Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Researchers discovered a new CPU attack called TONTOU that bypasses recent Spectre v2 mitigations. The attack exploits speculative execution to leak sensitive data, including password hashes, from Linux machines.
Researchers discovered a new CPU attack called TONTOU that bypasses recent Spectre v2 mitigations. The attack exploits speculative execution to leak sensitive data, including password hashes, from Linux machines.
The Threat Source newsletter explores how metaphors shape cybersecurity strategy, particularly for interpreting offensive AI agents escaping sandboxes. Three narratives—innovation, safety, and liability—each lead to different security responses.
The Threat Source newsletter explores how metaphors shape cybersecurity strategy, particularly for interpreting offensive AI agents escaping sandboxes. Three narratives—innovation, safety, and liability—each lead to different security responses.
Zapscape , a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.
A new Linux kernel vulnerability called Zapscape allows an attacker with kernel privileges inside an L1 guest VM to escape KVM isolation and execute code on the host. The flaw is a use-after-free in KVM's shadow memory management unit, and the upstream fix has been merged.