Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks

Posted on May 14, 2025May 14, 2025 By CWS

Chip giants Intel, AMD and Arm every printed Patch Tuesday safety advisories to tell prospects about vulnerabilities discovered lately of their merchandise, together with ones associated to newly disclosed CPU assaults.

One of many CPU assaults was disclosed this week by researchers at Swiss college ETH Zurich. The researchers found a department privilege injection subject, tracked as CVE-2024-45332, that they declare “brings again the complete may of department goal injection assaults (Spectre-BTI) on Intel”.

The researchers declare that whereas Intel’s Spectre-BTI (aka Spectre v2) mitigations have labored for almost six years, they’ve now discovered a approach to break them on account of a race situation impacting Intel CPUs. 

Spectre-style assaults may permit an attacker who has entry to the focused system to acquire doubtlessly worthwhile data from reminiscence, resembling encryption keys and passwords.

In its advisory, Intel stated it’s releasing microcode updates to mitigate CVE-2024-45332, which it described as a delicate data disclosure subject. 

AMD has printed an advisory to tell prospects that — as acknowledged by the researchers as properly — the vulnerability doesn’t impression its CPUs.

One other CPU assault was disclosed this week by researchers at Dutch college VU Amsterdam. Their evaluation, dubbed Coaching Solo, led to the invention of three new courses of self-training Spectre v2 assaults, which spotlight the constraints of area isolation.

The researchers developed two exploits in opposition to Intel CPUs that may leak kernel reminiscence at as much as 17 Kb/s, and so they discovered two new {hardware} flaws (tracked as CVE-2024-28956 and CVE-2025-24495), which “utterly break the area isolation and re-enable conventional user-user, guest-guest, and even guest-host Spectre-v2 assaults”.Commercial. Scroll to proceed studying.

Intel stated it’s releasing microcode updates and prescriptive steering to mitigate these vulnerabilities. 

AMD has printed an advisory to say that its CPUs usually are not impacted by this assault. Arm CPUs, alternatively, could also be impacted. The chipmaker advised prospects that whereas this isn’t a brand new vulnerability, its safety steering has been up to date to extra explicitly spotlight the dangers.

Intel has printed 25 new advisories protecting dozens of vulnerabilities discovered throughout its merchandise. 

The chip large has patched high-severity vulnerabilities that may result in data disclosure, DoS assaults or privilege escalation in Tiber Edge Platform, Graphics and Graphics Driver, Server Board, PROSet/Wi-fi, Gaudi, Xeon, Ethernet Community Adapter, Slim Bootloader, and Simics Bundle Supervisor merchandise.

Medium-severity points have been addressed in Intel’s RealSense, Ethernet Community Adapter, Ethernet Connections Boot Utility, oneAPI Degree Zero, OpenVINO, Advisor, Endurance Gaming Mode, Arc GPU, Core and Xeon CPU, oneAPI DPC++/C++ Compiler, and QuickAssist Know-how merchandise. 

AMD has printed three different new advisories. One covers 4 high-severity vulnerabilities in AMD Manageability Instruments — their exploitation can result in privilege escalation and doubtlessly arbitrary code execution.

One other advisory describes two high-severity flaws in AMD Optimizing CPU Libraries (AOCL), which may be exploited for privilege escalation and probably code execution. The final advisory covers a medium-severity subject in uProf that may be exploited to delete arbitrary recordsdata. 

Associated: Intel TDX Join Bridges the CPU-GPU Safety Hole

Associated: AMD Patches CPU Vulnerability That May Break Confidential Computing Protections

Associated: New SLAP and FLOP CPU Assaults Expose Information From Apple Computer systems, Telephones

Security Week News Tags:AMD, Arm, Attacks, Chipmaker, CPU, Intel, Patch, Respond, Tuesday

Post navigation

Previous Post: Samsung MagicINFO 9 Server Vulnerability Let Attackers Write Arbitrary File
Next Post: Is AI Use in the Workplace Out of Control?

Related Posts

Google Ships Android ‘Advanced Protection’ Mode to Thwart Surveillance Spyware Security Week News
New AI Jailbreak Bypasses Guardrails With Ease Security Week News
Asus Armoury Crate Vulnerability Leads to Full System Compromise Security Week News
Radware Says Recently Disclosed WAF Bypasses Were Patched in 2023 Security Week News
Code Execution Flaws Haunt Adobe Acrobat Reader, Adobe Commerce Security Week News
Law Firms Warned of Silent Ransom Group Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors
  • In Other News: Hacker Helps Kill Informants, Crylock Developer Sentenced, Ransomware Negotiator Probed
  • Critical HIKVISION ApplyCT Vulnerability Exposes Devices to Code Execution Attacks
  • Multiple PHP Vulnerabilities Allow SQL Injection & DoS Attacks
  • Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors
  • In Other News: Hacker Helps Kill Informants, Crylock Developer Sentenced, Ransomware Negotiator Probed
  • Critical HIKVISION ApplyCT Vulnerability Exposes Devices to Code Execution Attacks
  • Multiple PHP Vulnerabilities Allow SQL Injection & DoS Attacks
  • Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News