Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New StackWarp Attack Threatens Confidential VMs on AMD Processors

New StackWarp Attack Threatens Confidential VMs on AMD Processors

Posted on January 15, 2026January 15, 2026 By CWS

A workforce of researchers from the CISPA Helmholtz Heart for Info Safety in Germany has disclosed the main points of a brand new {hardware} vulnerability affecting AMD processors. 

Dubbed StackWarp, the problem has been discovered to impression AMD Zen 1 by way of Zen 5 processors, enabling an attacker to hack confidential digital machines (CVMs).  

The researchers described StackWarp as a software-based architectural assault that “exploits a synchronization failure within the stack engine that manages stack pointer updates within the CPU frontend”.

Exploitation of the vulnerability permits a malicious VM host to govern the visitor VM’s stack pointer to hijack management and information flows, enabling distant code execution and privilege escalation inside CVMs.

The CISPA researchers have demonstrated the impression of the assault in a number of assault situations, together with reconstructing an RSA-2048 personal key, circumventing OpenSSH password authentication, bypassing Sudo’s password immediate, and attaining kernel-mode code execution in a VM.

Conducting all these assaults usually requires privileged management over the host server working the CVMs. Assaults might be launched by rogue staff of a cloud supplier or a classy risk actor that has gained entry to the supplier’s programs. Commercial. Scroll to proceed studying.

Whereas the probabilities of such an assault being carried out within the wild are small, the StackWarp assault reveals that AMD’s SEV-SNP, which is designed to encrypt VM reminiscence to guard it even towards the cloud supplier, will be undermined with out the attacker ever seeing decrypted reminiscence. 

“These findings reveal that CVM execution integrity—the very protection SEV-SNP goals to supply—will be successfully damaged: Confidential keys and passwords will be stolen, attackers can impersonate legit customers or achieve persistent management of the system, and isolation between visitor VMs and the host or different VMs can now not be relied upon,” the researchers stated.

AMD has been knowledgeable in regards to the vulnerability and printed an advisory on Thursday. The chip big has assigned the flaw a low severity ranking and informed SecurityWeek that patches have been out there for the impacted server (EPYC) merchandise since July 2025. 

The CVE identifier CVE-2025-29943 has been assigned to the StackWarp vulnerability. 

The researchers have arrange a devoted web site for StackWarp, and a paper with the total technical particulars has additionally been printed. Movies displaying the assault in motion are additionally out there.

Associated: AMD Patches CPU Vulnerability That May Break Confidential Computing Protections

Associated: Chipmaker Patch Tuesday: Intel, AMD, Arm Reply to New CPU Assaults

Associated: Intel, AMD Processors Affected by PCIe Vulnerabilities

Security Week News Tags:AMD, Attack, Confidential, Processors, StackWarp, Threatens, VMs

Post navigation

Previous Post: Vibe Coding Tested: AI Agents Nail SQLi but Fail Miserably on Security Controls
Next Post: Forget Predictions: True 2026 Cybersecurity Priorities From Leaders

Related Posts

European Commission Probes Cyberattack on IT Systems European Commission Probes Cyberattack on IT Systems Security Week News
Mercedes F1 Team Principal Toto Wolff Sells 15% Stake to CrowdStrike CEO George Kurtz Mercedes F1 Team Principal Toto Wolff Sells 15% Stake to CrowdStrike CEO George Kurtz Security Week News
Critical King Addons Vulnerability Exploited to Hack WordPress Sites Critical King Addons Vulnerability Exploited to Hack WordPress Sites Security Week News
The ZTNA Blind Spot: Why Unmanaged Devices Threaten Your Hybrid Workforce The ZTNA Blind Spot: Why Unmanaged Devices Threaten Your Hybrid Workforce Security Week News
Quest KACE Security Flaw Potentially Exploited by Hackers Quest KACE Security Flaw Potentially Exploited by Hackers Security Week News
Two Exploited Vulnerabilities Patched in Android Two Exploited Vulnerabilities Patched in Android Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark