Intel has announced the discovery of several high-severity vulnerabilities that could allow attackers to escalate privileges and execute arbitrary code on affected systems. The vulnerabilities affect a range of Intel products, posing significant risks to users and organizations relying on these technologies. In total, both Intel and AMD have fixed over 80 vulnerabilities combined, indicating a widespread issue within the chipmaking industry. Users are urged to apply the latest patches to safeguard their systems against potential exploitation. This situation underscores the need for continuous vigilance and prompt action in maintaining cybersecurity.
Articles tagged "AMD"
Found 6 articles
A recent study conducted by Specops researcher David Ketler tested the Argon2id password hashing algorithm against a powerful eight-GPU system equipped with Nvidia RTX 5090 cards and a single AMD EPYC 9B14 server processor. The findings revealed that Argon2id effectively neutralizes the advantages that such high-performance hardware would typically have in cracking passwords. This means that users relying on Argon2id for password security can feel more confident that their accounts are better protected against brute-force attacks. The implications are significant for individuals and organizations that prioritize strong password protection, as it makes it harder for attackers to compromise accounts using advanced hardware. As password cracking technology continues to evolve, using algorithms like Argon2id can play a crucial role in maintaining security.
A serious vulnerability in the Linux Kernel-based Virtual Machine (KVM) has been discovered, allowing attackers to potentially escape from a virtual machine (VM) to the host system. This flaw, which is 16 years old, affects both Intel and AMD systems. Security researcher Hyunwoo Kim reported that the issue is a use-after-free vulnerability, enabling malicious code running in a guest VM to corrupt the memory of the host kernel. The implications are significant, as it could allow unauthorized access to sensitive data or control over the host. Organizations using affected systems should take immediate action to assess their vulnerability and apply necessary patches to safeguard their environments.
A vulnerability in the Linux KVM hypervisor has been discovered, allowing guest virtual machines (VMs) to escape and potentially compromise the host system. This flaw, identified as CVE-2026-53359 and nicknamed 'Januscape,' arises from a use-after-free bug within the shadow MMU code that is utilized by both Intel and AMD x86 architectures. Researchers have demonstrated a proof-of-concept that can crash the host machine, raising concerns about the security of virtualized environments. The existence of an unreleased exploit that could further exploit this vulnerability has also been claimed, suggesting that the risk is significant. Organizations using Linux KVM on affected systems should take immediate precautions to secure their environments.
Researchers have revealed a new vulnerability dubbed the StackWarp Attack that targets AMD processors, enabling attackers to execute code remotely within confidential virtual machines (VMs). This flaw poses a significant risk to cloud environments where sensitive data is processed, as it could allow unauthorized access to protected information. The attack exploits weaknesses in the architecture of AMD processors, making it particularly concerning for organizations relying on these systems for secure operations. Companies using AMD processors in their cloud infrastructure should assess their systems for vulnerabilities and stay informed about potential patches or mitigations that may be issued in response to this discovery. The implications of this attack are serious, especially for sectors dealing with confidential data such as finance, healthcare, and government.
Researchers have developed a low-cost device that successfully bypasses the memory encryption protections implemented by AMD and Intel, exposing significant vulnerabilities in scalable memory encryption systems. This discovery raises serious concerns regarding the integrity and confidentiality of data processed by these chipmakers' technologies.