Intel and AMD Hertzbleed CPU Vulnerability Uses Boost Speed to Steal Crypto Keys

Intel and AMD Hertzbleed CPU Vulnerability Uses Boost Speed to Steal Crypto Keys

(Image credit: Hertzbleed) Intel and researchers from UT Austin, UIUC, and UW published papers today outlining the ‘Hertzbleed‘ chip vulnerability that allows side-channel attacks that can steal secret AES cryptographic keys by observing the CPU’s boost frequency/power mechanisms. According to external researchers, both Intel and AMD CPUs are impacted, but AMD hasn’t issued an advisory…

2SGLpNBN5vtjBPQXnqzYfc 1200 80

Intel Hertzbleed CPU Vulnerability Uses Boost Speed to Steal Crypto Keys

(Image credit: Intel) Intel and researchers from UT Austin, UIUC, and UW published papers today outlining the ‘Hertzbleed’ chip vulnerability that allows side-channel attacks that can steal secret AES cryptographic keys by observing the CPU’s boost frequency/power mechanisms. The vulnerability doesn’t impact all cryptographic code, but some mitigation techniques for impacted systems come with as-yet-undefined…

TPM Invisible BIOS Vulnerability Affects Dell, Alienware Machines

TPM Invisible BIOS Vulnerability Affects Dell, Alienware Machines

Five new BIOS security weaknesses have been discovered in the BIOS used by Dell in many of its Alienware, Inspiron and Latitude products. The vulnerabilities, collated by The Hacker News and partly discovered by security firm Binarly, could allow an attacker to execute potentially damaging code. (Image credit: Alienware) Tracked as CVE-2022-24415, CVE-2022-24416, CVE-2022-24419, CVE-2022-24420,…

Security researchers at Wiz discover another major Azure vulnerability

Security researchers at Wiz discover another major Azure vulnerability

Enlarge / This isn’t how the OMIGOD vulnerability works, of course—but lightning is much more photogenic than maliciously crafted XML. Cloud security vendor Wiz—which recently made news by discovering a massive vulnerability in Microsoft Azure’s CosmosDB-managed database service—has found another hole in Azure. The new vulnerability impacts Linux virtual machines on Azure. They end up with…