enabled. The disclosure comes nearly two months after MIT CSAIL researchers disclosed a speculative execution attack technique called Interrupt Injection, which bypasses Spectre v2 defenses and leaks arbitrary kernel memory. This vulnerability affects multiple CPU vendors, including Intel and AMD, as well as web browsers, language runtimes, and the operating system kernel. Mitigations have been released and merged into the Linux kernel for CVE-2026-64507 and CVE-2026-64508.
Technical Mitigations AI-generated
• Implementing a branch target table (BTB) to invalidate stale indirect branch prediction entries and prevent the reuse of obsolete offsets.
• Using a cache invalidation mechanism, such as flushing or invalidating the TLB, after self-modification operations in JIT engines to reduce the window for exploitation.
• Enforcing strict memory protection policies, including address space layout randomization (ASLR) and data execution prevention (DEP), to limit an attacker's ability to infer sensitive information through cache timing side channels.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-64507CVE-2026-64507
CVE-2026-64508CVE-2026-64508
Target & Sectors
BENELUX
BENELUX
Incident Timeline
Sep 29, 2026
Threat actors exploited a Spectre v2 vulnerability in various CPU architectures to execute side-channel attacks, exposing sensitive data.
2026/09/29
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed a new variant of the Spectre v2 attack, codenamed Branch Target Reuse (BTR), that affects systems powered by Intel, AMD, and Arm CPUs.
Click on any entity below to view its context and source!
organisation
VUSec
Researchers from the VUSec group at Vrije Universiteit Amsterdam in the Netherlands and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs.
Ravie Lakshmanan
Sep 29, 2026
Vulnerability / Hardware Security
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new
Spectre
CPU vulnerability variant that affects Just-In-Time (
JIT
) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.
organisation
Intel
Researchers from the VUSec group at Vrije Universiteit Amsterdam in the Netherlands and Scuola Superiore Sant’Anna in Italy have disclosed a new variant of the Spectre v2 attack that affects systems powered by Intel, AMD, and Arm CPUs.
"
As a proof-of-concept, two end-to-end exploits have been devised against the Linux kernel that can be used to leak and recover the root password hash within minutes from a fully patched Intel system with default protections enabled.
organisation
CPU
Ravie Lakshmanan
Sep 29, 2026
Vulnerability / Hardware Security
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new
Spectre
CPU vulnerability variant that affects Just-In-Time (
JIT
) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.
CPU vendors pointed out that existing mechanisms, such as the indirect branch prediction barrier (IBPB), can mitigate BTR, and that fixes need to be implemented in software.
organisation
Vulnerability /
Ravie Lakshmanan
Sep 29, 2026
Vulnerability / Hardware Security
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new
Spectre
CPU vulnerability variant that affects Just-In-Time (
JIT
) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.
infrastructure
Linux
"
As a proof-of-concept, two end-to-end exploits have been devised against the Linux kernel that can be used to leak and recover the root password hash within minutes from a fully patched Intel system with default protections enabled.
The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox.
They developed two end-to-end exploits against the Linux kernel.
Linux kernel exploit leaks the root password hash
The kernel exploits abuse classic BPF (cBPF).
Linux kernel developers have introduced an x86 mitigation that triggers an IBPB across every CPU core whenever a cBPF program is placed in a memory region that was already used by previously executed BPF code.
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses.
"
BTR was evaluated against SpiderMonkey (the JIT engine of Mozilla Firefox), GraalVM, and the Linux kernel's cBPF JIT, all of which have been found to be affected, although with "markedly different exploitability characteristics and leakage rates.
Following responsible disclosure, mitigations for BTR have been released and merged into the Linux kernel (
CVE-2026-64507
and
CVE-2026-64508
).
"
The disclosure comes nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed a speculative execution attack technique called
Interrupt Injection
that can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel- and AMD-based Linux systems.
organisation
IBT
However, even on race-free CPUs, the researchers were able to bypass IBT when constant blinding was disabled, although they describe race-free IBT combined with constant blinding as a much stronger defense.
organisation
Oracle’s
The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox.
organisation
SpiderMonkey
The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox.
"
BTR was evaluated against SpiderMonkey (the JIT engine of Mozilla Firefox), GraalVM, and the Linux kernel's cBPF JIT, all of which have been found to be affected, although with "markedly different exploitability characteristics and leakage rates.
organisation
WebAssembly
The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox.
organisation
BPF
Linux kernel exploit leaks the root password hash
The kernel exploits abuse classic BPF (cBPF).
organisation
Mozilla Firefox
"
BTR was evaluated against SpiderMonkey (the JIT engine of Mozilla Firefox), GraalVM, and the Linux kernel's cBPF JIT, all of which have been found to be affected, although with "markedly different exploitability characteristics and leakage rates.
organisation
BTR
Following responsible disclosure, mitigations for BTR have been released and merged into the Linux kernel (
CVE-2026-64507
and
CVE-2026-64508
).
organisation
AMD
"
The disclosure comes nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed a speculative execution attack technique called
Interrupt Injection
that can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel- and AMD-based Linux systems.
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks.
organisation
MIT
"
The disclosure comes nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed a speculative execution attack technique called
Interrupt Injection
that can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel- and AMD-based Linux systems.
organisation
Daniël Trujillo
"
The disclosure comes nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed a speculative execution attack technique called
Interrupt Injection
that can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel- and AMD-based Linux systems.
organisation
Variant Exposes Intel
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks.
organisation
Data Leaks
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks.
organisation
Branch Target Reuse
The researchers named it
Branch Target Reuse (BTR)
, and it targets the just-in-time (JIT) compilers relied upon by operating system kernels, web browsers, and runtimes.
The new Spectre-v2 variant has been codenamed
Branch Target Reuse (BTR)
.
organisation
Seccomp
Seccomp, socket filtering, and packet filtering in applications like Docker and Chrome continue to rely on it.
organisation
Mozilla
Oracle has rolled out some mitigations, and Mozilla is currently prioritizing the completion of site isolation over IBPB-based mitigations.
organisation
Arm’s BTI
Hardware control-flow protections such as x86’s IBT and Arm’s BTI protections make exploitation more difficult but do not fully remove the threat.
organisation
Lion Cove
Older Intel CPUs can still speculatively execute instructions before the check, and Lion Cove is the earliest Intel generation the researchers found to be free of this race condition.
data_breach
8 bytes
“Our exploit leaks 8 bytes per second.
organisation
Cristiano Giuffrida
"The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida said in an accompanying paper.
organisation
SMC
VIDEO
"BTR targets JIT engines and arises from the interplay between Self-Modifying Code (SMC) and indirect branch prediction," the researchers said, adding, "JIT engines do expose exploitable transient-execution opportunities induced by SMC for the first time.
organisation
JIT
The entire sequence of actions is as follows -
The attacker lures the JIT engine into allocating a training chunk and forces the victim branch to jump to it, thereby inserting a BTB entry referencing the current entry point.
organisation
BTB
The entire sequence of actions is as follows -
The attacker lures the JIT engine into allocating a training chunk and forces the victim branch to jump to it, thereby inserting a BTB entry referencing the current entry point.
organisation
Indirect Branch Predictor
"Mozilla considered
IBPB
[Indirect Branch Predictor Barrier]-based mitigations, but is currently prioritizing the completion and deployment of site isolation.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
The researchers analyzed Linux cBPF, Oracle’s GraalVM runtime, and SpiderMonkey, the JavaScript and WebAssembly engine in Firefox.
They developed two end-to-end exploits against the Linux kernel.
Linux kernel exploit leaks the root password hash
The kernel exploits abuse classic BPF (cBPF).
Linux kernel developers have introduced an x86 mitigation that triggers an IBPB across every CPU core whenever a cBPF program is placed in a memory region that was already used by previously executed BPF code.
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses.
"
BTR was evaluated against SpiderMonkey (the JIT engine of Mozilla Firefox), GraalVM, and the Linux kernel's cBPF JIT, all of which have been found to be affected, although with "markedly different exploitability characteristics and leakage rates.
"
As a proof-of-concept, two end-to-end exploits have been devised against the Linux kernel that can be used to leak and recover the root password hash within minutes from a fully patched Intel system with default protections enabled.
Following responsible disclosure, mitigations for BTR have been released and merged into the Linux kernel (
CVE-2026-64507
and
CVE-2026-64508
).
"
The disclosure comes nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed a speculative execution attack technique called
Interrupt Injection
that can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel- and AMD-based Linux systems.
Metrics
data_breach
8
Bytes
“Our exploit leaks 8 bytes per second.
Intelligence Sources
The Hacker News
2026-09-29
SecurityWeek
2026-09-29
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:16
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
VUSec
entity
3x
timeline
Temporal Reference
Sep 29, 2026
date
2x
target region
Target Country
Netherlands
country
2x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
2x
vulnerability
Exploited CVE
CVE-2026-64507
cve
Contextual Telemetry
Context Block
4 METRICS
industry
Targeted Sector
Defense
sector
infrastructure
Affected Product
Linux
software
data breach
Bytes
8
bytes
general metric
Sep
29
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.