Close Menu
Tech Savvyed
  • Home
  • News
  • Artificial Intelligence
  • Gadgets
  • Apps
  • Mobile
  • Gaming
  • Accessories
  • More
    • Web Stories
    • Spotlight
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
Apple Reminders sucked for project management until I learned this feature

Apple Reminders sucked for project management until I learned this feature

10 August 2026
I’ve used the Pixel 10 Pro a year. I hope Google fixes these nagging issues on the Pixel 11 Pro

I’ve used the Pixel 10 Pro a year. I hope Google fixes these nagging issues on the Pixel 11 Pro

10 August 2026
MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses

MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses

10 August 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Tech Savvyed
SUBSCRIBE
  • Home
  • News
  • Artificial Intelligence
  • Gadgets
  • Apps
  • Mobile
  • Gaming
  • Accessories
  • More
    • Web Stories
    • Spotlight
    • Press Release
Tech Savvyed
Home»News»MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses
News

MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses

News RoomBy News Room10 August 20264 Mins Read
MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses
Share
Facebook Twitter Reddit Telegram Pinterest Email

Spectre has been haunting CPU security since 2018, and MIT researchers have now found another way to make it misbehave. The new TONTOU attack can bypass some of the defenses Intel and AMD have added over the years by exploiting a tiny gap in how those protections work. The research comes from Daniël Trujillo and Mengjia Yan at MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL). Their findings show that even after a processor wipes or isolates information used by its branch predictor, there can be a brief window before that information is actually used. TONTOU, short for Time-of-Neutralization to Time-of-Use, attacks precisely that gap.

The tiny gap that TONTOU exploits

To understand TONTOU, it helps to understand what makes Spectre attacks possible in the first place. Modern CPUs use speculative execution to predict what software will do next and start working ahead of time. When that prediction turns out to be wrong, the processor discards the result, but traces of that activity can remain inside the CPU and potentially leak information through side channels.

After Spectre emerged, chipmakers introduced defenses designed to clean or isolate the processor’s branch predictor, which helps the CPU guess where code will execute next. The idea is straightforward: remove anything an attacker may have planted before sensitive code runs. The problem, according to MIT’s researchers, is that the cleanup and the moment the prediction machinery is actually used cannot happen at exactly the same time, leaving a tiny “post-neutralization window.” TONTOU targets that gap by injecting a carefully timed interrupt and poisoning the predictor again.

The researchers tested TONTOU on Intel Cascade Lake Refresh and Arrow Lake, as well as AMD Zen 2 and Zen 4 processors, and were able to trigger the necessary branch mispredictions on both platforms. AMD’s Safe RET defense leaves a particularly tiny window, just two instructions wide and typically lasting tens of nanoseconds, but the researchers were still able to hit it by manipulating processor timing. Their technique, called interrupt injection, essentially schedules high-frequency timer interrupts and attempts to land one inside that window, allowing the attacker to poison structures such as the return stack buffer (RSB) or branch history buffer (BHB).

And yes, it can leak protected data

This isn’t purely theoretical. On an AMD Zen 2 system running a stock Linux kernel, the researchers built a complete end-to-end exploit that broke Linux’s kernel address space layout randomization (KASLR) in all 10 attempts. They were also able to locate and leak /etc/shadow, which contains root password hashes, in five of those runs. However, the attack isn’t exactly a speed demon: MIT measured the protected-memory read rate at roughly five bytes per second, while The Register reports that each complete exploit attempt took around 18 minutes and required specific software conditions on Intel.

In other words, TONTOU is a sophisticated attack that demonstrates a real weakness, but it isn’t something ordinary malware can casually throw at a random PC.

The good news is that this isn’t an unpatched zero-day waiting to eat your PC. Trujillo and Yan notified AMD and Intel in February, and Linux kernel maintainers in March. AMD subsequently released a kernel patch that mitigates the attack, so keeping Linux updated is particularly important. Intel, meanwhile, told the researchers it doesn’t plan additional mitigations, arguing that real-world exploitation depends on too many factors, including the availability of suitable disclosure gadgets. Intel did, however, award the researchers a bug-bounty payment.

PC Trends AMD Rizen CPU 1700 hand

The bigger takeaway is less “your Intel or AMD PC is about to be hacked” and more that Spectre-style attacks remain a stubborn problem at the hardware level. TONTOU shows that even carefully designed defenses can leave tiny windows that researchers may eventually find a way to exploit. For most desktop users, this is not an immediate reason to panic. But for shared systems, cloud infrastructure, and multi-tenant environments where untrusted code runs alongside other workloads, the research is a useful reminder that the Spectre saga is far from over.

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleThe $1,500 flagship might be closer than you think
Next Article I’ve used the Pixel 10 Pro a year. I hope Google fixes these nagging issues on the Pixel 11 Pro

Related Articles

Apple Reminders sucked for project management until I learned this feature

Apple Reminders sucked for project management until I learned this feature

10 August 2026
I’ve used the Pixel 10 Pro a year. I hope Google fixes these nagging issues on the Pixel 11 Pro

I’ve used the Pixel 10 Pro a year. I hope Google fixes these nagging issues on the Pixel 11 Pro

10 August 2026
The ,500 flagship might be closer than you think

The $1,500 flagship might be closer than you think

10 August 2026
Apple going circular could make the Watch better at being a watch

Apple going circular could make the Watch better at being a watch

9 August 2026
Intel Arc G3 Extreme Tested: Intel has finally arrived in handheld gaming

Intel Arc G3 Extreme Tested: Intel has finally arrived in handheld gaming

9 August 2026
Logitech’s PRO X2 SUPERSTRIKE HITS differently — and it made me rethink clicking

Logitech’s PRO X2 SUPERSTRIKE HITS differently — and it made me rethink clicking

9 August 2026
Demo
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
I’ve used the Pixel 10 Pro a year. I hope Google fixes these nagging issues on the Pixel 11 Pro

I’ve used the Pixel 10 Pro a year. I hope Google fixes these nagging issues on the Pixel 11 Pro

By News Room10 August 2026

I’ve been using the Google Pixel 10 Pro for almost a year now, which means…

MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses

MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses

10 August 2026
The ,500 flagship might be closer than you think

The $1,500 flagship might be closer than you think

10 August 2026
Apple going circular could make the Watch better at being a watch

Apple going circular could make the Watch better at being a watch

9 August 2026
Tech Savvyed
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact
© 2026 Tech Savvyed. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.