Meltdown, Spectre, CPU Side-Channel Attack
ID: 7bee2a23-5a24-5038-8848-92a019940e6e
STIX ID: report--7bee2a23-5a24-5038-8848-92a019940e6e
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ summarizes the Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753, CVE-2017-5715) CPU vulnerabilities that exploit out-of-order and speculative execution to leak sensitive memory across processes and virtual machines; these issues affect a wide range of processors (Intel, AMD, ARM, System Z, Power9), require coordinated OS/hypervisor/browser/firmware mitigations (e.g., KPTI, browser site-isolation), and have produced PoCs and detection signatures though no widespread in-the-wild exploitation was reported at the time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
